Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3.14-alpine-fips, 3.14-alpine3.24-fips, 3.14.7-alpine-fips, 3.14.7-alpine3.24-fips

Index digest:

sha256:ddedc7489e7dcdcb731a403553b068243230b5cd449a21482b1bf33a8a1faf41

Manifest digest:

sha256:cb01e2ab77c88849b9cbf3453784cdf4b541040161ea2920edf73b431a887fe2

Size

18.41 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.14-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.14-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:4bf1d940ec3f57d02ed5655a5f8782612922ee9980c919e4ff060a5085d6b74e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:73057116c183bd7dc988521dc3b26ddfda5287499d3d0d4a579c86bdc10774bb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:bbd30ee313e819b186ff5874cd2f366495ae155518731a3697099d47f6751645
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:4975c9309411f942e57ab674bb6bf5f42f612df4b6b4b6dd105a2f7a224e0a9a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:99c3a3ec2fb77084c031e5d75cc2fbed2559c59a5ffa31b012f169a7acf6fc25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:a78e70696cfbabed3a51f817a6a1d41b7567c37d48d0d864640c16113750ab86
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:071c57fd215fe59fa8f6287d06b494eadab41db9cfa0d32daa05540bed7b21fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:e859bb932dd62c662b43631a45cf9b5d90dd7b98d33fd1c7793e53f219ec9ce1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:bf35695a34e428bac383a978d7e7d769850b0431b7767edf43a807f95ec9ca92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:3cb72740c8b7c904ff093b6805fd14eba6ff433349d925cb71d983d619b13731
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:541544ba05d8cfac815ec98825fcc1ab7322620f4dbcac1556818b6f8dc9fc2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:8639ea0b60b6c5cd87c114b0ccd59e88ee8ad9498f5e7247cf8e027242b0bba9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:9bdb504b283ad8a1dbbd29f34ea99d70535a0de6956ec7df0ed6ac8cc0b74efc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:64678746729e0937d558178f833974ebc66d084f224b93e45f6f4de85ae06497
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:b5e6a41dcaa28fe3c69d7f4b48950438e53da0d0c88aa66bb44bf3f5e14fda76
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:ce9cfdf18be2a8e80bf20fd0b0254f1c3036971cb184b81d53714430e823419b