Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.35-debian-dev, 8.3.35-debian13-dev, 8.3.35-dev

Index digest:

sha256:bd2f63c5ff1a05110e1ff66f2273f229a7bacea59bd77395d5ea80811b474932

Manifest digest:

sha256:67914fe24f8f9d72d4c5d5c51db4c48cbf1e73bd20bb4912e4b9c840ac2d55d1

Size

159.54 MB

Last pushed

2 days ago

Vulnerabilities

0
2
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b726067c113fd78a2b59c65417a5d87b7e7904460474cdbc1228a41483b5392a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:c9030a9d3af2c960d755f7449a40445e307b865f6bff092a2ccaa2088036e073
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d223bc5b87120d2c33bf3b9e3b6b1f4b3420f93ff432c362998935bd05a1be29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c3171ff6307c64fabedc71a8067354af250061eb5aa42deb9a24ce5353792875
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:81f86b2647324be53a76d560b785a99ab13292a99a663fa69fe9551adf1ebc58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:4d1f8ca2acda0c195f36ad0a052c471a25583d21d85bba60371d6e13c842dd27
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a92abe88d5d2811317ce677d8a0f14eb73efa350f885e130a03693896937f943
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d59cdeded62112f7fa150d36250c1d4455c14f91e66e2b3f7ae0df72ee712e7f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:7477163d8b35ea95bd21edad86cb08381c149ba59a92e64513617710e03a38a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:0bdcf64bb3162cecde07fe6f7f5dfaf234144b9ea81c0d9b63b9fb283403d1a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:2b835c2d53f57803449e23a8547257c3d54b62b5a33875ec18a52d54234d81c7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:56524df36b336b412117f5c6b9ac8b5e10453a222057ed5fc3bf93cbb40ceaf3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:af80c8947fd2d993b63d893838a1e53f4525ad99b8ac4b57aeb9c68c6a1994a8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:ab373198db6a2b3f673aaf1d9f7df51e824f351e4553e9ca3f4ac7d2b95f1237
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:2ff03709aef212c19925d9095b7d13f5a478132a9f3dae2a09ff2f99521b2924