Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.4-alpine3.23-dev, 8.4.26-alpine3.23-dev

Index digest:

sha256:20bed5b1a6444acf0bb2afca59ccad12560c1b546b259206500bb7afd8da33dd

Manifest digest:

sha256:d7a8802480b5fc33bc63c506e6cad8a2f4bc108abc0aafa1cc47ae5b9a529d6f

Size

135.43 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:c48a1733a23542e496045abb00fd7d6039a9fde441a16a167b1e67db78587994
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:b5141fe40afa3cb24327fc0e4cfd5899550987e701878f62bfb55135efa308ab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:605b4932b6119eae4b037f65bbc55c303b25781cdbff2f1fd082141b5d3df337
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c3ddbfcb40abc93595febc22fba7caf484d58657eee74312f88f0c5e8f4dc4f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:0a3d68939be489330feb5dbbbb6969c909a782c5a2625108dbe2a043a9bb6e78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c583b1b9d8ae1be91ba77f2b8df69e19b25094a08f30fe3b25200471551f832a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:085b3f36d4010344f5501a0fb7b0b619a772d58482f48774be53e141e91f4e60
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:f618ed087bf9f42f9563406ee7e6e241b4ca3f09bf7805f2bce2ba4ef09cfed7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e821c1baa92fa705c1cc29b05b80eecd9bf84327625fbb6bb1dec408f230929a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:41edc8d46223a9123cd40bb699377240f4c90dda8f6bc412a7479e5b7bdd28cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:6cc1cea9e599080cf5721ad46cc4affa9ec2ea313764d767ebbf6da507338de0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:788e2a96154a02a6a07c6a333049fe99579f850bce58bbb1e6a8e197a6249810
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d551abecbaf8c603bfaaa546a5582f5443cd8b0d249fd95b56595834e613a1c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c908011d12e2aa571d3017dc3adb27630142d0491efdbd448f947b7c034f0ba4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:52e6c0324e40040cc65b911152654cd94efbc9cd97690d7e692929562148b4a3