Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3.14-alpine3.23-fips, 3.14.7-alpine3.23-fips

Index digest:

sha256:71a820f4350e7c2e5ad54f7f7b4d30c8ff720f7088a3faaf9d3d1126956f5888

Manifest digest:

sha256:e1698b3b99b16d11f23b97fc7c5b86ef7f46793ab1b89382ded0a62b750e5338

Size

18.75 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.14-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.14-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:479e721bc4b0d6e7a29c77fb7c75d0b2c3a98f771d25200d27e54da7964c53cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:2aa2fbc6ea7004665c334d2c013240b07c30587502b0d7b503a2b2cd93400736
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:939fb645d71cb9f26b3f7f2d53f827e48d2da42b88582e691704eb0004745e0a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:eefa7de86130c8159369e4004bb3e3b04f4225a33f697477035fae382d6f1559
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:1cea1ce42f9870a176f4a98b2de261cfb71180eb27e5feb52287eb0e63557c2c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:f366b010eaea6139d35e6264c6fc3b192a72ee98fbad7bd5f6fdd4b96d7f94ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:856f89df1de13a9bad6dfa5de3d0c88334b0fe527c0a49737a6e46a374e7c8ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:a3c7a8a0a26e0099fa8400722b065991f96cb39dd34de2b081df135f54830595
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:60a1373063b4e2986e91b297c1849c81b13a900b4f41bc1583bcecfaa92c7442
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:86216d965340c63f492a9e33c5a1c1bd7576c79f2fb5d5275f6b4c033da8d274
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:4488eb8f9b0964b8d4391a02172d4674a4d72c774b414d553690077744f3e954
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:844ee70d620d2061544ae02fefbd707d0451ee6760d87a7a53d1a8ac895e086c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:f9399d1643dca60c40e51aaa48272ae549bd2cda7361883355e6d4b85db664af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:66649a2cc07dff0e88cf925ed920f303faa9cb6ab6d18d9c85d35cd19cab70d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:6a09c55c15dba22dc526d1b5e341a517c28a0c201187937b2f18c533fee45f0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:223f6036ad73a1c413349c790575f4e6d78bfb1127105082a0b0af33510802fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:5f9f58bac80bc4c393bda489911310b7353af8d5b602f1d0d592e7f253974a71