Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.3-alpine-dev, 8.3-alpine3.24-dev, 8.3.33-alpine-dev, 8.3.33-alpine3.24-dev

Index digest:

sha256:be44debbed64b9c8e6d6a878c983ff9138dbc483c6f822bc2135123d8f53d35b

Manifest digest:

sha256:c12e035c8d6696ff04643ff26cdfbcc3c81294a0c702a434b2c81cbf004a4c69

Size

132.48 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:16da963aa32199da95372b89bdaf0150556f0324ba24d05c1dc876d100f87c90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4a77a616234ba8074a76fcee54a89320806c729c6ed3dbf683aeefad6bc556eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1883d78b066b4157e1df85c730bc5aa6ea8ba17c1e1dfb76963b1827b103a596
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:894356e5b91f59144774451ab679ca832d822f5fa5fa7a02c0b805e4c4ab6bf3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e1bab11bb33c72ef6e6a6083c67fd2bfcfb54f0875f3fe05d95536289e50eb6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:d51fa19214f21c493ff5e2e46e3afeb7b4835d13c32138cc8d2cc11a5be028f4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:4e870d50f2597146504c4f6fa0e0d7d2979db907edcca78506e4b3d109ae8ce7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:e06913e4c480a88fe8c91031e151d64876b67045f9169198b25323e53f712b5f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:dce05a053d3f6dfd2893f75a2eb6f1275356d074feab836d5f4823aeff09f343
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:cb25cd84c93273b9b85e1471e618061e3e63c4272ba0750b6cebb69fa9028a4f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:616fa2463922f7490f6cf0a69210005babca55585b458fbbd5e668c3d6fb6217
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e0c39004c01b416327cbe118c9134372568f4824cdfe5b66799fb18373039f58
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:51015a2fd5741658dee74d33b705a1597cd67a18ce65be901cf25844cea24456
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:ff36f1580023e0dcbf38030b2e80f788ba1f1b767d499f702a9012dd5092ef11
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ea8cf7e58ab5605635acd502860970db2673edc9f1a268a1d86ee36e21cca242