Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:425799e8a03757fe834fc1bd0f3c6208de0b0fa9bee127404c8d8466608e8ea9

Manifest digest:

sha256:98f8d807be294438976a5f0a45aa419c8b3e30c41c57a67d0a0e9c81e887bdf3

Size

162.91 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:5a065b13a06598cfdfe0f41b18ca0e2547d67800c0b413a80dde532f6f81853f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:47a467e67f14728e19e770b281e755f9d1b86e9cf1f6aa4e7eacc6f52c3320a7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:055c321267baef67fa0c00fdad583cffbb05e6e59207096be1ba81991fa1f1f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:46aa1510a5b9c85724357ad24d41e52879d34493456d518efd19a6fda82227fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b53d2663fce5e8f4a422c8e23bc1be7206a1fa7edc37b7ebc20654b737c4f50c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:6e3d38609da6831f3da6f3cc9f528a2217bae65e92f917acd7fcb5772299eaea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:5212b762b584e05ce9794736623f9dcd690dfffc9cd6b31075b77a238e9cc1e6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:030e1d20f6bf53e595f63c22f51a4762fdd196e1e97f93515b7da796116f8df0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e84f29387b6cf36894237820c712224dcda1941d9bc04e31743968d6023e52a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:d1b1794c45f7dc4769238c689bf16e815baf9b3f649dfcf2814a39d1510615c7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:fa988efe53a90f1b278c72285d20bd8e6b187f794900cb23d2a40690612b660f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ffdcdb126cb9d0e53ccf57da8684508812980cf0ada5f65bf1bbdc3dd01f3f0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:b440342e6288637e68ea7a3a2a138c42d02d06ce59ba0630f6e425c2e0536c77
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:d1422c6a961f4a202eb0ed315fac1135a0a4f1a287b5fb0d70854c4c20292773
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:8cb1176352507d6bc2d22fc7620ca56201c23c7d69904af757ede4a9bc71a379