Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.14-alpine-fips-dev, 3.14-alpine3.24-fips-dev, 3.14.7-alpine-fips-dev, 3.14.7-alpine3.24-fips-dev

Index digest:

sha256:abae993589a6b1b693c5c60398941905886e55fc55ec6a463d80d13dd6c7d960

Manifest digest:

sha256:0514d333bcc6686178e912445213e98b4f0ec3d1620fe1c08d1f9ea098934e80

Size

134.74 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:bd37a2f7220fc343fb57c113d77e0833fecbb75afec87c847d5c0c705eeb15a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:e9655354e750558e3ee67566fe75bbffe65076f8a62165d572af972a8fc27d3a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:93f038c390023c0c5efe7394071cc3bcf1bb9a2d3ab6d0928bcea6eea99bbeb3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:b98bf74bed808e8defeb55fcf2d4e46d12fb29fbe1cf3b77ece0422651da3c3c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:cce7b3bd1bfe10b37bf85023831ca75e231c627ceb8e57f9bd5f5fb8fe2cbe56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:8ccd4ffd8d00e5fdb6a9d0c14fc2df06521a2ca95c8c6ed647eed585b85a58b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:fbd40e2113aea974dda2d5fd7ee52685fcecb498c2d2662fd75ec01a00b93bee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:c181776d9ae9f9e99e9bb73cfe5d3791640361b13566efd43d21d08b57ba880b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:b888357c1abb4ba0cad9bac4f4b0587615f8abf4f64bc4223e20ce4769fc49d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:6e06496e2dee90216539a97903254539cb778b8eecbb5a0df83575cb0276d3f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:a4c27341fab78dd702109893094973f657a6b611d0e9c7d304bc04591849fc00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:027627aa51fa249015ea5790f4d719d584203e6b052a90eb47c9ae4eccc7ed5a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:ab7f10b882a5f70b8eb763671ca2f876594299f83475940aa6db31ac820d8076
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:ea3ed119bda1163a471b5cb896ce153d29425482b672e7b125d4ca73729a8817
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:0f2341d325baf184a74eacaa2b8384d2ec5774438ccd455ba90ab47b66af34c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:d44dd1ab2377001f9865b43f4110ff4ae8d3a04aa4041ba5979ee587f06f97fd