Sign inSign up
Python

dhi.io/python

Python 3.10.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

3.10-alpine-sfw-dev, 3.10-alpine3.24-sfw-dev, 3.10.22-alpine-sfw-dev, 3.10.22-alpine3.24-sfw-dev

Index digest:

sha256:f36b22e39f2a9a9b0a761b3de8bb1ee0291abcc31a94e2bbe4016af6796a54df

Manifest digest:

sha256:0e136844f41e9279d9f835907375f6724204305bb141a0a0c73dafcfc5aef37e

Size

118.49 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Ends Oct 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:681d9806195a20d31d0a31a5fc5ba5bc2e7abf43aff0189a00cd55a94807b997
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:c2fa64a743ec090f6e7398973f1a046157daad6b81770491a3edbd577adfe61c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:47e79bbbd5e167c3501c5b28d3781b217ee1757260ad371f14e445e32dd479cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:e26b6e7cfa59596f3ce593f4b754668c25bdb828ee07c635221fd25c5ddf3ee4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:4bbd4a9b8a7d4554f59c15f7e98f7d30c4a04153706eb2ef4b65ab013fd5996d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:070b61f4d38c60e0fab8e20a6e9c66e39ac3cc1cb402fad1df851042b63dc9c7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:c801668758fd517cbc8dbc20e2826f330df34b6f10eed95770ff2a00efc149d4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:466adda45196e8833b9d8cdb5beb7998dfe35460a34be166d0c31a0676b707da
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:07436f2fd9855c355fab0ed54b3430def30d49ee49907c77e7cd6a684e0d47b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:5fc0ab0e3b8c12185a01da0f92e63e19ca19bd67da886ede19666e7061aa2ae9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:8a7a98ac3b7753f09fde742df2c623942ea092bdc7f42566cd18e88801375dfa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:400788d2fbcb5b93734c373040190076998353aad6ee130ce12a63926ef35fd9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:eb1cdfb8df558ae0a68f6ab66b99c5206307bfdabc63e173c56bd0b6cc078c57
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:95be93f4f6882cd813a1613f0828f66f18cea49bf3b89d0d789138b92816bd35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:4955ce8e59e27ae4db08bb70f45dd823aacc8cb15fc5985728766cbb18ed9f7a