Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-fips-dev, 8.3.35-alpine3.23-fips-dev

Index digest:

sha256:6f273332897fc2a4d0c82a5a3affd496f97a47ad61f12e86147e0e55bc9fc3f7

Manifest digest:

sha256:c92148f2565109a34ebe10bc833403f21686a1eaec7bfb42ae12b63272cf93b6

Size

132.99 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:382c2bfd7e63c1944eb18eefe55a2520751f1ca4312c703749ce3b5c913be1f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4cfa8b9264ff99a4140e52ee95840b9dc68c6d093749918b2b6eb089a6289b35
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:9bab01904db184dbc97515304a60d5fbbd9c9e574d43774d97ed1ff246c8d03b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:94ca26e2d63c5bbdc8ed3a03fefa87e13fb31d0068023392ccb1339f1309651f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:542980719001c7d90eca498d3c69d3e7b272604b60290041cb97bf90699dbc1b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c1f7a06490f464eaee25ea407e8cc0835855c7d6f230de4605fd53d3daa0a67b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6086af924b0a9d31d642eb28a06dc9ea450b3a05d8d1e53d7fa7a7f6139ff6ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:45ebae57cf7a20b6b3ec9444b6d10ac89981ee49ba000d0e536ab0e5956c9a07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:61336fc9f0895e88893dda3c0108601e00fa3da5b71094bf8a7fbcc4c1ca931d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d3817ea2f0fbdde714bf86728a6ad3ab44688590cc4d6989303044cba72d6a0e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:a2439db539b5c356c01a0a3636bc098e9e39490600bf9d1753610ed99064429b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:8b087464ecb33fb89b72190c062f82b2589baaa95470fbe85139f0fac5c31d8a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:5e18bdecb3bea6032b81220ef05d9dfacc685f6c3d2d8041c41af0bae99eca19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:a0224fcc2e2c4868040e76d2121e2bacbff223f491607989bcd4e8ec7fddfb03
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ca2726acd64dfdb084b7b96621d7fa87747b53bbd6ad7245148fce17a92b0cdd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4cb1b8a35fa48490f057dbaa929422a1c4efef360cec8be5337b14a3f93de9b2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c8d4cdfd49e54a3f15e77fa95040538f5594ee9451fac0da447b95024a006e4d