Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-fips-dev, 8.3.35-alpine3.23-fips-dev

Index digest:

sha256:38ee4981db41e3f5a40dadfe6e68dd43d81a84c25af1a4044ef91f7ffcdedc96

Manifest digest:

sha256:85f6dd2fdf9bceb12663918709f404bb96edb50b69f9a4bfb80473a166442ef6

Size

133.06 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:5b374e0bf5c7e4b3a6c8613a0e107686f2c4dc8bd83f420d12303db66358840d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4c38ce67eb1b8d6c84a772f10341d7de5b8050ced71422923890f90da2d626c3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a5aacecb0292a67530378acee59eba475b51d0eb1034566f173f5050e29adf6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8c1b01dae8ece4aa1e9aa81751dedde0fbd29ad666747a9f66401a2a36ba383d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:91130c9ba6cabd08e41274fd721866e0a114dba6f616f97dd9fda04b16cebaa7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:fdb1021d55e8657a9d095aa4433fa007493a28d262cfa308a82beb7ff48708c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e49560c2383f020ea5a37013e7fa3eadb2b739274ea301656f4e95ca1e3029d6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:b2669783b37ad60849efdc347c0322de2aa55c494f1d7c419af67fae227d5767
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:4b94e70c02fab8a128e0f4208a9d69afe676e9284bc0a3ea4f2a494836c3b2b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:697827d588c7d2d85288d1d70a6df79b8b7197fe043ad236939a7f0db74e16ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:8e702644fb8092ff461d78f92869407d63891dbe4fc309550b1d04fe76fc7f6c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:069db1a97b953763a0271894234500be3d60e414f3a0ddb0aa2ad11b8a0fabf9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:37ad191cc61740227307bf5b2e31b8ed44f8fcc2db7b88f3c89f9404d0c43d8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:aa634bc0c56403fbd7598ff657c584447d3c13870e9125ae161c6b0787989b8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ed2565f0345f8319e66352fca68c2ebb62b71eb40fa3e2bd7eb49b2ec5555ae3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:445d3be28bcf5eb0e8b969cd5758416c1cb375b38f1a17aa3767333372ad48f9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:18ed29f5e373da6632db43ebef0bc121aba6c2b818ed9f7e9614f4c2e52f5847