Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:587a39822e485a45c08719eaedc2f48f44a84af0883a0db07f3af69143770247

Manifest digest:

sha256:1bddab2fdea1671f368b3ba5e334ac6c05beb49360ecaf59f92364e44feccc31

Size

162.90 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
3
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b6ca4f0d4efe74c9df3612a237ce5da79a8635d4a3c86c8720833e9aaef96852
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4f2f9fbed3df7476db0d9c25a175a4cc40b0ed8d128cffc1cb1a1cd5058bcf10
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:9cc1fbdebfdf4a2638a58820841441b22f8be20292c2012ac2a4c4c70e806a1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ae5e95b3a3d4ce25eea17747ce1a3f0bea665f1c3f78e508f4197297309d17f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:84ba63cc9eb59f0e252caeb9864b5f739aae241a9980717b84b32cdda6585d18
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:285d900338f53285aabb3159f7b2832fcac0fe970dc70474c163c146b11a96a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b3581fa09c082480298d9ca67609d8c216bcff9ee3cba21336b7caba85faea2c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d1bffa9728aa6fec6e11939d00cf779ee642b4806c47453d09f62af971680b70
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:105982a8774686c22c63e402014e70918023b0cdf9a7cbbcdb9eac5705cbbaa2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:61ceb4c7ef45f1a81b8057d9f9fe3aaa8fada7ff79b53030837228cfb3f24ada
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:824c3288bee408f93f41d959e7141c391a54504b80355de4157011aa48953d23
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:162be97c4b60aa553482006e8afa0d68f8cf43747b7a5cec167fb2dd0ed5c93f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:8a500e9a58335c2aa115c8c74a42a95a1123361ff729031d2be435c5188eb0ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:28c354a0fe8fc4dbd1333f55c020c8ee98efbe3c9729ee18da38406d364f3369
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:a34f0e2efa42e9c858673628bbdf9cebd9efbe448e26467f0804af0a76f2c03f