Sign inSign up
PHP

dhi.io/php

PHP 8.3.x

CIS
linux/amd64
debian 13
Tags:

8.3, 8.3-debian, 8.3-debian13, 8.3.33, 8.3.33-debian, 8.3.33-debian13

Index digest:

sha256:e46b899ac3e29db8d529bcbd00ed252e50aeb485a434331ac41d5d64b89196b9

Manifest digest:

sha256:c2c821c0028f750b44f859ca50f595797fadbf8ecac6923878c3bc2becc2ea9d

Size

33.22 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:419ddcf1ffa18e03b786e73c8992f9d7605f4a5b7cf2b6bc4c312a2af3c0d63b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a99a7fc0188aa6e29aaa936c0773f7bd9128e79f2408752bc27fdae6efc6837d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:49c5fa0f74c4180e9d192ad2da5c72ae9eab9148a3effc900e013e69a7da171e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:5490e125619f35e69bb6c87e717803382c237ff6c1c2813813393195851986a7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:74608593b325c5dff62c03c6775850159367d623b4bf821ad275db54eb172848
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e74081d2cef26a923117a93fba6f71734245096bb87ea6740acea536829c586c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:08280227ade4ffddbda4675b491479c074b4f8082eaa761a14cea0a196825209
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:576e97667f7ac75faf32f7249b878b8c33e6ae40ef67b27592a9077e81bc2eac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:5feba98ecc676d444eb5234169ca82d1ce460c68cecc3142ef75ac526549f577
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:fe0b4807f9884656e9a1fa06d3bf845398df0df7e769bd471ff15b37341172ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:77ccc25d3d8551936644eb977b7439f1a509b68bf57fc575b38e031e2c1b1572
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:d9b9f1724336b8e723fbf4502be94cbc30a1524b79de014f1b3ce7d82138013f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:bcef685341f7f2103a6aef1e340662fe54398dacf4d030ae01569d5a934d5046
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:1edea6deb151b988beab2a5638faeec78eccdf554b4a53c4c199a765e4911ee5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:dac6de041117a39160bfde9045d32a02a6290b189363a7e2908a756db8503fe6