Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.3-alpine-dev, 8.3-alpine3.24-dev, 8.3.35-alpine-dev, 8.3.35-alpine3.24-dev

Index digest:

sha256:b0209aea00fa9988b71b5b77b6ece251f9e513a4b52e0575610b493bec7f2461

Manifest digest:

sha256:befca6e1d287d134ff937f430876b2fff8eccc63ba2dfed3bb10735ced2b0f86

Size

132.49 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:ce08d9148627bba30531e5ff265a69aa87c58ebbad18048404b26d45fb68582a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:0113512d0622c06b4b8b69772a897815d75e49de7e177c3d85983fc0b4f48546
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:22d9f13af286e72645aec8a11ae2999e2d4bcca240bc48d99c777a31d870832a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:6fe194564630d7ce565bece6ed74d832b9a1b11fd96188babbf18801dfbc84f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:9325c37be7c922b923a688f87d7f45fdc1e0136f03d8dfa542c4d45e39d4cb54
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:49af4e860f580e922983887ca0e4253d859a2ef509983a2b15cd9749220558b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:4a6775fb1875163acd2a15883d0ef85328c86926fe79d36a8735a81130104b86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:61c07aea98540e0e5c4a5004839560c7f6262bdd7a3d2836e62cab218b9e74f3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:46e2d582ca05d1a06933f849277975e38efa248932f02cdbeb0a07ad7b6365d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:e569c4d649b39f304fbe95c48a93dacae7de58018d97f9eeb246c5c6aa5da7d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4ea949f47d6567f5241850390b9f32dc79dccd476bcdfdb928e8879ebd12c106
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:79d7d42b19453fc11a687a46f2632ba5afface5d49a0056c3961ac89b7be03cc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:402f4523a234fd6bd85f76d0a47c3c2f8d7619bd1cc0a1304ce829ac6152bf7e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c40e289e8bfd3795bccb671dc9417576c8381fe6e066d93091d57a303d2aae21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:61841400fe8bd2b16612649cb8b6d79dbb0488076d283d07c9ecbfe49c369245