Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-dev, 8.3.33-alpine3.23-dev

Index digest:

sha256:45e8fe4e77ba69ccd93b9154ad563b8d710791307ed1d4c6a0248e80f2ae2db1

Manifest digest:

sha256:93883a5d9a2f5e7c1996fe405a16e45a37dc0e3d3a35880347317ee71d50c958

Size

131.80 MB

Last pushed

1 day ago

Vulnerabilities

1
1
3
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:fe964e82fc78cc47e3bbfe8d59396aaa3e45aff36a1592b27fc33ab8eed030cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:632210b2b1222a667032de80ba5735bda8b0c0ef6ff4a8e191a7ffd2f565e612
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d8e44d6c370b20dbee8c88ffff130ed724a406dff19d7329bcd390b79526c6ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:bf92733a0f12ae8788a26a8da4fb70c716a98fe2a7c81fbaba259cc0c5c83b1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c90cbf89fb3e132b112c7f2110a1c1d686abfc4e8774139f89d77f4376bd103f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:10d98350156c7b8022ed91c9c996ffadd9ceb7cebe28268711485b269e147e09
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:f0b8d28380099993deb971ca94a3a4ef3cc0895eaf709aad632bbb164a73a246
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:dc90dfd829c2dd2cac36ec4b2b8c10950cab816d09b792a0f8634af7c3ce438f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:928e4d8693456ccb6da09249e41dd359891b611455a8fa272f069f65903f884e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a6cde94ad58f6cde2d36a8809ce36f172dfb1241f3b0df3c4c452eb13effbc84
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e7a84dbca41b2ca346da7853c9734fe262814a0ed0fc29f9a15cc6d86372b0f4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:bde5bd8870500ea3007d3f8e7ca3e1d4a48eb5f504d2655cc05ec8fb0fbd7aca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:7c21c65d1e53ebfa56c0a5c77bcfdba873da7ad82d7828468b07a00818f266d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:d3747184c5b1b393fbd6e56c3de056330a9f73db9ae039d00c3e726c2f80e364
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:1e545af8e9e9b2a13676187e49dd4df568cd45ffd9c0c857b0366bcf2c9afbda