Sign inSign up
Python

dhi.io/python

Python 3.11.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

3.11-debian-sfw-dev, 3.11-debian13-sfw-dev, 3.11-sfw-dev, 3.11.16-debian-sfw-dev, 3.11.16-debian13-sfw-dev, 3.11.16-sfw-dev

Index digest:

sha256:a96e8cc21f789e87c80e93d4543fec5d394688e038d73f89d43414a000cb1790

Manifest digest:

sha256:bd6f1293d5675880047e6e7ec9fb0c6b336ba77587a1868d191e7ae0f810d85b

Size

74.86 MB

Last pushed

1 day ago

Vulnerabilities

0
0
3
2
1

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.11-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.11-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:6e3e514a1537fa7aba003d82731692ba13f53f939cdd58855442f03ad7b8636c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:8ffa39fc4e511d4a58b12c0d693b2837932686102e42f6d5b0bd78b7cb90daef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:1266f22f7c9e3f90051f16bcaf37afef72e2684a388459abe6d544571b859e23
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:025be8de5b0cffe62096d9612de1b87e3e40f7ccf14fb90e7de75bfa2d1eafbc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:1f36e33b57e8db697787272c31e668f84d7908ee47aaa1c784ecfc3cc43ed0bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:d5f630204ee82b350894d625aaedc2de16ab43571d773a557e4c93311666d676
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:7a6c50ebd2478460e6b2f13048c6b9f38079c86598c6de8a2a3c2fc7b249fb98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ff9c25ccac3d1e3e2e08e190492e9373fa6a99356546b60e3d6029013c50eae9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:585f4043bb9a807f542986cabda9e2f9da69be858a93e5490f7417df79697605
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:fb5ebc646db37a5ef5ff79c420d6e4483a673546dc1d9973355ce9a2f5367cae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:183792e8b018aa481a4c68b9f7a24ec9c6b442fe550d919b83e42b02edc5b3b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:f84a124ceb85ad7453d30a3d5c7bb38155cc40c0fa1f3644ab1047cec1119e8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:8767070636b62003cd809a036d562da386002ebb753af2d1e5e5a9a93d96d0c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:47e44711bcfe66b000aa105469ab0cdaacbdb3ee6ff5fdd4c2344fe78df32ee0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:a94fca90e60430149134bd368e9bfea81e29b7fdb7a1b65022349636beb4acb6