Sign inSign up
Python

dhi.io/python

Python 3.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.14-debian-fips, 3.14-debian13-fips, 3.14-fips, 3.14.7-2-debian-fips, 3.14.7-2-debian13-fips, 3.14.7-2-fips, 3.14.7-debian-fips, 3.14.7-debian13-fips, 3.14.7-fips

Index digest:

sha256:0f08665990fa657ed37a8c0ade69e2fff49614c19627e62293213e7d305402ad

Manifest digest:

sha256:58254179cec1d52bfcb7edfba05f7072f8d76e1b9ed110154e8f7f48cc7c80be

Size

22.61 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:0b829133f72bb0918135c1bf6279302670a0449442867000c4fc3e3c448e1422
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:7ae0090d90244526f71fdb253c2436015cdc81c29723a6ee670841c9fef03e39
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/python@sha256:a37b5566e422e7704f3d72e22c72f57242ca456f169cbb327079a36bd29963ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:a56a67159ca7c753785ae56169e29812c92d8531312620ea4444118ac4b6bc66
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/python@sha256:d01292114eaa8886b22e79aad9a739643fc958468a5888ae28e98d74c9779c01
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:b47145974f9f94cd071890b4865f5740a3660f289eca80a65a23ed10b391052f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:d9defd3d6ee881ee9d8e52a2346c3b88b315382d85a60b96a0f6767b5a8373b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:e509a9117ffae48ed6c014cc2f425f6fce3813f2cf1dccceb6325e325f40f5b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:1b515f7761d6942e293c7d702c156899d8657c4306bd3c50004700be1ef4d487
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:47be0261ee4cd88a29879f809842ce93baedbe101ca5adda0999f3fc29493fc9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:a8b66894a1657f689eff2c341ef786ace38c7082eae4ae8f0b8837f5b380aa8c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:1c1e5e3e02bb3fc2c521d8107f5937f96fcee6976abe2cdf9f663c94487383fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:ad1a40703fef82add1684cf7a909917c16b4307e7ed7bb0f89eb442658dacf23
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:3ce5a92cb26fdd93a04e7c2c9ad9538b1a70b3d7e9782e05bb90cbbc8799623d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:d40781f701c39daa1c2b71e7e15cc063082d4f2b9f491b669486ba13c62a9116
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:e6fbd57e0f9062903da5d840f558653ac74c2cc938b4a62f489c6f08d468bed9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:ccabf44fd7fe467af9c315ff329d02a269d34e0ae6cc4b5a5c9fbaf9fbcd7515