Sign inSign up
Python

dhi.io/python

Python 3.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.15-debian-dev, 3.13.15-debian13-dev, 3.13.15-dev

Index digest:

sha256:8c0174aabf811c640280d1d5bdc39ed6084880903a2df8e35d7ac000cb83aa9c

Manifest digest:

sha256:97244f150b9d91a71db42d5b963a64dea5e28f77a209a4809c0de61713186ac3

Size

38.47 MB

Last pushed

9 hours ago

Vulnerabilities

0
3
2
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:31b5ecdae1c1c79ce57abc2d4c42c10f7a8ced54402ad1663949e648c95066f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:6ebcc082142dfdbaa91fbd783c4975816b804f49a84611cfcf29a3b3929620fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:643319d1f1cbf30897d23e92e4c7f7e1291c2248bbc21f0b99c8576923107d83
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:23f881dfb9cdb35de3dffb28cd9489573527c14f2459d85efbcb5b8d6df0f870
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:796dcf44ccec02c98b5224f0ca2375bec5e245474b1d927b6cb72dc7883930a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:5bd6713771ccac179b6296cd1c3d0b73180d6c8431cb6d7797fb77a5521d14fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:39554b80dd935c0cc932cf69eea398a3133352d6972e77f692cc2ccab37ff37b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:f29fce46b5b792a5303c79761737ffe733c0a9f08ef1e78f0aa6d075bc38fcf5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:1c75acafb642c56bd6c89d0cac48b19f512f9a931d968f1ab388147ea5baf110
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:b0963a84633090e104476bc2104abfe8ac8d7355e6a9b9ea925506bb059459bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:5eca0f4f66f2e8ffc13f1c98ca57e41ac85a5546865dec27e07bd529bff1eaf5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:c40fee805c673536f208051219eb77f35eb6693e468b4167e39c08af5d587811
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:36a17a0d83ccc45a9f870f2391b6ed5e4654d10023797836d06e563000074b5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:143fda8e38ca09806bdff8d3dc648dffc22482886be42ced780dcf218485e66c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:aed750404127dad58a4611ab7bb5f30f26f48e03a5279f709692243ae42955a2