Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:da8fec3370b13551021eec05431a15fea5b8a3ac7962ee8125eb9f54179f96d5

Manifest digest:

sha256:7d8c5ee8fab12fc546ef1fb0290813a53b0438fe0da390c9a849963d8e4eb545

Size

162.91 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:9b541018c460b621591777c747bed62b175274344f0ae839ae50a2a7973a14f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:52841f0f23b35b05fbde4dee317eee40c03b70c47cce598dac1f68a3ae9f768c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2cadc486be506308f21dd3eb736353eb43f7eca6d0ddfd5fd052df0ce60cbc42
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c0af9aa7bca373daa7aa07a7358127696735eb0a5834e9f6daa14cf3b4642442
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e16c30e5547b84fdddab7c811ec504cd3ddf13a23270694129fa968c9b7361b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:5aff6356b9412b80a45e6552fef22895fafdfd02bda3ea8b04575ee47bcd2c5d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:995f3732cff0513d170286b839d813b6dbf8ed6de57422b85b8b7643139f8449
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:581c1bf675a1daa83790564ed0ffc562ef5c79ae7eea7fcea3db0cb7d71eb1fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:32c824573191eac2cbd94d8b479106654f964834826616b3373f8ce6e8248c2c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:d1e50698d90036aae0ae4faf1b79e89d67d06c5e0d1853b336e1606bbc4ee959
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:656d9368519f30172123fd3955ee36913bb9676acef3e208f670f7ee82d8cf05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:470532014245be84a62ce9da67d076336dd84abaf238b4ac57e735011c6a986e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:508bbf7a416a0fc0ab2e459eba613ac9a9cc16671219f3b87734620a1f5f7465
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:7d3fa627db1bbc0eaebab918fb9a68b12ff0a554b8366ab0d89b6e224d7c562d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:96e16132ccf8dc606ce54f9b9dc44f1b2fbac60a8b2bf9043474a985b4a3307b