Sign inSign up
Python

dhi.io/python

Python 3.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.15-debian-dev, 3.13.15-debian13-dev, 3.13.15-dev

Index digest:

sha256:dd14beb38cfee3decf279bf0e7e438aaac23f00a32c7cd6f2e999e19c29b2d0c

Manifest digest:

sha256:94765ba9a56a75fbcaf2c99d0427969c14351d2db2cbba7e951e11b352a967e0

Size

38.46 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
1
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:ee384bc82ab4d63a00b1ab820e7bc5230a625103d2af9585b7b46ca3c91e58b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:91d7e00ca7084d93f25dce1c6d10fc13fb1752498fcf19c868670d0dc794ace7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:1c27baa1ed0529ebd3dbfd22411f464ffc665a355b4b83ce41e026f8e474b104
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:dc055dc2691d29e864539ccef9afe7f7a521fabded75969e5f2d692da8fb2a89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:1a52835ce4909d3c54d4ba6a08c8800b21144a34f59c00207f2ca598f6cdd1b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:63b12179b1b66dabb71b6d79580b61b568162e81ed5834f12d5a1a22f9e4a8b7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:7c607ba61284c46569998770cac862c67925d694a246c25cc65bd8189866f2ea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:b462eab33b3be41d96a6c2de5136a254f0e983f3a5d5559812e433f8a7a8777b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:89b6c7feba5983b05d9679ebf0fbeb7ee0123393874c1c5eb9d4c6ddee0c2bd5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:b785e84c90cc265c4654500dd29aea9517c157151d21856d353c8e073aa29ce4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:11492deedb2b6fec7c2bf07b7b14acbe2b5baec0dd1ca8ffa3522994eacb9bae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:8433137e8c960dec2fc1f4424bf16d400f35618e42ac90900d9164f082d9117d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:7176989d03ac371b0ccf1bca93cf23d0b4e7599499429ed3c5f10bf746b3d2b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:2fb6870b501580e5ebb50145ea5ca738bcfc1b36c5183469d361753acfc81d0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:e08bed96c7a6e53a9f0054a5d3fe454e909b362a468449f6ee37ad292b6a7de9