Sign inSign up
Python

dhi.io/python

Python 3.13.x

CIS
linux/amd64
debian 13
Tags:

3.13, 3.13-debian, 3.13-debian13, 3.13.15, 3.13.15-debian, 3.13.15-debian13

Index digest:

sha256:c21f7985f1b2726586b71e51ae1ace813572fc78d94f8ce42a021628d3babec0

Manifest digest:

sha256:307c4784113715369eeb2a44a8937d1f8d012409a7cb82109b0470ce85162b25

Size

21.52 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
2
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:d21668329a7c9f136fd7b53533d7af9d47f186daa2599b4dde9ada23649c9369
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:1365105587ce1644e49b29691dc22d4466f9d222d16822ceed8226bc32b1ac71
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:c8c594b0a3ba6b9e15e3bd59cfc3bc4530efc4aab11539f53c153da8d7fc0946
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:a52d14cc6ccbea1ea851d6dd3787b52b1681ed12406687e0bfbf64dd48f37320
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:33ceacbe833866b0f9a2d028b5392c9722ac1281028392d118ca1db2404d1908
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:06cf8392bb1723d117ccfd740f52cc7ff14b5cc3d44f2ab3552235ff66edced2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:8ae4f34882d73077aeff0cd33a79f615431b00f300741c2109eec3eca90737dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:af16f81b92e57c078386286a4a19d92cddaa004f48855b5752c78cafb936cfb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:93c9807f8e7efeb745bc764440bbc72908f736d267dfd2c46fa1ca509ec14253
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:3fc933d2663f433c17182c973c31c7b013778f84367077002da1d76bd241ea96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:419e9c53be3c37e868847311f5e0b4511eb397ad4f757860ed68e4c54cf7c80e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:d8c01cd6b5a18b8c630824df987e9cc90c1b56d1a6d1638aaab8369cce640a2c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:fc0a4174d753040c6d218667f347a5fdac4c818728347466c978573af1155edd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:b5ace045a6e9ab0e62f3c171f9cac0a72cec3f0df9a5c75b3bcb84d6bd0f4fe3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:ae6612c6437a93fadd21cf26ba21414cc53a89ed43f66fded74cdee24fc96de8