Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-sfw-dev, 3.14-alpine3.23-sfw-dev, 3.14.7-alpine3.23-sfw-dev

Index digest:

sha256:e03288f1a845a4b790ce7a4be9eac2b5e9d841d7819c48a71e981318f953a922

Manifest digest:

sha256:1b7cf1e7a87929f6124972e426da15a75c2fe679567d79eeabaa70a63abe18f7

Size

118.80 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:2ca0b2163293d41ee9ee0de1f6f124514b4d100eb044ace1ed4feb7679e0ea6d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:9c085cd1949f97198d9168af35e499bf93b8515753ed227558ef2759ba59ce84
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:2e2370bd257cf4dd8cb59e0dc73a6cdec0ce8c4938766cee0841d0f1e3b3bf54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:a65f8b199a22b0329607e16e1c7044e3feecea6393996f315361b22fac85e081
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:772de94cbb99fe7a44fef76765ee8974405cb3a603b156f51cab3479a702bca0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:9047469c2ba0b1fa555cabd376be904120653e77bae6f627112c599847b92f1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:344ca9be037eeb87b1674cc442d4a335ae502a18456aa445cb596c0618df860c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:f973e0de744e2bb1661df810bf106e5f8e2ceaef0d769b6fc8dfb8251002fa79
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:ba97c2740b475e2cd531d05956184ace15881f67d38a3a1646e1bae640eff304
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:0edbb68929ae0954c5e1a992b29ad7dbf5a7e0e45cf226711c811466d52e473b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:ff3335ed253e59a4514d4b422e8c0082788c01230dbca23fc508b2d9cd3f3142
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:7dad77c65b30fc7087b242c1e792b988de6231ab26d51dd4da5bd49dd7dc22ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:a30a6d84843afeb68ac3621363eba015c974d37442e8a69f19dc8bd887c91972
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:3e1660dc4e94eda1e1af08dcb209ed383885ebb2000b465ed687be8723ad69fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:e9b806f76f7e073a5fc32033c86af225f9de4f761a544661a0cd2c9d65c7f6f0