Sign inSign up
Python

dhi.io/python

Python 3.9.x

CIS
ELS
linux/amd64
debian 13
Tags:

3.9, 3.9-debian, 3.9-debian13, 3.9.23, 3.9.23-debian, 3.9.23-debian13

Index digest:

sha256:7172145e0baa75875cb34a394cd465649389a19cb7eaf6898641a9289337f058

Manifest digest:

sha256:63b5600981d1d9e3f67861d413af87e92d85c51d4aa7bc50f3a2e7f0dffcc0c2

Size

22.58 MB

Last pushed

2 days ago

Vulnerabilities

0
1
10
2
0

Support

ELS until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:a62cf24f5ae13db2cac45376fbecd324d9d01095f4a6b8124092967dec42ae6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:6648a1e4e2f6e764b07ba68edc53b38a08947a73834c78945f2e44cb44e62788
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:2ffaae1b5dfde979f487e09a7adb7621008553d2a8f838267cd11b8716e5deef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:05746a9c8fa026fb463793586a825269868b42a9a0a5c33d7f47dd58e99347cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:d90579774ac0469463a2b68b805ddf7a2d10c0896273bf442a2d101ac66996ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:815f5fcbc4030131a5312ebc79ef26f4300e37b65cdde20251aba067b99c629b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:01ece72749a79dd05c8160f07d5aaac2beb1398d8c5676a800e155978a54a063
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:3a9cbadbe191261a9bee2d4f99894bd8dcb1f44ce92bfe998b76718ebea793bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:03365414145c0404edd8af9c1b605727257cc74175df244dd3db2ff72b62f29b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:40f0cf57fce49ecefb19577b86c08eb59fb4f85e9f162dfdbdb7e351c90d4ba3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:b335f9190bb722b1c6a7c59fc3a3e66192ad5c21586ea88f17d746064571f426
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:ea2203e20490fd0f33823a4a7c85d034d4eaf94bb37c659754740854b0e3e6e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:3ff14038d1a7eead49b1ed254eaeb9fe91316d7e381b3a0a068a0efa9a07da8a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:a31b638e05519dba81bac2898cce2f8f25928094ab6d747abf426c06197ae7bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:3c650700e0c4380f127fd04e85ed14d02551fa85a556d8dbf16e6839bd2430c7