Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.14-alpine3.23-fips, 3.14.8-alpine3.23-fips

Index digest:

sha256:bff6fa28b845a3148d9cdd5560fe4c58f6083726561a7a4c238936a75612e340

Manifest digest:

sha256:944ad2a7c21daceea686f997da285e20b730a5867cb2ad149b8271263d18476b

Size

18.79 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.14-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.14-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:d1f7682039d26b08c311eafb75f0368fb5bbd8a4e9a6a51c17b307850ff0da64
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:6fc501c1b4404917efa8886bf1bc60e5b96bfd8b4400a5914b45378ca8bdfd60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:664df13fb5fb0ee255180b6b339152101598a03956e416d66f6dd71b686cca89
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:9596f0ad310b88d468b8cf3d54e8a2bfb07159fda58f08884c3c9768b6372c6e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:4d86f0fead309ef662b488cb70f62c86e632861cde03a1d6b4c36ef3cabc032a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:2e85e8e2ac45115089f066d84eaa4ec780aed71ccb8bd51a48fee8bacf07e153
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:91692b8967d4c7ab1ffc0a846f00c81eac8d754c6c40dabed792cc7e732d1bde
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:2af341691acc3a2865f8207ca4d4ded3f4705466ada00ecbb37a544157b3f5ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:680ed341d65ef847d7d32adc9f1d2b5032093b3645f277353a62f84b9f62d575
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:cf0b642e4f8fb2627b379afa025516dbf4b834c50375b8d203041ca18a6f80e1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:09d26317dee324d1734360abeaa1a9111699383b44d73f9919cd34caaa4a2bd5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:795ad59b932f7e276ff1de78de3efd7771e85bb676c4d504f9277f288e816f69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:bdd9c088ee4f4b09f882a994e3b675efa3aadd575de9f1fc5654c46a1eea1168
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:01c1bb2f325ddf66f89fbd9c310cbee4f04a6239b044d50f1e23f2b4c997192f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:cb8f7779678177a7deb4d65412094caff0638c37ca0787089c782458a177fe46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:33bcf20b5cee0bb6a7b6d673749fde0df9659957c56570a37494e9343908a215
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:d5df5435ba045fa2bd71aa8e7a1804a89915fe11cd693a519ce67ba4cb066c70