Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-sfw-dev, 3-alpine3.24-sfw-dev, 3.14-alpine-sfw-dev, 3.14-alpine3.24-sfw-dev, 3.14.7-alpine-sfw-dev, 3.14.7-alpine3.24-sfw-dev

Index digest:

sha256:1e60f4523af0285c8c82be805b2487d087b4cf0c562db65f015feeaa4f5c50e8

Manifest digest:

sha256:0c118b7fe60c0dd2d2c5139250b681adc849d7aaa676cb5414d41d010fc403d6

Size

118.93 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:fcc8f083471dcc54d855b8686704eec65a46564275f413be17fba5d495de371e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:4cef302ed8a232e103a20e3389e4eef00854afd4e80854d535d7882605b81dfa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:d33b380926612307318bfd167d249a9009887bd6ae2f690c0a6e48a46acac50a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:10876f6acfadd27f3785801a20d6c503039cedfce362dd64155f2d7295aed14f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:58388bd8beecfa80a7ffceb77432929c5743fb11c0d14e16bcb746086a33291e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:75034dd026a5800c169d56cf3629a7aea677d3aec56f4b019a800e6378f8b385
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:760cf72bd2e7b7ddd54ee2c96e27cfaeefce1609b557bd5e6215ee63eb4d57a6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:787568694d4f1fc740e7d6a35494a6e99027725453dc7af3cc8621441358a7cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:e6ca271058b9d59323f03804d00662df1823073c3f0dd4e534b22f68a4119661
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:39d6f10bfe6ae67a507ecf4f5c41fbcd28b908f6b63655d7237ef957137134df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:469d716e5b24713636a5109dcb15661860851cacc5aa50c689810523b190fa86
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:af15f843d3870b4f27234afb70d7cb62f8179e900d64a46a8b4eaa18f8acc16f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:f916b20d18eb3c181b334ffb1693ef95ebb32e55270fee5fd59894aa07c3c26c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:868746c6b256a91d2deefe65c4b2fbd5f4f791a1d4aa33ff2b7bcfc0e9b8f6a6