Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall Enterprise (sfw-ent, dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-sfw-ent-dev, 3.14-alpine3.23-sfw-ent-dev, 3.14.7-alpine3.23-sfw-ent-dev

Index digest:

sha256:7b05208a848545ec40ff10d8c665703b9a46f478a14846d20159d6ee4e295c4f

Manifest digest:

sha256:2d10839873869c202a58ebb04b3054177067f6fee19b274404a4b4a6c3b4ce47

Size

119.55 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine3.23-sfw-ent-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine3.23-sfw-ent-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:c5b210b849bbe210e6e672dc33316942d78ce3a6ccab390acffd558c928435ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:1ddb3ef89dfaf1c325d6049c323d9ad62552fd108375fdf861a52fb837d91e2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:fb2e697900712d2f69a481059b7da9e431a5bf442bffaa4b4a10c5dfde676713
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:bd1aa2d187233cc91c7716636360db7c6745a3f75ba675bde6614d4764596b6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:8585f5cfbf238b6fefa56f00f5f4096bee8752bebc399939789c60c0eb6c0829
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:f26bcd18d8d43dfad1da74483197443b3a85362e583f9c44577c8da04c46ea6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:6aeea3e0f16ea2ab851eff447ea9ebdbd6f75b8d57f0e71a6420057125c66ab9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:8869b3812ca322de2992fe2f40a1e87dbb289f1717f99063ad98377ce47f46f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:76459cf7fb44e03a8f5c44fedab45e98abb99b8c5cd7181f76e78fbe53260be7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:6b3b48db3d1c26422e6d8272751f11b85180ac31f60ca4e1fa2934a6b331e6d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:c3710df526c99d19d261e099aa4fcb2e05ec0b8dd59a1c5a91b94f50784a9d2b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:b1de1d9085b5e005b9bad6a4f2649a5583d02ac9506c31484732ab3bf430d5c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:5cc774fb761b3bfa30cebde7f4a8c2b501e9d5c47a1f9a9c2d66bbc78b40ec7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:5b44bf1f79e2ed1070194e9f6b95a5bca6459a5c215f5c7c1fe776ddc0bd2deb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:c6581860e02d8bfb20a010e4909ebf13eef26cc03f504ed87e229dc46bbb7470