Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-fips-dev, 8.3.33-alpine3.23-fips-dev

Index digest:

sha256:cecebea3f589a51c2141ccc2eff0926dd65ef7b15e4f6299d21a6daa86c22de0

Manifest digest:

sha256:cc4dd9bbbf5774a2b3eff96ef8156e713dddf574caef4f70a6fd7200237d85b6

Size

132.96 MB

Last pushed

1 day ago

Vulnerabilities

1
1
3
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:661ee6929618f8328191a99d66e9b716502c6253de4e822b3f71cdf1fca33bc5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:6992202a614d80c773123d7463d95bd2723384c5694724fbfac0b31ec8be1a55
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:9462ea3dcef46ae8b1dcb9d8a269226fc1a4b15cafa93bbd713f8d0e64bc05d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2ca58ede50919a96c251d7e72d27b8005c0161a7699fc6c1ad58c373605286ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:a6bbd737538f81fa64991df6d7c03c00e7c148b887ebfad94f4d19a2c7fb9b1c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1a5053b144baef628cc1a03750218b6e10a6c4db093a6d3dc69cc9045d2a8d30
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:afe5505a829b59b0529ad2e904484125fb8877af8e55ed71ce0000c7a8f48da3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:077b88df31883348e3a86649b23dd7d73e734ae73f431055ad0a006cce49c2a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:636b82b82a27fe73f95c1cf8e7c48c98ef01fbe37312367a70f8d4bc8e956cc1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:cab492a3c715b1edd415c47c30ba92b3b9e14c5dab09a64941bc89c224ad1c59
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b16179c0a161c32db52df5d6fe0f878f862ae7309d576a454ebd04aa2f791579
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ce0736d629989e76af516d69c90647452b2cc3b0b2cc26262610a2adf1e9c546
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:3c2df6fffa96aa90fc92ba1402c20d6f586f7793656ca911bbfd85d7b64a8835
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:882729f2a148bc79bfaa318777a3133469898406540ae6b8e91ef6fde857142a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:08b64dd7c3256469d0f5af39e34ddd6f510b554586cfd1d631d14fe0f6eec186
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:7fe4962538bb93d5909279a86dd9cd975d0e3496c16c33124cd72b5ba2fece5d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:d8c3a1595c29920015a4582db5a97f714eceb80c503cda58c4c358ff1aa53a1a