Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.14-debian-fips-dev, 3.14-debian13-fips-dev, 3.14-fips-dev, 3.14.8-0-debian-fips-dev, 3.14.8-0-debian13-fips-dev, 3.14.8-0-fips-dev, 3.14.8-debian-fips-dev, 3.14.8-debian13-fips-dev, 3.14.8-fips-dev

Index digest:

sha256:64a652ab9ea443a048a2fd69b58b9cd58384f62a297b75e3e07db8a845ba0765

Manifest digest:

sha256:923bcb5905aeb25667d4e7f322f1e078769690007f1dcea95c72ec746f14de5f

Size

42.44 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:756262356d65694f871735dba5096423ca562516db8c916ad4a9a2f218cc128b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:d37de4148f64736ea77ba778d23f026f1cbbda351133fd5b189322d499c63b06
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:b24342541062d6c97e145114de73e92a170d4b7ccdceac362e7080e31a84d59d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:9704ba2fa79e0d9c1acc8b063336f6ea718a0fa2197dd5b8925782f3fefc6c47
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:563353061adc7216409582c59ad17d9ff8705760304c2c922b791da4f15d061d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:8b9d3d4e628f2415ea5fa66d24204a3a46ef90e1154d17beaa36a4473fe55af8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:91e16a4067653979e67d13fa6a3765d6463e601c422e70264af1c858eff4992d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:440441f0860e3465baf60914a8cc7a4e233c7ffa671e0cacadc1c7eef76ff1de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:83554839e37b5c24a31be9f190d997ca6aaf800dd71e80c6fd1e7c0fa1f95819
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:1cee3674350bb944730d56bf9bcb38b0d93d922a6b1b13cbba7cb1c90811efd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:b69557b2177a7f7e8f49cb77a247016a00340cc3d03e87ce3134dfe8025d28ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:30976ce141e8b8daa7c6b413a11025450811805460e040624744543fbcae2c56
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:0e1c027a825d4c34965c5c832b70bbf63bcd2750c0b6ea5f7f9fb27d985da85e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:0b55b794de693cf230019a44a48ec5f9bd4c8da4ecfd3550adc5d1f53b5e2d1d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:a5a2e3523209862e08097d1d5b1f6f23e4866bac95a742a1d665e0dadc41fc5d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:9b833976b6a2c01352a90766b2eee3e805fabc189c3b202eb92a6d504cc1d20b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:8e6f96adeb8cb7bd905fdde3174b812bd1822b6bb82de8b1bd870e6f9967c7fa