Sign inSign up
Python

dhi.io/python

Python 3.9.x (dev)

CIS
ELS
linux/amd64
debian 13
Tags:

3.9-debian-dev, 3.9-debian13-dev, 3.9-dev, 3.9.23-debian-dev, 3.9.23-debian13-dev, 3.9.23-dev

Index digest:

sha256:465faff2b5f6a2ec87c66c3cf97f065e517248f26867def31eefd18a335f2da6

Manifest digest:

sha256:e65a400d1d86b7cffcdd0f65f598109f0445765ae670aea161c962ffccd275ab

Size

37.94 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
10
3
1

Support

ELS until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:bdb540b1e59b8735607cb101b02c5ad28abc56d9c2584684863f3e18dd515638
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:6a6590e5d3d367f5c6bd7b9d3ec56f37e46ce14302ce76756b246072fb025414
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:70ccaf70bc658715794a16778a9cbd4b8fa9af433675125f4c4cf3fb4d831036
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:7029df5dfe8d7e4eaa1424c8f0ef951a5e769fe415e766b30d5bb05a5f0c88a8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:1c38887cecec4701545176e10af3c6805f68929e393480b14f9bb12bdb926181
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:8dd09b18d66cd33f5f72394a4f664fa410b383fd5eb6f856aa46fd0c0bb0641c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:387e39b7d1048d0dc360e563dacd2e35bdb2e9fc0d69e4651dd39926b5997178
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ad213737879b07c662709c6505af1d2232db4801c4af8d1ef10ba26ce12c8b96
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:3329b100b603628c8b75b01fd0f63cd211ed7e9b993c6a12bf736b4a8dab2709
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:be85f47b4b450cab92a1a237df2c158ce07b8e48b6d56b4edb466e2d76529e58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:a85e387d370b135506bbc87c89916af25d2688f3ebd26c90ced3edadaac41dd5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:e3b4251d7f5d653bebf87015e68c35d06d8fa836542612e71702db164004dc99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:13a3b38a878f230ccaacb336d0a4ff43a23922d5d88c05babbc3ae29a82a6be3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:8da7083e3069a015b63ac411819bfc654cc544ae0b48afcae657ffd99a5ca78c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:5fd382098ea53dde91f9dd18e8580605eb1a6eee3eecfe269cc0cde3ad865c1e