Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips-dev, 3.14-alpine3.23-fips-dev, 3.14.8-alpine3.23-fips-dev

Index digest:

sha256:79d089724233919d14c7226a96c75b4e60a8ee49d8141bc62f64b680986f12a6

Manifest digest:

sha256:f15d26738a09507178f732b3adcbb93c13cb99bc4f1c682afb34afc8bfed6d81

Size

134.52 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:2ec2c50a5a7e52d70d27ca4968ee361af946b814c57bd427e81c4474038a5204
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:44eca63a6920a68a938d24ca88340098454c60b412ce46cb187a88e3eff089f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:d5116fcce4adc7fb101888382b6045ed5560f0f06d6a2e58ab42d38f50f01299
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:d9f86aaed70865bde1a12005d6c14f6705aedcb4cb822646fa342d2baf0aac30
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:f07f5c057745819f113e4719fa81182b6f65caf5e535dc78d70cbe6d5965e855
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:501097d766c93e0a10206bae8fc121af9a9372be1a9510707ab2b3b19efd10e2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:f3eb4f74a7a888caef0f00cce2134acbe1142cc6729421db9b1037371442e025
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:cca51f3fa6f1ce18fe604147e272c7fb624e1ceb5d48e2820974526228f55728
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:b62252eeb0dff350fd81aca01cafcee9bbdd9da3b2c6223386b4792bf8c771db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:9eb004c23128c4781b7e5680d98a7bb93e9ebdff7f974410dfe79f114529b321
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d55ee9d6a3b8bfc9a6a162e21e37138e52a8ae50005d8d0db68bcb12ec55efce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:894e87fabc23c2016bd7c3dab8c8511493c34b82008e771c76053c1e71cde6cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:4ff4617c1705108a1fdae9ab4ef3f8a5e36bc72adec3fcaf5b0cb36691fe2f18
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:37fbad2ace385c8e68df1137b047f4c565e161236a62ac1690a28c673df6bf2c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:1412b2c0f4d5e3aab652c2e0fcdc569491e1690e2d535923b228056f1e655214
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:b51857ebd7fe70ec660e15777094a3f6d21521200a112a20c2ed33ca0e7454be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:fdbbfd428d0d044057a07ffe32d522622dc839c67b9679958466afbdcbdfcce6