Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.5-debian-dev, 8.5-debian13-dev, 8.5-dev, 8.5.11-debian-dev, 8.5.11-debian13-dev, 8.5.11-dev

Index digest:

sha256:ac38e381ed6fbda20b532bc860de53bd04c786efa995a9f424e4c3f679d95863

Manifest digest:

sha256:1801aca305fbc572913150408a2e40bca88b88003f864384e610aba58b5f6971

Size

165.08 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:783c84573c13aef0fff5e31ad99205944d94405120af4a625428a169f5227147
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:316bd7f0b01eb835bfba6ad052a2156a66da839bc52fcdf731ef19bcc234aac4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:78e93f284a7bfc5f84c69d36895828fb5833dc086f1d3f264b709f60cbbe33b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:77133b52ea6f3622de7b6d886c2ecde0a64ee4566178faf93517699cc8464bb2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ed476eb4a0c4b292d92e431ac732bfa94efbebb5964174f7b87f926205662426
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:34441e75f6fca161c6237ec1810a2a2e392285af7baf5da9fca714ef452b5a86
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:feee2dd4eea9d196ffa0eced4a434a0b4ea66daff74df4622f5f083de4e6cb53
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:6171dc7ae8317a5860404f6f4b830e9d2d498350092c032d18e9e6e910bdae22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:79b40a1ebf2d18a9740448ce91879c37ee6002cb7810347817bf4b02764018af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:4a28b187ac0fd25d401f6472425837690a36ee6d2ca191b9991987c0c46a182d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d90c6c4aaec6d48594f76444bc8beedf80c3990d742bac836aab5e82befa4735
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:9f5c935554dd64a25cb6897947cd0c2e3361c9cb131e0e36ae73814043ef96a3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ea6414e24d4c3d2127813f949f17ff5ceebe2e8684eb9fe227c438ee2bc16088
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:93e5df679d762810f76b61ee64e70e17e71acd26a11c7872aa0e035ef82f7ead
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c48dedfeca382e5ad5dfeccef63558f2c12243cc94b207d2bbcefb663c5923a5