Sign inSign up
Python

dhi.io/python

Python 3.13.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

3.13-debian-sfw-dev, 3.13-debian13-sfw-dev, 3.13-sfw-dev, 3.13.15-debian-sfw-dev, 3.13.15-debian13-sfw-dev, 3.13.15-sfw-dev

Index digest:

sha256:a42af839d5ad52c303572f67360519492f45c1aede31fdaae5f33c1c03577739

Manifest digest:

sha256:a2c5172565970827ea0d45176ec5f1e19b95dbb54acbaa5f09e3f33c963cd738

Size

75.07 MB

Last pushed

2 days ago

Vulnerabilities

0
1
1
1
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.13-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.13-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:bcd7cd717090eaaa5b7a7cd8a67e61f073fed125197b00882813c4e4a855a3d0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:67324144cfd17d5e1e37a42732c9f230d9796a71eb06b79bb0a97395c387a446
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:c200bc09d785930afc63aaf2444847d28fd7194db590f7a5e455b1ad34c8f2b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:e258a943645d215faa1645b23b0c213217bc29b4032ddf87f93ab6f5c53711d2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:8a3e13a24db5f9df3d23d8b0db5e8c047fa6687cdf74d7715bd5f4d3a1eeb802
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:d909b40583e876bbfda61e936af13b03508b3a8fa79651c0e467974aa6b57184
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:258f8072ddafbd1904ed708822b9e0597e4e4a6308c26b07ada7f2817ef18a9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:bbe1e6cd60b2eaa0443ed580f475ff864a6940ecba3fb5052ced66a278f24287
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:f8e7b2ef0f4addfae4340a45f8691d93855d23acdefed267e4c1b34dbeaffb40
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:9ebc3a943eb5c1d158bd19cfc8faf90f1112bab2ca69f2767fe6fac9653a7ade
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:3e1de292076260ba3a3d69353985fb3e995e66c898df21f72555030894b5f6cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:b5f24084b62bdbd0253c52eb85a0d7ab70463bd002b079fce2cb184b0eb6e549
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:5c5ab18218f0380693f9c2c52a1135b0b28eb416ab959b45e789b1158886d8e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:a28a31324b91557dfdda62ce38a06422c0eb0ec7b97ab629f8766a81cf8d1ad4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:26fbf00e5bcb628d5347d38e77e3590cb7d370785f40b721244a4ee8b1dedf86