Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.14-alpine-fips, 3.14-alpine3.24-fips, 3.14.7-alpine-fips, 3.14.7-alpine3.24-fips

Index digest:

sha256:cbdba1a6df3176bbe5212bbee4a5cc740a3c0685684fbeda00e8e0867c679412

Manifest digest:

sha256:a88734e87c551ff72b0b1e24c266580700aa248f5cf9bba6f8af2c62ab1f7efc

Size

18.38 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.14-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.14-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:93800940ddb564e5aed284658ef2757580770407e7e3016d1ae89355c7f501cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:93d516ae98500bb215be4474cdcb0fe861c136e21f632b78f07efe30d1203748
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:9ecc3a4eaa45e0eef23b9c55ea7510b88aab8b76247c149b21395fc912abaf51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:05998975f4d022dc51f2605a56856ee1d7278ae7ae0b196cd76daad424912f3f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:02ad62d3937477d7a48f2898fb07cf97bb41aed5e24a9dd476c6da723f86da50
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:01993b3cc545a4ee5d86728df064d67f663795a43cc62b224281208bd6e6345f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:8109ee1e765c15912d8d42875c9e70595c5129473fb080a9357d3cc2ecc05c7e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:5cc33a8a11a075e81c9979911a4581d9ef5b469a6df5bdea1af078190ef0c6d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:81743c2a47d6e0180d7db40e084ee49adbad2b0d46aaa2db26d64b507d217855
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:a4f3aca8118b7eb08c83ff9e460ef2018a5474e0838a2d9d963fad78e3c7a98e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:ca655157aa6c30d84b0ecee0b8ca97a57022e96cb504c598fb03b3cf0d57d650
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:a0c5daffa2489c9d1965b7ba44b88c1e38461d2bf3a61816ed6387f30f6f589c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:86d86a728b9a3049067a171f1166f83531d69c35457e811d96344060e62a5b9c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:6f7e8e967e4ca7ebd1509f7fd1ac4f7134e7ec286c7b70fa4ad40069ee662744
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:1b51e2bd8b9ca962d419477785f88275d6371fb036ce80cbf4a00de202e0fc33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:63a3821572b93a0a1060e9c35168ccf488fc4c608e088942d8e73abee3c3b30a