Sign inSign up
Python

dhi.io/python

Python 3.9.x (dev)

CIS
ELS
linux/amd64
debian 13
Tags:

3.9-debian-dev, 3.9-debian13-dev, 3.9-dev, 3.9.23-debian-dev, 3.9.23-debian13-dev, 3.9.23-dev

Index digest:

sha256:895f65f17abd8a4c656526f49db3592f59a6c4ea6fad5d0b5423f6fdeb7a3aeb

Manifest digest:

sha256:3c8c7aefed44575114b2ee69cff873aa7d8b63a92f77932d585210eb1d3b8749

Size

37.95 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
8
3
0

Support

ELS until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:48dc854033bfa03bba9532ab92774a1bafb9836d727640e09731e1cda1b104e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:ac1576b9454603ae42acc14a87731b3bc60c32cd2d57ba458400c852fff40269
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:af8bd94e8e4465495dd2a4b50cc80f7f5175b81def4a594555d5e82684a29c2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:6846b9a7962842dd4e6c06ac9eaa0e5fcb3729b44c38fa3cc2ad6a8b7cbc613a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:3e8d77a4d4f34cc9ea9924bb5351d43000dca043719c069f38bfba165c42c626
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:22d262c800f06aa77a7e2c8186c235cfcc65ccd6dee61601047fe24b99e6f240
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:f6d12eadca2bf0a28b0d4ffd27866129e16b1cd723bb690a3c4a49d440ab0bb9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:17a05837ed60f1adb06144dd58c7c109c02826d6a9eba3497f00f53f99e9cf1b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:b11651db6b70931f4aeb9571de007f5fe58241568aca3af432eab004e7cc16e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:aa949e9a9eefc2790695a8aeea953d6f73bc2b3a1a80c7a8a1d62ee5f02bb2ce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:614774b58291ff8fd9eb84271a7c56392b6af5241b732540a5640a5b55aebcf4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:426f41b4edd7057ece401a6acde6fc34e1b2a197b9cce21503c237a0ed45069c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:dc0b2be76f5eb4f809b48cde7f45fd74a6665a6276ffd8af5fa606ea7966e803
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:a18054a90762c5d561f73345a8fadaacde8a956d4db34f6ccc64fce47f8614c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:6214f1bf8c970c240f795e0f5b2d587454336dfdfd3d63c7f2c5e23fcb7a7d08