Sign inSign up
Python

dhi.io/python

Python 3.14.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.14, 3.14-debian, 3.14-debian13, 3.14.8, 3.14.8-debian, 3.14.8-debian13

Index digest:

sha256:2af3a6573fdecaaeb5c5a8073ced2d511cafa38b4b1205ee8d4ab820b866bd20

Manifest digest:

sha256:3629601491dfd68543fe32b762165f5913b8c7c8b322d86ef06111499aac9151

Size

21.87 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:cc978340ac0447bb40964e640ef9b9630ec0702af9031e4e0c1dec70deb60343
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:98701bd53f753657c0d385c9c130fde2e3fcaa801326ddc1a6a362b978a62220
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:319fb4b33536d80798f2625962c53c93abbf813637dba504d55f90cb4edb3a06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:d91db2035d481073f3b0a8d838c795894d089d868b50bb67f05bd877dcd88db7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:645c2ceb5bf77c9b4a3658858847fe21f7c378019d56e7351566c11219dfd389
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:db003e49ee8fdd9e4ed385c41f230e869fa9af53ad960d3db4e2625fcb179eab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:34f98eafde47476261840509d39b0d54f978fbdb410fe2ae2d7dd39e12bc562b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:ddddd79576c81a060a8c6fd6532dd7208ffd89e064d8809f1aa70addfe8b2f45
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:d54bdbff9976ad5a0560c5de7aea1fb3615a7709b056df84c5ded70948c3ff8f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:6a4b5361c3b3431ba77de3babe934db099edfc172b977fc4fbd58d871405a400
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:148f1349ac24c418db99c9bc5cacd995d2408b2415eb84a5c5daa0621f2eb5a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:f0e57d325a7d356a9b7a8234112322344e36b98a713d3ce398dbaecf40bb9bba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:0e402cbe38c6d7d567e75f65e7424bac4070a778fcbd5d3c39dfbd9517346910
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:5660a33f3370ea1983a1b00c8b58d53dbcc889b6b3bdfa69376940cdebccb54f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:241b1ff44ee8fb3d04e784531db688f279df3513ee9d7a54a4077937f83e98ad