Sign inSign up
Python

dhi.io/python

Python 3.14.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.14, 3.14-debian, 3.14-debian13, 3.14.7, 3.14.7-debian, 3.14.7-debian13

Index digest:

sha256:21b78d6daf1b6ba5e1a96c07de143364fc1a7da65eeda24c7ecfc3328646f6e6

Manifest digest:

sha256:b20e51ad2aa329b6e36d593347d48e9f87e6f74031e911ce07b58646dc85eccf

Size

21.83 MB

Last pushed

2 days ago

Vulnerabilities

0
4
1
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/python:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/python:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/python@sha256:96fe7a3d820137a1cf563225755841b4eafd7631186d9c77e2699fc4042fbc43
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/python@sha256:b03e3285f4db90c90820f1a6cab97d2702dbe41429413cdbe2a916a58d187d91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/python@sha256:1cb6f279dcea6545aa8dfe9d992b385cd539e9c5cc4f3ccda601e53a331eed2d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/python@sha256:b84c8512d7078aec3ef738dea929423a85a4437a3f2c90b12614e24151a6a78b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/python@sha256:11f6643c319559db31d991837302d550f84dcca6d4754c7fbf7aaf6a8693aaec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/python@sha256:09b3a41f096073997fe248891bd36680fed846aaf3efe500fb38a5d8362d8f45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/python@sha256:c99ecd7f704fe60d78371c54e81a2e028656ee731d5732fdefe45f6808bd8929
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/python@sha256:362dd5c80c4516aff3a8a9524d4b7b3dbc7b421f72289b45a8275a971b4c4742
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/python@sha256:4dc92fbb589564bd2cff58d6ad23ca58b1460d4a9f60d455afe56d6406261d14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/python@sha256:4f946c607adbdf5c2fba7d63c9fd16ecd40efafa73b96eb6e68d9b2cde270da5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/python@sha256:31314348e58a9de02725d8d57927740fb812801c5b4f177daf2ad8b65da3d1e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/python@sha256:42ed7422ddd281f083c236902edf77b47979f090beedfa6d12a5decff514f79c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/python@sha256:b57498643dba43eb87717d6bfb77541b749ed36488f2bd6fcec801b22c2fdd69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/python@sha256:ba6ea2c36ba62338190141f2da8c92a947c60ba9abbb4fe5ff3c9abab5a335cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/python@sha256:7639daf8017c5bf07424fd70f7186981468a2dd9696a45842bdcf2d315b05e64