Sign inSign up
Python

dhi.io/python

Python 3.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.10-debian-fips-dev, 3.10-debian13-fips-dev, 3.10-fips-dev, 3.10.21-debian-fips-dev, 3.10.21-debian13-fips-dev, 3.10.21-fips-dev

Index digest:

sha256:11f69282dc154e134e1d264bce0add7bdc7daabe603226100a69c47140b70055

Manifest digest:

sha256:e9c9d8b620e0d87e9f7e9bc15be9697cd76c62cebd04254efa3057229b950cf8

Size

41.46 MB

Last pushed

1 day ago

Vulnerabilities

0
1
4
2
1

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:d1dc0132f06d9af09f70eb7126c92b4bdacf4ede4b1fb05f72d097be28ef011b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:92797c020df20cd7cc5cab65cc6802fbcc640f3dff56a3e69f41de2453625ceb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:382afd7fd0d17037b2addaa25ab9ca4649569debdf4912b4d1ae44ba3c5d9f97
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:7a45a1bb20252e0e0da55ca3e9d04af01f1d95235dff2e4a7f12abfd0cd5abb9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:d9bef80f299ccc05740a8a9023d5a0ef28634fa22d2c22d8d1a58b65315c36b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:195e84f3153be0a97da22f701621f4184298a47a2620c2552e26677c619c072a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:6b1c6091b04940f92fb9d1ddaffd93dfc048f4643de81dcf3c2cac4db4a01f8f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:52dba98ad24086a737555794a3e7f1e0d10f17fde6a8242a156fb44034a66a7c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:4b08b45b926cdcaaf27e54001cf1367f07478fbfeb23e455598a423b80b82903
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:e8b2c380f0cba9107cd6fe653731010caf74af54db3c6bfd089087e50de6d948
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:65ef102b17505261997a6ccc4cc063c7c8187d80e6c3f87190989506e653e9b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:0b6c394dcb288a96d7ff6118e82ba2eae44702bffa00b9217ce407efd215e4d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:dbd0fc3b5abb4b89bc2eed5cd62a85cc7062ecf5108883b560421ca0cd0fa9cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:fafd04da9b8b4139b95cf330c12fee26bcad8d3c597f5ae9c938107cdcf7bf1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:fa68c28ae11883c85a956d64a88ae5b076dbf072b16372ac269401fd948baa52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:f0d62acdafbff1af35f32c100f5c8c817b5c22ee1ef12430cf7f16b7f001f50d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:fbcbd9105240194c90053f4923c0acf6036d2c18849ce1fd291db001ab64e8af