Sign inSign up
Python

dhi.io/python

Python 3.12.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.12-debian-fips, 3.12-debian13-fips, 3.12-fips, 3.12.14-debian-fips, 3.12.14-debian13-fips, 3.12.14-fips

Index digest:

sha256:99e74b78616af566c4458ea76d292c14bb4d925a27ff4f9cefc61aaf0259ea64

Manifest digest:

sha256:ceeff41037b9b9a48c74ec654aadd7e29ec4f9de5e5847a062d249b51ce19c49

Size

22.44 MB

Last pushed

10 hours ago

Vulnerabilities

0
3
4
1
0

Support

Active until Oct 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.12-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.12-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:8c268a85ee5028617eed720c0200c7a7ef39aa7773787d954b0250ea3af80b71
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:4596b60279f1b7255385db16fd8212723e60abb634e7fe8e6763fb12b94f966f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:501faed3f6bd64bc9aab4b3660b8eecbaf7e676cd8cef6f4c6dd77d00929256d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:341375e5b1c9daad93b8781cb763680673d60c5079673a51e2a2de5f423e4e11
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:3c0df214941a2b26ee8ee9d006101b0e32297bba33821ae19d87468a31dc8201
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:8573fc113f078803ac999c00def1f0c24e8a5560d0b695f2116a41c0c9b12918
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:86b75ee3e29f3792f04080304654b371bdef18100318627e837475518fb61505
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:727a5de4048609533c4b9b616e31e1b408ee87c3222e55cefe7d6455a14f1339
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:a552c0ba894cd7ab2527c468569adc50a393b83c9de85934149bda6c9bd6f598
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:f6ca1a6182c7b00260f1d6d0905e1cd4fd4a408c5177ec95acb760e60ee6afad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:92a015ff55524de0b31e2e9453b21fb19527ed38b681d21cd739079d4e55b0f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:54baefc487fcba129d1f95e49916e75619cd92e5234b0396cbecfc71ac7bcf00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:1bd4705faef8a59fb61880ad832b8546a2cb8b7e39b3a374c99140c23d48fc36
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:ed00278ad54563c80d2ffc4ffe13f71ea356300ba44478c64742250678ab8418
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:cdcede2e984f37f923a1abd502f1b9582152ffc2e77069a72c65153b363ecb95
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:53a132f1134a3804d725d1e0d4596135cb7cae9c90754a17a9dc04949d32c682
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:080c067d3b78632239c4caf9f269edc867ef1409d72db211348cdae553a44431