Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:590a5e7d0210829dba7abb802b2bf920d8c50a3473ff8836737343d200e1ad2c

Manifest digest:

sha256:eae11db247320c2d8925e0d7f85caae6f3f50ba40cb61b5c42d5a7ded04c635e

Size

162.91 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:ce3635527b914d1cc73a95c137590e63afa0e4e2f76e7a5d9430793a5d4ee38b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:bb41cfae44f83a4d4e5995a36eac9ce9a5e9680212725994b7e7e582d7771888
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8b7ea991baa0252c536896fb794f57218652751a14a3c8f739e633980af9792b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ebd59e79f26e58c45e71f25713af9a4186550e4cec4a6078dff88d5f624146df
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e2a2019f5c9e05cf6f8e7bb0314324e83b18f50619d15485c54188b892b2fc4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:fdcd9c73d535b206a8ea4e8a18b24ce368e3cd6870afa2b9e3ff2a93ca1eb5bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:3666daa1600a5c2b24a4b3850896e0bb3926781b6a58df679f2053d6333b9367
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:c7cd350b7ecf3c651226d714392d69dbdfe0b67428fabbc0924e769cd0106b87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:7d1235e945424ec63e6c897b1d86bd353aa407827b734d5a49532c3a0b08bdc1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:4a568dd8e2ed67c12fd64975c040656ceab610755b688067af2811fecae1cc17
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:68ff54c07c6260efa408465d543a1defc567bbb6a008c02fa6fad8fedd2e6fb9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:0fc29c2957245b6ed97c92217d73a76f5569afc87621d01cb9b8154324283a6c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:265938b7ea45b7d3aa6ceacbf2cac0d3486704a398642564dd1311ced70836a1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c724b3fc00688aa09a6926fe5129fc79add980234cebfbc2994c99e7d504f4c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:39c3c40df14841c62de257806cf954a2644222339445b22f690322fae50c6860