Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.14-debian-fips-dev, 3.14-debian13-fips-dev, 3.14-fips-dev, 3.14.7-1-debian-fips-dev, 3.14.7-1-debian13-fips-dev, 3.14.7-1-fips-dev, 3.14.7-debian-fips-dev, 3.14.7-debian13-fips-dev, 3.14.7-fips-dev

Index digest:

sha256:dd22c679d29cc11c54c1b8af00b15e91bf11694ea1e5bbe46e223f58fe2455bc

Manifest digest:

sha256:1b17de5eff7c54f5d21a749be19fa4fdbe166cfc64887ac375b5488713eae8ab

Size

42.41 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:0415a7ee202b3c04eecf8137373295d90a98dfa9f37139fc1dcbb4ddd068bf87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:e13d630cf474fec23870f64fd6eac0c486e37297041791a67b9c429bf2e4c6e3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:a732f18ca1c65d5f5f811a93ee0cbe3f53caba5bf5cb8750399b67885bccb18e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:40898ee17f87736e5e7210763d6dbe05104d56c4a2dda62f9adceaa78090a2f9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:0c23d2bb3618ac076c2218f7f1211e94ee6fdbe8a6635df3f2bdf168efee649f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:e7daae4c3e5574b3568d612baf376bc105cd8f944d6eab01b58774abb301a875
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:707fc6ce0af49ec006ec606de896edea2fe93815a3e518a70ba681705a5a82d6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:e49a0685e2e47403a96824e87b8183e79464b37e7054f1a2b8d2391c906e8fa4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:024fa2be65178d880d312fca47a5f23473a043c8c71b0bfdbca44156f19892c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:62f8f35aaf46b6cc0fe4ff421f34f96a1c2f8f01f6ca22470bf4eaa406499cf4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:7eeccf6eef60d054bae08b2c01ff63d91493f61a3861fc90e8dc9ceca7420470
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:4027db91804e4d9d9b21efd1def7c37284d6f5a5b6ca6298d1ac13503627fd11
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:2011b0e279f13c9157591b7ffacb88271c791ca4df73c0a4a20bc40e63975d54
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:a6aac3d331494a3e55244e0b78a792be0cdf1ae8b5f6b5e5a078ee48a016ad34
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:e5bfd297f1baf8b8127800e1f0dc39da35c1813b87f75c8e30811bc941fcb270
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:70393f179c1cd38af68f1277637fdf9fa3d8178d6b0cbfb83e952de9d2fed844
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:2792624a3a750b3d53ce5beae22b9222869363550819e357ef00b581ea6c8f16