Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-fips-dev, 8.3.33-alpine3.23-fips-dev

Index digest:

sha256:fe4b6190d49b14b93edbd66823b4fdd7a060ce4e8c2fc7c109f1530f11a4533f

Manifest digest:

sha256:c4aa77db73fdd7270fe89b95edab5885765782f92d8fcab42c5103a22a9a28f7

Size

132.95 MB

Last pushed

4 days ago

Vulnerabilities

1
1
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:c87781c90577f8ffc101ada5336d76a1ca48abc627cb33b7da39c2c9b77777e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:e0ea00bda73984fd00ae9f9a00e393de12d7757898da897720603185c1604ebc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0db4989bf4e5a62a94eb1953007ac76e650415cb545f9c848b4047cea7a06e85
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:aedf7b19ef74d30940327a8fea27dd56304af9f0c116593c5a1ac8c21b03b2e6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:85e92509ca61150d58a596b0e33536ba1f1921dc68bf15a3204365f18997a8a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:3ef17c74811f5c63997e620ea76345e20824f8b8f0c1d0343c49eb875c94f2f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:a7b40352f4fe6c0dd23cdcc8a2cca39f4e70e26cbe9b508d1d15a99b71a29358
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:19778574b116145890fb38d08e92636647734acf9c360ab389cb91329155c83c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:bdcca9bb8dee24e373e0e7dcf72214d455e28eb9b9a14e4382a3ebb38ce95647
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:06aacd552992e392779cb17074c5e0cfb69fdea84cc7434d1a93eabe40e9d66b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:3c96779a44d244a174f159c3f5d8a44743840d832066c068d831d915190d1922
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:98d6c38068a15f3f58d7cbb4998df6baebd208fcc60ab6c4fe25a2b3160286cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4a85d171d830f2376638805aeee1b2f4d0d466947a6fd4370c9d0332fa61e4e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:896a25923924f0dcb63f47fb579bd2bcb5648d4f76f4c5b2e3ff324b5bec2e29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:68d59a173790351ceee154d70a18d2418ad49f0a4db344b9315a7c7ad137ab11
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4e7d412442c9407e41bd70c77f23121e6306acc3a8d0dabd7bb18f11f13c647d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:f41ff7a7c88cb2bf23087a3bc67e241d0ad61e538e47d9a6df2bde1f1ab7a560