Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-fips-dev, 8.3.35-alpine3.23-fips-dev

Index digest:

sha256:a2d6f5b2b71468de5d6bc55fa05e9d681db9191c239f80b712fb6058feec0d59

Manifest digest:

sha256:3121e4fb75a4f72a07571210ab96ab5981ee87f2a3d34deec16bd113c95069df

Size

132.99 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:75c5562db1d7ff98101001869501b9328bc718ee4634ec2a7a1cd87ceffc3e87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:209d7440176927dfdbabd62ae85511925b354b3ff50af866ccb50f322563e971
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:6d540f0821235932398a9ca52d0d9586dbaeea648a9feb1224e931a7ffa0c616
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1b5be7b8c7cc7537b5c049189ebf5a3d1caf794312d08069c9d12bdb34965f6d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:7ccddd1a8a4f17f78e83e515d386b64b0f4f586afb54adc050fc7afd5948c4bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:3722c3b5342bfdffe9369909602475ead7173c967e05f6f7d85e5e5cfb56a972
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:de30d1202f9a2c3c05a1e06ab868535c3dfd51ab6f277c645e5224a6ce8e8b72
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:5dc05a60002e1844b5505b1bdba54350e187985c2670cc697601b15e2fc06ad3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a2ae9f1494f6ed250223372c2ffef7d9de735c91d6bf8d1212a3b2ed394b5da5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a1b28654f8a438930f65e8fa4526bc6f0f5b63904ec6dc9b639f9e00680ef8e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d6dadea4c8ddb950df78949ad04cbd958b99b6e6ef5bbda82942e004fc333a91
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:621628711fb0ee009f92b6c3a74eeb2b5b0fd3b7c7e30337fd00bcad3e25ffec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:dfb1e80eddc7e78f000a10746b80fdc6331ecdd860811b1411a0a4870ce40fef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:8e8b6538331b1af2bd695693a4bfdaadb24201691056900a9bad4109d7b5b7be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:1b4b23d3f5e43d9c8a83944afb3d4a7c12de747368d715b192fd68826ff8a29d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:20047f80b6b2c3758c7860727657af7380039a3f0aa929f6afe493990c840e8e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:20929732023ed5068a956ff9949b68a3c383fe7ce99ee8e2e58ea17c03548234