Sign inSign up
Python

dhi.io/python

Python 3.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.14-debian-dev, 3.14-debian13-dev, 3.14-dev, 3.14.7-1-debian-dev, 3.14.7-1-debian13-dev, 3.14.7-1-dev, 3.14.7-debian-dev, 3.14.7-debian13-dev, 3.14.7-dev

Index digest:

sha256:cc2a26e03005f5eaa345a34efaa48d1c672186dc27b74bf566804ce7fd5b8afb

Manifest digest:

sha256:476593cca6e045fb4f0ac9c2825130ad6103d36297b9550fb741d25b1bba0a14

Size

38.79 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
1

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:668068e2b707d6881856286bfa65d67c40883277b80665586fac31734a0b5cf7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:2b5f0e27534a4d4f85456fff9fdb3d537d7d494a82f79ac5d9bac287dde21e9e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:47df65de0a346c3d80abf8b895228030c1729d397f4e324b306802c527aa36ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:1aa5bb8115f8afa93e02df31b316c25f59c8b88bfc9e96e310ead1133508f68e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:86e38e31b06d466561699892402940121c214e3c699799a0de2113372f3c5241
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:0b0dd7456d9a492ad560caac2d9e08d2f8d4a867d082927cd5a26fda3e78c1c1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:982ffa8486fd3fd9d80e6c52a6b0c95a08b2e9a9c5929711954c07e1eaf30af9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ec6d1d4a736e035678ce05381bbc48cfd1479c829dab5803c7593fc332d13043
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:4c56afeeb4680a565f5738e63f52824394ebd82b710dbeb7ccbdb934fd9b7408
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:ea4c63bf0360716482ca443760703610350205e7a7957966b0bc322860a994eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:bfd612c77ea598bfcc92150f8dfa1bf998295689aa12a65406f38ccae85a2881
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:5b939a5e4bd8f10981662fd3dcfa80ebf08d3e4e89e41e6f8ebdc3b7d5d91bd4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:120b1e043ba376ae8cd1bd4ecc587a3bac71d59a26d0290885678a1546cdf774
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:abfc6dbc20e8ef0f900d7384e20435121f000803c57c1f6ae7f28477acd7385a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:cb445fd06a4e76fe0181c9516117e4d56904e8925b074b31f28ee67b2b90ea30