Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.4-alpine3.23-dev, 8.4.25-alpine3.23-dev

Index digest:

sha256:23c301306a5764b04372414905622b96faa4a8dbde8d0466eed734cc77e2b31c

Manifest digest:

sha256:4988a0469f142640eb36ba8b190e57a110e8317e6c7d7b6708714545ac71b94a

Size

135.35 MB

Last pushed

52 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:3e5708fe60ce529928322164f74b13349636ce1b953df71925e8cc39b1acadb1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1b693ea661ab74de5056f250c3adddb4199e2f71667b2f4408b0c73f5ff57f9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1ed453fb46dac50df593f2736350bda60a1049902ef13ae754da2d3e4380888d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:0ac8724d63d7229311fd1859e51de449bc211005c9c43e7dbda2855f37f92eef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:14ac664047b27ffce53382fe7302416dcf2174f0677c0d0b6fc778e130944a41
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:7827fc5bf4c97e5c7e9c0f237a515a0230998af126f7048c92cb3b9c1ae6ce43
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ae0732f8199bab3a68f1df28c09693639c1b684d1dfb69cc5589d3411c319b9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:1ea691d058613f07997df0f171126f7c2151d870a1101cea2ec4fce8c79a3da8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:732afedd9e958c2c4102de08d3268255bf7275871125053708bdb6931ce37a27
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a84ddd8c12ddf5f228a0b4cf65a7be01ef92c3394619252bc09f6e15428cba18
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:39973ab40b7005ce7b41c949b3216e614479b6ddd3dc53b4ee0e07542be685b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:787b8469c2f40a374ddb8343746b7f60d09dbc0c0284aec6402b8106eb40f80e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:20cb1181c1f281bac5a86699a98787ae7adce58c61e52f44142d683ee1cc30a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6241b518781c9f79fb2bc3978a36e8b9bd1b7659e9915a636ae519d0675879b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:69efcc0796238fa8c08884a4fa17ef60f842c04b330348bc79ac555634ac755f