Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.3-alpine-dev, 8.3-alpine3.24-dev, 8.3.33-alpine-dev, 8.3.33-alpine3.24-dev

Index digest:

sha256:3177bc21a4f1389daba1e94578f93791e5c1ed01732e3b409805e78e6b20dcfa

Manifest digest:

sha256:a3cca54a5d27a39b5ec6a62ee87270d6b5708ca88281da8b7137efd041db8691

Size

132.48 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b0636b00e786e0730990070679c67d913fde5e4775b8eec1e80aa9a65eaa7f94
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:962611b2ca6b93e41126ef7c5bb32a706d1b9a03af97eeccbb1f37aa2b998898
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:93dca57f87bfdca5404f3570b081d1337deb108518af29ae0a59fe53949468cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ca46526dd501a9cb9712940ee4c627b1bcf23d46b0cd5f76b68e609399ac3296
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:877f4402b1106c56eefa4c798ad5bf83b9ea7831db0258ab8a7080c047fc991c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:bfddb799c48b05f9739670a83399e89401f3e9006ea9dcfc1d4e8591cd8b7882
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:65d4e36744920bf43a04a40694535e2cb7a9a22724b6b6f6f08d489315983a59
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9a7940fa7622544d4a1700877db7eaddcdd8794caf9d0bf85ab97ded5131b095
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d9254896e4e0cd7c0aeba74f94ec7728c80cf112985f3e0b4ede2be82fc459c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ff677d503e29bbade7721e70d9ae53dff15bb03406f32cc445e09ef10b393bbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:8b02385e1bce6ef23808ede068967d946d169abcce774b0eae7db13aabd1c434
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:b8e4cf7764a17c6b50797e7b246048f9c21ee3ce13e0f4043aa6244686e7b966
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ed89e9058812869661289c45cc3384af59dbcd220eb6c0780cf860c2817282a8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6cb7506289b85f03b39b2610db934603f0feadbe9458c948c410b07fca8cdb32
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:96b0a74767a4836eafdc5e2a1cbe7a31a96766eeda17818070b48cb73a9a24c4