Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-sfw-dev, 3-debian13-sfw-dev, 3-sfw-dev, 3.14-debian-sfw-dev, 3.14-debian13-sfw-dev, 3.14-sfw-dev, 3.14.7-1-debian-sfw-dev, 3.14.7-1-debian13-sfw-dev, 3.14.7-1-sfw-dev, 3.14.7-debian-sfw-dev, 3.14.7-debian13-sfw-dev, 3.14.7-sfw-dev

Index digest:

sha256:b57204c4062042611eaeb215f247b0a2aa5d60e938f03c048176aaee3eba8678

Manifest digest:

sha256:b8273be7649a79ef2deb7782c29edc9beffe7140496201aa20dce335da550d46

Size

75.42 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
1
1

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-debian-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-debian-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:c349108c6a51c1903160078096c4363a3a5acb9b6648c730d138b6bb184527c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:7ff9c6490689ca83d6e939d6ac1fc31217367be611cbaa03ed9d88a323cd4a5f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:26dca591ac699cf02faa0a09077f9cd5ff8f07c9db4bb47022dd10b0c46cfebc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:d0bd7c52b0cf08f13dadb44c640e005b06e640ff1cca9e259b1bb66bf2e0e447
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:c1be5676fd7cd2b609a004f80cdcdac7450a55ede7130bb6c581b0c30ffd9fab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:1243d381363f39db07124300978f0f781f58c94317719ffe534be605f5bdceed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:5b215dc37d556b7d684cd32641132251f06c8a9a00160fae0594462edca60e12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:eea43d2d88762bdcd84b25b5be7c0aab80eeb1c3ec06d8ca101df969f7de24f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:2f7f8c570c3486eaca71b859f261404077a560d37d38183c823e5d7380aef184
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:510c1e7c46b9a3604f2e4c0c437856d6aa09161c9279dfda01080564dc0c581d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:56724dae059e138e859436a9dbcd420b36683e810aec9b46564c867e1dc6e2e8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:a85e7f8ef5211dd161771ec3d0414ee48f58eb095344a2c76247e2930cb805d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:e72d844d80dfda27a0a28b7bd96c56dd0784975b3c8689da8300e91fcddd31d2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:58dfd6c17c97a9f0729eb4ee7cdda7c34ecf6cd35505bf2d079fe4f52f879aac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:af0a119e5a0800b47271a3b0269c1c918aa1434e7d1e8156aad1e63a55e96523