Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.4-alpine3.23-dev, 8.4.25-alpine3.23-dev

Index digest:

sha256:5c6424c43ef239165b47b0e8c0fc3a01756b76201d4380f478a9380b8f0b582a

Manifest digest:

sha256:efa8195fd1b7aa93c2a26cb630d3e4d4509709eb1ad2bf9fa5f78f9f1478f62b

Size

135.35 MB

Last pushed

23 hours ago

Vulnerabilities

1
1
3
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:5c398d2ebca7609175f1abc698b0055d0c6e12f7e33126395ba5e59a2dae4353
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:fbd7b9f68b70de936b45d5bb205417e47d730ec44114f0f9b431ddda73cd5482
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b68e227a895079434e916c731faeefa680e3361e2c62dfc16f7cde6a3796edfe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:69d0670b6501182710f4cf2a0fc95bf0f8deb4d84f074f8855b62e3f96256501
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:19740de7779644c6010c9419038aaabc9c583827e0477132d5912aa1a4cbed51
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:62f5ff85a4c973065dcb0acd857425a622c4db84bcd1efa27bbb17a4d8b90999
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:4fb99ad22a3da7178d4ebcdae90c571f6e66b9d9c58e96c952766bdf0d21a232
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9d718dd7b5b1d109e4abdf471ca4341a29aa57d306495f54dd0b185dec20303b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:dd03a4acf6050e863f6d4de4f9272c8ca4dfce149bbd1ad98d72676c270c3882
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:bf9383dd369f44fdf1eca6b0f72aa4c2ea953e2e14c43de871626a818925caf7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:8b741375dffd5962b334df2a90fe7f520610f754e6932b9f314d9a5ee011e7b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:fe0f7c8632713a0db42c73253928f525824a4a703bf9c0d6c176254941e746d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:33be5b0c1eded57c0e742d1aab8a85c9baa42df97350ecd58eb09d38cab1f94e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:e4455bce0fae4abaa2d620c6415f1c6caaf1221af5e8196fe081f84c5d68c9a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:4e6075e6226a82eee8a1c185d933fca73737a124224119d8ab13e708d12bb4ac