Sign inSign up
Python

dhi.io/python

Python 3.10.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.10-debian-dev, 3.10-debian13-dev, 3.10-dev, 3.10.21-debian-dev, 3.10.21-debian13-dev, 3.10.21-dev

Index digest:

sha256:7007c0c1582ea5ee076800c35a08496786674e7254d6e7176a0eb58a429583a8

Manifest digest:

sha256:0ac344cb18de9e4814a895e65327705847343503502c47cc4d1f0b51324808dd

Size

37.85 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
4
2
1

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:0578fce1a680126578fd589e69bb674a726bc9f3965a6164096ea3bbfe9643a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:1fd307d3b7100d07517a61df9ff4d029b4e6d281d9ea9da24d5288a3bcb1835a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:922be11606c5f23ff8b7b904d6bc9a7c49760c77aa216e7f0617c11057b8964e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:44fd62fbae7c778492a952e56d9003969ef1f6c111a2ccaed157ee62d8bf8c38
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:238d508feae496c7049fc423e1eec8a6576df748b3f3ce4a5d5bd016ed1f37db
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:d11f798b470804b750f080e6eff8c7057547e6856e52fbb95774ff40d440cbc1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:8fecb2e2f3e7d908186d3b7a29f3e481c2e7ffe2c3622dee955d3c616ad1aab7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:32c45d1ea771fc6ea62458984f1c52c121667cf59f0d6beba3d83f8388dbda93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:026d289a654a9b95e9847f680737fe452b36df981f2243d80e5ff9f85a8e66af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:64fc239e10a4ab3b1e6957caa69695c723ff7143fb9782410af0a03fecbe2942
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:bd42809f58cc1a5bdedc1643dc4c5932a6842210a431a2c2fbb81506504fd408
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:4e38d237cfbcb190ec57583bf7edd44b9df5576b91fd1e2a80ab081c49433821
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:79f8bba5f7929df0c078a1e67f0433317aba4ec581c9561bdd134af51ea5d6c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:08de9a3125fa061dffa890e300b8bb504f9b14c24445734bbd53713047b94c68
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:6a8ccde6aa20f69a2e9243233a790dfe9d0a40a288baffd3b40b72515bd660aa