Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.14-debian-fips-dev, 3.14-debian13-fips-dev, 3.14-fips-dev, 3.14.7-2-debian-fips-dev, 3.14.7-2-debian13-fips-dev, 3.14.7-2-fips-dev, 3.14.7-debian-fips-dev, 3.14.7-debian13-fips-dev, 3.14.7-fips-dev

Index digest:

sha256:2db4de88f95263705462dfc2c90e8d34098f55164c964bbffcf9af7eb74cb3fe

Manifest digest:

sha256:0a2f20cde50e960bc690ac8e9f3e9b14fa9c885b272f91a782c13a0abe1554a4

Size

42.42 MB

Last pushed

9 hours ago

Vulnerabilities

0
3
1
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:144846e5a66618122179e058868a887f4a2fc9ebeb3f90493cefb4c32bb9bc47
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:4cecaa05abf28b345ff6be4e91c650fbe7a142ea8605ec990a2b4d74ccef895e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:8d3b47531935463c72c9ca5272d386cca5cac73170c09b4c1ad42790ffa7c0fd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:3060d17dae412748931f48885954ed7a6322867c29e284e5401fbbb2f25c52b9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:66eb3d195e1a43e36fe25873ae4f19b153bbafaef484b1b84293b90afe607c47
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:aab34b916e5e2ffe95c402047909b9f28624cbb3d74ecea223c63b86ae387e49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:369e26300d2b385e440f80112e2dece70f7cdc9f94ee8ef3eab93d9f07d980d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:21f544cf3e1634f20b5c658f7fd732e43debd6df01b9f0b7e96ef69c71554ce6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:8a8ab9d3dd76da32123ede2fd8966a7f0e6f904c32e7fb0fe58989732c4e0a98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:737e1fb27a2f97f4551f303e35e3c7289530e34f4a1bdb5a2e5d8b422c884b20
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:89076701030d3656033255ef9891829a1db421674081a2953e6572522ab2e932
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:b689e5c41fb8d12d1592a7b7ce5013865afd6c75892ed3368f52fefeccbe740e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:953ffae0e9779edfc36a80f69050636face3c83e79b7e3ab0c9660d1b4a4b204
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:28ae1eefcc731ad41199c335e8023955cbe3f408905ae194d8e5649ff674192d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:58cde3bba45ceab81e3c8c8717f78861dc60d0fe41ed3a7c1348881040aae73c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:a98956c910c9e7ef761a56230a3deb36f0b31b946136006913aeab0dfa448997
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:26a2393feb7333a189fdd77a398cd821582245518f53db84253854f87f4fe3d9