Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.4-alpine3.23-dev, 8.4.25-alpine3.23-dev

Index digest:

sha256:ea0e369832b2466525aa784125a15c003c5418ff7188e3fa6290eed8e3632136

Manifest digest:

sha256:d729fa606f9f8a49e6ef09da05fb33587f24e9016f81edbcb0fe7dd1e8a89d27

Size

135.35 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:8051209979196a1e8c4b2663da22e16a35755cc4ac5211376a6e26fdbad6edf4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a00e81b0e81058deeed6c1b650d0ed7f7e982972b47e7cd4652baff196a34438
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:ad5b0658d59304e2d402810631f8a4ec676bb3966801fcc12e1c791acb2f168c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:3737854617c5266bfa0dc074e317482e723cc260c95332ff4622b1d1e70c7bfd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ec1173a97fa3a799d43534f2b621089c32d1933606b5868248feff0d99e0dd65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f041781dca4d7f02ea9fa61c13413b5e75b8ab5f043dcc8590dd757d7ec614a0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:bbf917f15d3f25033f74fdb58311a6fca64e66ef5b7a5b27aa9524c70ffe2bf1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a2641112d0c4fbcbb3134c25257b4a7a621c2cc4f6e22de1b6e49e43a0095888
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:76aeadb95a672b681ae7ada60a411e71fe7fcf248810e1f897dc14d468d16431
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:2e26e5e954c92d0667c37b6db5768465ca044b97a534d441848eeb115d119e3a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:a080c3e552b42f20de36bf5f0dde2b63305b9841adabc0f3fe2baec3a3b5b9ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:bdc64c70d4f49ffeda304bf328a76cdb25f69d2158d9057c605a47fe5ec368d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:03c95350aeb2ef46e222fec6056bca7f94e8d71b2428afcfca8c4b164276d4e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:1cac178f77420222847fc98717754458ea65c6cc2b577869c0b1f95bc1224cb2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:06234889e6e35a1dc7b81f9fa3702e017f1a8456cda64b2c6cd5bc313a9759bc