Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips-dev, 3.14-alpine3.23-fips-dev, 3.14.7-alpine3.23-fips-dev

Index digest:

sha256:237acd99e07bb90fba06d4bfa6f75eed32cf0f137320d5a0be5ad3f86e5be62a

Manifest digest:

sha256:1d1e84ae514f843de042361815ac234b30ea962b945c3446336b107c26f092ac

Size

134.48 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:2d1685259eb9d1bdb7ec8e0840077b4d24f9fd603e96975a70012b26eba9da0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:4c6feae8d22ddd7f9d3d4e1f5f114769d71bd4892d6c209a1f6d8e69488e70ac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:1b1c95a338327272e926d9da9024ebb5b7f2ba3dbb87ca291d241196f32eb1cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:66f8df334f81295318b7c1e23cdbbe0dda68042e32a5f7e1b7e9ee545e4f50bb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:959ab4d1b56c61727072bb2faa7c8491bd353fd67c2add3c035110731799260d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:0889a51213d1345ade3c3d2b6415c9cbc2931462953c105ac87138f3a2bda643
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:732db37d8083024175c9b8bce249bc5872781fd3cfff6541a6c35a762479f849
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:30bf982a485e43116e21f614af47ab78b0b023958fb56546d07b16651ecab4f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:01b0fef8cf3868c171dd4d322d2a2ebf3cc9ab81a02468468b8bcaf4eeb19512
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:3e3ca685184c37e272584047bb5cd687199e28d5951528aea5e217a540344bd9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:0e5fa66f93959cf8193bdedca7b97d4e8f408248d4e1d61260e67afb92e58495
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:84fe24603c2b8e5a4a60d01f95348248d085172e60cda9a04eea54f06783d69b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:38f585c91b42d069ba4ad486bec4978d96f419240c023fbbdb28635579f0f5b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:cd520d17a656dff39e33cfb03046c6ec80e26afdee6ddd3f665f840914185a0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:69938e9c42dfea245f4aebda9af3ee543f6932319b38a53aa09bf6ce4f6c7550
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:df829a51f92338fc175501ac8828c8aff5a988de41d655e998e458720855ba37
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:f9c73f96d14994259491dcb421a14495bf304abf257d6f0124be68863027d211