Sign inSign up
Python

dhi.io/python

Python 3.14.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.14-alpine-dev, 3.14-alpine3.24-dev, 3.14.7-alpine-dev, 3.14.7-alpine3.24-dev

Index digest:

sha256:b718c87cdd7bb7dc88d6bbe347f81123b9cf6f2dac6eec6d4828c2cd8262582d

Manifest digest:

sha256:9ec93de838bc6840ec301a01141f9ab7df29eb13eee3aea75b2d42fe32ba85cf

Size

80.90 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:37002673fd004dcffc9523e4dcacf3f21321e45786a8325244cc7718a3080764
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:7b33b5c240e9f61ca2e8aa89f7669af444aa03fe18ffe1466573de34d528db59
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:2f6143b1d524a8e766820519ee6fa292744187ffd526ae4f3b25dad4f137d5b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:e69a2b5f4408f7f99fc60d67b8b7cf4d73fe04c3ece27743145986a61614293e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:a6e9be886b76c11f3286702b19f489d23885afb1ba0d22b163bda51a2dd4c492
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:a90f1398eeea8bcba0d69da1712a276452afbddc4985c23e27aadb3b525ffbf9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:2bba2acb66276a926491ef1005f43774996b809550278c9fe8e9a2313833e44d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:ffc825de02eab1e8367999efdd481925215cfcd5bb829a170e8b6df3faa72f88
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:ec992dfd8d6fb22b8daf47b7be8acda2805f83f588b0a5806374b2e1b850f41b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:1184744c35dedc2f1d889e27fa44f68145a0627e18b6915c9b6424f4a20c70a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:a879dfd178fa7898f3c67364307f05a906deff85379f710f0ef9c17c613e60f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:bc3cabb8c82049d5a38162892ee3efdd67c9c59435bb731c6730b080b7b2bc88
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:794e68b27b5eb1e7f928407b8e91624b20aa9edff8f24dc6e91e5da13ae043fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:837bfeabd40e4ea72ed9f6b7dec4bf3ad8a999310b99fa39cb4bb886d39d751d