Sign inSign up
Python

dhi.io/python

Python 3.14.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.14, 3.14-debian, 3.14-debian13, 3.14.7, 3.14.7-debian, 3.14.7-debian13

Index digest:

sha256:71245bfb85e3632288e5f9816dd9fb809e65b10e1e20f25bedf4d1a92b0a4ddd

Manifest digest:

sha256:f74955e9c0e72e6011329cfb2bcb96ecdd53991c63da55276f8df57ca10552f8

Size

21.82 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:de64fbdf6a6fa86f87be72915adc81a87dd9ca176a52315eb773da4100267afe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:9a1f7e50e88c47ed628828270ed3c91cd145f48aa649dc7cd9219f4bd9dfcdd7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:30bbf87bb60914a0b04d630a4b1aad1dfe15b659552e737f1aecc96b173e47d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:ee37945ca5e852bd75aea7917b718ba48a8842b7f83a42fed2bbe46ce1c61898
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:3a7a6e25466ade7df793b0263bed65a217b662a0feef76d6faeb6d46d7e59350
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:98eeaca98d3a6dae794133c28e90e495e2858c5b7addc934df8e0c01f6d981f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:d5e4a3bf71d3d0b46d3e86523b0ceaad5f6bdf93227bbed931a0f5ed3f7b5046
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:e92c21c2bf54a67334e83e03daf164bd9f8b05484d2e2d284bf0d30ef62a67f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:f353cf2804ffd69100af65bd38d3de5bd0d97904e414fda4a989f616b9c68820
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:dc49d26d2e15ed8398b7daa06baa91d27b916516fd8cce525f03644d63490e5a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:34dfd04e2927375b51a0d835c07aed1ba001dcdf61ba0468db1141b85aba8da7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:ce6370cdd08a74621f647a491c3fab3124f6593d4ec005fe357a5d9ba234b5a0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:5da5db7dbe7fe24c00fcf75238202ae01091ee77f71a9bb1c00dac90f83de2a1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:4e68a6d26d15cf03c2a5641f17b74784d3f649e8aeda36a52638aefd78c94120
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:6f63a072cfc7e664726d8c4511e40f1190f469579f3e43b5bbf092e454006537