Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-fips-dev, 8.3.33-alpine3.23-fips-dev

Index digest:

sha256:25b0f82614bc371f886def281a4a0f73fa7debec8038abfd84b03a3bc75828e7

Manifest digest:

sha256:39f09b0a0cacd64ef21cd214d2dde2facf13120b34a4c874ed0be488d785b70f

Size

132.96 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:0cdccbcc8be152a385aa6f992408f856b2c8cd9d97d2ae7171576375e39dfde3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:290a79704cb15ca7429b20698fe58b84ab15fc1bea0605a5f68017495ef5f347
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:5eb09256c0d0e1fe5d963e25cdb01233b2c922e543bbed499ff934ce4ca47195
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d04a592a9618292c413c7dcc288d58e153b679cd139e48f87c724ba5f5b15f6b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:95f58c2b0d7d92a86bad5a8322e4a55fc623fc07da34d5eb3f1f70a335e58f5d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c763781159d2120653cc14e927e2143d37eb7fd695d3c192ba613cfd1be68ce4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:9de4886101b1da496e9c7e07e8c4e864495ba78056aeba593c9305237b2b6bf3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e16323e0aaa1e23ad91fe4bcb95fc79c972bb80e1e93cac5449a62cab295240f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a9e4ecbf9843b0b7f38f221c51dc0f912466c3a19e3247af91a33a8abd577cf8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:da267a69f263124c86526ffceef45616c02bb1136b8bd6f6ed94318f3a189e77
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:00615d3a520892be390af0ab4f56bb2f11bd0b801f901bb033da7de902144cda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a9c3717dfa5a898c96296cb9b54a2c8c4e3d726f8a0a8e616bce5611eff04540
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9b7e826afecd7c8a56aa21a37520d0637b23e249119c299cd601c12ddf873b13
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:bab7472ecd083c2c6c577d469abff873e132f7f212b0acd61543b71ae270ff67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:c63a611563f120434a73c4da2570da7f0a530d9e2ee4c6f5f0784a8dd55e9377
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:0d23e6936fca514933b1150cc9fbcbfd1614d84e3cb10075a8c5a2a736525388
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:f4ce1b34448847670e57a25856e95ff063c4f160bd5a4dfcf0ad23cf91efda25