Sign inSign up
Python

dhi.io/python

Python 3.13.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
debian 13
Tags:

3.13-debian-sfw-ent-dev, 3.13-debian13-sfw-ent-dev, 3.13-sfw-ent-dev, 3.13.16-debian-sfw-ent-dev, 3.13.16-debian13-sfw-ent-dev, 3.13.16-sfw-ent-dev

Index digest:

sha256:44b17c99bd2d25b18371b9d27888cfbef070921690ed5f8ba58e2290e8cf3716

Manifest digest:

sha256:ca83a10a8dba003ab719d73cce5742bd1f712bb70eb575479edbe9741c92bbbb

Size

75.74 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.13-debian-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.13-debian-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:9e7279285b620162fff85469637fa846ed1eee29204881674364ace048d3339b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:0605fbfde435b084e15fd960c1086354aa979755f6d32266e3be0d7349a1dc39
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:24160fc822da781e156be1b0d4ddc4e174556eaa6d1bc6fb5a95e28a5c1fe5b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:c037cfa368fbb70f13825d5c15cd832c1fe5aa35b1882ec02e140382d2c7ea5d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:e830fe2296291160901c4287d227c6201c305961486e5f642f59ccda982a2eb7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:54f007bec3a992b9e3bb74cff35168db4daa3d1457cead4541b135826f4b7555
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:891044867c3dd40cdc4915af66e4f603b614ca4ef2aee8957266b1f10b6f792e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:dc9f15df91b8f4ba8697490c2949d5ade00d275771b59eeaf41f838a71fea45d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:131caf935fe45e85c2f3b4f38fafecb0681c6d2141766734275f826f09dd7009
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:a5efef0132c536bea0aaae1bde845a661607643084b1545fdef62b92fd0e4cfc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:7a6551df671c3fbb038a9d31b2e0025ab6dc6a993a10028d5afe4d4b5cc9e2b8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:8af55d77a5f246b0d8699a7f03f564a69b3547829a12f00a89527cc7099676f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:34bb4e1cb8ee075d6899f10b7e473a37cdd3f7679283a5a5638fd4e57a31ea19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:230dfd63d7ac13f941e99c253062761b949fffc25669329c379dda323e2d63b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:21f395d29dfaf40911bdf57993deb1b880c6d324cdd478abaa0a535f9bcb8e10