Sign inSign up
Python

dhi.io/python

Python 3.13.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

3.13-debian-sfw-ent-dev, 3.13-debian13-sfw-ent-dev, 3.13-sfw-ent-dev, 3.13.15-debian-sfw-ent-dev, 3.13.15-debian13-sfw-ent-dev, 3.13.15-sfw-ent-dev

Index digest:

sha256:524a2cf0059cf61310d8424fbd1a1f5ab7f2a77a531f85da44c77da179d2fa9a

Manifest digest:

sha256:623f6743df3810ee95794a3b346e66cfedca3e7914ca16c1cb49dfa9be5bb347

Size

75.79 MB

Last pushed

2 days ago

Vulnerabilities

0
1
1
1
1

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.13-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.13-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:d600aa606e827ac71bcd206aeab2d7c41779082e3c977785e4d91fc419b61161
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:f31d162cf87d576e0ff1c7863d76a8da3c9c24eb075823ac2ba0f924591075dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:f0a783c10dbca9ef58fb8d710d21d5d88777f38312ba19e05704ee500ef208ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:9ec4e26bb8a516b8aeaacafe4bfc14edbdef481f92f569349f6b8f2ba3b90235
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:96f1bb7d9c723cdbfa293601ea6c3193a34ad85c36d51f691b982aef9f9efb03
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:ffb7ddcbbc1a429bdaa3320fafd62db0dbed4ea8d8921337001c271bb3c2184c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:c3b799a911a6771191f6f7e252727b2d42f850ec72a7e1ce4900ec02ebc4d8aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:f9b26f2b362d27d1ca7742c5f75b974453a5fa1647254d8f2f3a921aaee63f2f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:890c10d3aa88bf71a5ba10d1282155f9b588cb1403d8b8eb06f48c730a0736f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:50789fac6726574e463f8cd6d91e59cfcbc554fea5e148273d4f84727c19971e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:3b0d0bebb847bce5c9b5ce2763c29ff3e56f5fa19a7911329e65d02ff7e85421
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:14a772a1638d0db329d6d21b1aa76b75b53185c3ebcf3319ab0b5c6609c000bc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:b08e5887365f982cea7c3497368c44ce2fd526e1035741aa6f4e85ad12b6cc97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:1c2bcf3529acd0c95752854bc5ef313615872d32a713e147960dd6ca84b53598
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:000d86e74f83e2afab2e8ee86d83d9a43bbe8fe27088bac6962b25723a460e45