Sign inSign up
Python

dhi.io/python

Python 3.14.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-sfw-dev, 3-alpine3.24-sfw-dev, 3.14-alpine-sfw-dev, 3.14-alpine3.24-sfw-dev, 3.14.7-alpine-sfw-dev, 3.14.7-alpine3.24-sfw-dev

Index digest:

sha256:930a2f7fbc46fc815826a1c461b402b351eeee7a9e5dc2d8b12a336dd156acb1

Manifest digest:

sha256:04c2e00eba2ab2a223870655ebdf6644cdda0b40def7bf454f3ba3c0e91ef59c

Size

119.03 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:da2d094ca3374deda981e68c07bc1a3182e3cab0f800038a2727552fd99b055b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:c964a6c37865bc9e28e7afc6293e6acf4c27285c0c6a5443cd6b0aeb74b7c645
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:88db936a1110aba011fffd0d23654f82fe2b472e9dff613d8170846e2f9ef4d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:0efcb45c4120dc328ddee7bd3012f03ff8e6d221423f8fd47d8060b6455fef1c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:ccb3a8502ffee2773491dcca0adbc5ab9b818c861ae1bd21a3bcedb6cce7e462
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:35e3a58cde8380a7baa3dd5920bb5585c75e7248901a9cafedd0f7e7d7b17d77
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:59920808148d9f602f068094306ea70e52c3e839a15c9e3db8320cb901f701c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:2ce2f061b5d479f81dc2f9f608d997eb9152f4caf2fbeff2cbebfdd326bb795e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:3816f4a44bfebeccd17f6e5a6020573b25f155a7477c1a1f8c92e81041c55738
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:b0a8b55c3abd280abc19e3fa3d6d2411845e867ccbc05638cccbc5b2acbc0fe5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:93e865f3b4eb6d21673af9ef2f8e9a5286f26650e76e35123a3c6d2c35e4ec32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:4b8036bbc90ecacb8b183b00f5d0d615762cd9cf156ac6dfa346422e9a0ee510
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:40614d70e9e702f128b99beb37efa8bdeae06a6a4709154b34a4bad7719e2584
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:c5cf03c3e1e96c70bbc59875d27112097a618e2abce1ca442e7033c821ff17bf