Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-sfw-ent-dev, 3.14-alpine3.23-sfw-ent-dev, 3.14.8-alpine3.23-sfw-ent-dev

Index digest:

sha256:b398fef6077bc20cd083c4c2139a248b719de0290528abe03c1b1a51bbf89fe7

Manifest digest:

sha256:e93d26d88d1ceb478e151211f8d1a3fda2b0d74123982a3b7ebe031a70895ac1

Size

119.59 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:bef308e437184096edd82302d41d26273e00b68097739351d8396ef49529551f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:8762fbc97ad63145da0d1861e7a973a9a47a3cde6ecb94f83e93e143e43b201e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:33f93b28af00ed9396af19da93f92ed70e5841fb31682289c5f81a4f4861f408
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:c97790bd173d5c020f9ff8fcb0c20d4f5f40aa5886192f04a9db7d63211b14b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:0aa0c033de50e27bc088e500475b7311af0e72ca3b924358ec33ff89d176bc17
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:9660c1344121be8b39b7a0637481f9816f566df2c96fb0429ca84b43afbea6be
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:afd422c448892374b6c66d9a66223e4dd3beb3790909de10868dba6133c374e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:bad02591d1e086c6566bdedbc1f75ac64f17fe77ca48376f48b0a773de71376f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d10b8365fb2a352793d66a4c8f456cd58a3ce4c619ee5278a8a62736fca21b44
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:7f3c0676f862d8b18a73549ce58a7f5c8d2f1b9f4e2e9137e523c55f6165a90d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:b613929ad01bd20fb5b9b8baaf396bdb8a8a2ddb31fdedf7dff165324e2b8075
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:6985b8ca09e77649aab7d20c2390b6d83d830a998ff8cbf86644e6bda6224260
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:ec54f38cf386ea071812f3400c941d5a4118718812705b71894e4f1a4e56c998
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:ccca9efcee03ab6b02256445b459c515dae0a343417671563504985c0205723a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:1f7033bafa7a0a0a447c61b7a8bddd9099ca61f38a21e3ac2663f439b8b6c468