Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.3-alpine-dev, 8.3-alpine3.24-dev, 8.3.35-alpine-dev, 8.3.35-alpine3.24-dev

Index digest:

sha256:5fe5c02af483a28f914587e114064e35ad3f201319e1d6af83e93431d576e190

Manifest digest:

sha256:38bbeb7ffb19c3c579f3e795c742523c9954bafafe793804710f36a0a3b20964

Size

132.49 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:06e11dec55997faea86bac0a38357b9f69b43ec6c9536983b19afe0c82f2cb87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8300146d16de45c5fc21a1f5ffd845b64203fd9deb2d68787ff6cf16cc6bb52b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:af489a30ed11a830c4fd6b7b8f50841b3bf4a7c80b1d243f735b5f0764ca9081
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:bf734ecd01b8325a05aca895c280c3eb88708667b998ed2b2209b0430add52c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:3831f9d5d750c2719085c7c1dd696676d624baef816f2b2a04ef304be81eb298
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:2db9398b1e70333b3d39d7653c9b19620aca366e9acc69b30a167c8252aa9d9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:0b8fb2683606b4e32725660404f6ecd4cd3441749ea85128fd7b646bc5ae1952
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:5a43a80ca93af341db498f675301b4924f1575fa0ddd7f2aebb2df3cf4e956cd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c898013a3fe58833473792342d29700aae6e1157ca0a140eb0078b8a940fe2e0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:1ea30bdb2e0c67f79df09b6666e9efaa1154aab247efd275aecf15725635ae8c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:df6831153137892278767e03156d457426feef5f72faf155576e93edec73c224
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:83b7ef65fabf730447125609b38e944c280c91de939b6f871b7905a07f280958
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:fc5d19fc5aa2536509f470d96cb8908c02118b04621a17eb882f7cd9a434e231
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:7413d721b67187de7ab4ab54858144fa18525bafbb124adf7b7fad72b33148da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:fc0baa1a1e05a8ab67501d8cb6ce4dd8ce53903a98285f6f7abf56dc5cd8140e