Sign inSign up
Python

dhi.io/python

Python 3.14.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.14-alpine-dev, 3.14-alpine3.24-dev, 3.14.8-alpine-dev, 3.14.8-alpine3.24-dev

Index digest:

sha256:8ade3fbda7ea40b3739d8a3c0cc092a02be22bc403f984df41f2ac7764711793

Manifest digest:

sha256:a738e5b8d75211766cfe46f4940f71d8adebbc2dd2759ca17e69802e11358f49

Size

80.95 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:af10809c3901557678738d8e684c0886e6ed00493274c83e616093db49d74a09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:77d0be02ee996e516fdeb1d25ed259d0877e2ed196e8e2833bf028f942cecabc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:c6a804c1a06c4c9b01c28cc3465ca8f62b5b0f2fad5f8213552002282e671769
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:aac900eef2434c7efbbb3cd33d5ccd2a9879ed164c13e0970ccacf09c6c6e55f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:f9c3b25d3326b078cde55363b24028103657207eac452ae09f4b6d7c2ea2a8cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:601984a901b1d298cf4c7b25945c94ee8ef08872557119950750dc421f542ccc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:4e2801a567c7047ffa1d96b611f5ac57fd9c3b5af779305d26bfb35c4e8a83fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:9a7ce606d11f9a3865f70df383eeaa5f0db85a01f10219367d0a885fa6550819
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:ec2fa8575b951678198140317a31d85b5d30072b3a1ac4fb94f23d68877091ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:37c3657e550d5bbf24a03c7a8d081e90f38c4976aae33bd19587e85c8feecdf8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:26983a2aeab7ae063352ec24fecd618e15492ff78d7f20beda5b125e791c1e71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:20b361d421d0823b7e9a2730933391382608e3fad7494ae36d8cfa317fd55c03
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:bb24e982f4923af3a9f4790c701e23189a13ed664bc407ec933d50c9d39854ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:0ec96e2afd13eb53c56378b184893e28aa7fa03fc8417edcdfc73f79edfbcce6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:31044a9dab886dbb1274ad020c8b8b85b7b160741e8648e3d65f416ec3751b1c