Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.33-debian-dev, 8.3.33-debian13-dev, 8.3.33-dev

Index digest:

sha256:dd4a0a2c1f21f6c613ddf82d7514cbc4c45c310ce24676156c835ff2f361b586

Manifest digest:

sha256:4fb899e9bb9305e7172bb5ab973c4f39e8572e771ad66fc041480d781f56de5f

Size

159.50 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:bf14bbd92339557ef662a19f936a7b4efb15d05dd9c11622ab1c7fe399ee0845
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:cce181ea4921e93bcbe4f0c346d0859ec1da0d01a997cd5eb8fb8ecd51e7d7d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e02e838fcb5b33af149a387cdaecb0817e7bf6a567130540b82f8a19d9e395cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:fbadb1b36345bf23f0044346da2d47652ae9873faf21fc47c060d3e790b48556
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d3053d1244f2e0c5f0a9b3837405c6eb0eaf8653e8158864877c8c11b13041be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:cf15673b3d9954e5239be06a87ea0d720e637a9a21f314feaa59fc20b6a432b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:878a9502976e1e3601304048bc192898ab6ec99c7fb05cc71d0bbb07595b867d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:aa9dbb8d29a6f8d6c8299bfc655c18c80fe2760ddf960bdaaf49449212f0813f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:ae410c32782b63fc8c431e7b4d6eece7280761f163015b152a421395172ee591
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:44fbca710a6558fa3ea74b4128ec942132c0a0b1af47d4c94afaf274e8fcc28d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:65052503aeb2d4ebd110438b0757bd565b96db334f744d1b921657b9b98a3011
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:6745f622909a44cac49b56b8051b3ff26f98a7839436c39d13be3db144a31c9e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d9426b0eae14d442dbf07ba15e34959d5952c69958342d469c65866de415d0bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4b187be38477b927b91ca7f9b1ee67217c1a9396e5233de95f45dc5e6de072cc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:3d9c006241edaca2a02a6c1c7959862ee0ab7b39c3bb8e563e092b0b0b21ac3f