dhi.io/python
3.10-alpine-dev, 3.10-alpine3.24-dev, 3.10.21-alpine-dev, 3.10.21-alpine3.24-dev
sha256:f706e07e18cd40532b5d111c316ece64e11c6454b11307bebcc2d55f7c1b6efc
Manifest digest:sha256:58e3eb43a77c0885efce5363411a16bfe7d52d36b27157d5fdca767e4b330023
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/python:3.10-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/python:3.10-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/python@sha256:4ed133452e872779d39f98ce87896cae6bed06087f13257c5018bda2b5819102 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/python@sha256:a7de5d11b8d5a0c3c41c40d94cb1ad1b476cd5b6f98b9aa87da89ea6c77e1beb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/python@sha256:85baa8ad1bc84d17229693ad5ca445ce6b582086cb7a49ab59c0e7a2549640ab |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/python@sha256:6ee24422238336ab7f96834075ead21b5402f991f4fc8d9fc095e3bb4a8d30c2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/python@sha256:bb3c651357da678eef239e33430ef4c61806b86db44be03bcc46b5db9a853de5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/python@sha256:b259ff3b1613847b239ae6e1f4dc986b6e2d1251d562b8b1fb46a18789fe66a6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/python@sha256:ce53adc558a72a64a500e8e2251c28ee886c0162bd4b8c97e71dde58e6949c6e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/python@sha256:d9c390dfc07bd16f0b8b33305a26baca9be72a4b12e8fb361a2c6de453c3d080 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/python@sha256:3c2a7585208cb654c4dc86b2b3bad033867f03bcc902b7e75f73804b3af9e102 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/python@sha256:1b9c867a54fc7fea618298696328132c77c7d0545a4a002f80fef170471cafce |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/python@sha256:c46c21c6720872518e9f73a2a3e03797e8caa48a6426b1251e6f48714218fd25 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/python@sha256:68598d7421dee8b8d56741d728a4d16cdae67b0bef456c1d698e92b8d94e3c25 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/python@sha256:ad707f9b40f5e2a9def4d741fa6c9fd6ff98eb25dcbb2faf0dfb15cd39647804 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/python@sha256:98d56738fb6a68791ae604a941e2e0d256ba3fcdd6c6fe06a9f8bc088029147d |