Sign inSign up
Python

dhi.io/python

Python 3.10.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

3.10-debian-sfw-dev, 3.10-debian13-sfw-dev, 3.10-sfw-dev, 3.10.21-debian-sfw-dev, 3.10.21-debian13-sfw-dev, 3.10.21-sfw-dev

Index digest:

sha256:4df3fa4d0093e72d61b4db02bf9a7a7d6dad84046881dc222ec33d221eba7643

Manifest digest:

sha256:33822e8dc3c9314cd2a4d8f746caa7380d6ec8b040e82ded96122df1adc16365

Size

74.48 MB

Last pushed

2 days ago

Vulnerabilities

0
1
4
2
1

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:b30052c14bcc28b83913121c2226b7aac62a26bc7f98533b724e6b8a9413f100
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:58250d898d09652b003adf13277929ebdc14afb1d5d235a1a3f4e5b6df1baa22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:145e5a8f8b0c7c6b57999282cae536d4b43af71c0e9e28a2d2cdef1776db2859
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:f78d0a6c3c2255a9b00b1a7e8f4d2e87dac06975f561725402555642d6b27d74
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:2d19994888fde356113f709df51b4a5b9bc0ec26fcc1b537028592b99013bf65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:1343401de7ea1ba06056b64ac1b50daf3aba830f3045e716643fce53905ed359
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:a620c92b5e59fe0294559b147c8937bfd591e0926dabaa91b9c00e4725beca4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:709fd9456eaa1fad9a60f0b508551275fe9c8c76117895fb3c26648b73e08a42
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:2bdbb24c1863772227d83facd43da783d2683575c0cd278657f09c95ba2a7282
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:79e222cf8509ea0c5876849558bf806967077c7526592f297a79065a1cac39e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:67cc6a71f4551b3bcc216d3bcca744b1a3adb033b45d184cb5f5ca46eceaf6b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:2e5609e889781a846f41b1bcf1f0f88e2b31a8e8642fea9f8d6b559fae4f71e4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:3abfa424745043a628ff319bd0bfdb4be5121d0dbaf09956502d795209cab701
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:3de25e8e63535d08673b14cc1329bfb9cc83e8302d0ed2b79f1452315b06a768
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:6ab20b828c88a5cdc54f749b68327965c38480d61913d77c68e8101935dc721c