Sign inSign up
Python

dhi.io/python

Python 3.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.10-alpine3.23-fips-dev, 3.10.21-alpine3.23-fips-dev

Index digest:

sha256:3605ae722d18a804bf657a3a5e60f0275973ffbd932fbadb281448a3de750249

Manifest digest:

sha256:b2bcfd090787add0b041342f266c7aaee74b269dedba6d4039fc181b34878308

Size

106.93 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
4
1
0

Support

Ends Oct 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.10-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.10-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:230aedbff013b441d8a2404487d6fb0a99d6bc24978c2c5994feef1fe1f6dce6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:cec040f6a1392b0dc2a73fc60fd1c44c347be284cf9cfed76ba44432bd7b3634
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:3a5f01e76443ec05e6129c3fac8a86aa9038f478ab0eafbd5232a2d6d403ae80
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:80cb5388ed7285da2672fd0242c21bc0edeb86d8db344ba08530682240f79213
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:e3a780269ad9450098ef077d4ebdf2f840d90b2bbcd2e84b9aca034aaf9b5ccb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:11d027a583ecd021231dcd3f8fe3c4e66c3e6784e7e6b89c5a57055c8278f66c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:ccac761701cdaaaffe940bddaaadbeb801439ca118d12b8317770aa05323add5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:da9ce56fcbf2fbe8a1e8776aa25836858d0b80e725e497eabe9466381446fc83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:0638003b78d86d7aa73c65f5b68a366697dec712f95ad235a8ff7144cee9bf08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:41f5a968b5e05ea8da38b5ea7711680bf85011debb7d8dbf5c1224772a472e7d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:152d1ef45e3cada1000a833cdd769e4db94d31387f97a22e3adaed8ef9605cec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:8e21148c53560c39f78afb49efb7c34d19099b7dae394ba5f055f771e518c321
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:3adf568a68d9978c86eeb3c8199582a2966991d715bb98049e5f290a08acd8e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:c5be3b3059ea293434c9e25a36bdfca802a3c16c1fd054749e348095d824217f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:2a2b180024a3286280d9806d7d76d79369c592c97c8aaffb5a9a8d6018c81081
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:c3849a17638e35a395dd2f1bb8bcbb4f174007ab14056094aa4fd8f8225c7edf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:8d8d04c27060398979d13f78edae2d5db1f7024bbfe8211ea500327b3c603dea