Sign inSign up
PHP

dhi.io/php

PHP 8.3.x

CIS
linux/amd64
debian 13
Tags:

8.3, 8.3-debian, 8.3-debian13, 8.3.33, 8.3.33-debian, 8.3.33-debian13

Index digest:

sha256:9dfa27887c56db78b0bb1d5699adaf082c45f61d0a6f60b778d58bef2cbb35cf

Manifest digest:

sha256:52868fb502610dd4bf67e75bb1e7863588e5452c15f055f9c8693c1da3767f4b

Size

33.22 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:2a7d68ebf79c5d3bc26e945a95c3da5af4944b843729125198a67dfd9239f487
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:9e5324e3df12951165c5782b70e1d69d89a905e25723f2fbc402512b880c95c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:036f94423fcb1b2c020e14a0fddb68318cc77e20a82df9b9d507375ae14af4eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:9018ac08b1b72eaa3402267cf0174daf7c3cf89d21644c730141557aa9526a25
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:4765e0f9ace1567d8a7dc984b2bceff0acd781b835ea84d62082d79757709459
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:38ca524f8b939da469f0754571a242cb42c4c7993765edda49646ee2169c2ea3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:130fa2ec3621ab6c20f7c7dcc37c346c20270e3af3168020a3b511427ffa1fc1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9f181c83c32c27b4d5da4909fff434b81968d22aa36ff7b6d02d13e17d67f827
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d8694c79d4dc437290c9ed2a59134d5b0023cc269142b0aeea591ba12794d736
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:8fee87973d8ddba002bc6680ce3cedc437b67919caed9ff75322eddb3200b921
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:b6f65a5908c9f355b4071ce596b4f0b1928e55ea76d1eab6e8a4b1cf4191f7f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:672c70ec6a51d38ea1676be0dc13bda02e955fa9a7cd9638810bb1cdcecdc13c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:5b0f5bfb11f638364f9c90345da53f05a824bae5deccc5322e91d058394a0ad7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c88d85b51674ba73982e599519a904f9ff50867eff2bbe12e073d16ef3ace8e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ca2383bfe2a5dfa9cda6f2251b084e8cdca69967da168bd120c96327d77fb000