Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.3-alpine-dev, 8.3-alpine3.24-dev, 8.3.35-alpine-dev, 8.3.35-alpine3.24-dev

Index digest:

sha256:5bc21ff5f8559d5c5149d430677bcbb28ab3db4b7ccced663bac3017f3108a43

Manifest digest:

sha256:dc311175c0cf60caadd2d4d69f1351bd16dbb91bf0fd4be62c2afae173d64454

Size

132.51 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:17cd279dc0d16b4fea00cf00f1f0b43a03f2cf1584d39b389903e45facd1e543
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:38ae2cb5766c1c97b446471a9d8170b315de4da2438779d7ba887ee4f9352787
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:0942c7ca4eec11c5d7432a497232da6d88a1e810e17b6923d0204f3536ac8c95
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d351b552598d31955c256cfd2303d041690f45a22ac5a0b3ba04ec5a3e083531
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:7a195ce986cf5c73c76553992ae7995189df405dfec82a97216e211fd356b91c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:2b44068bab41c346dd880d68a627be00bfc3cb2db4c86d146bfe2480a26eda2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:5166a27caae7cf9134b3ff7d4f1a1197d34a99546306f4dcd31bc13a1746edd8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9129f112bea3157518ae7a5e6026e84b4cea0d65032a1b1ffd4c557d55f8b609
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e24c096e6f927b3b84e6b28ef5386fca2da7795dbcefb13e44f1a09ecf8be385
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:9f8b767cd5258d4918f6e19270b1c4cd231d23000e59106ed7293ac699fef17e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e086ef8410f284aa02b0fe26abc3a5490fedf1141b1f917fb24a9e1aabc41a90
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:b07db0c35b7e5cf1f998411a53c6c272570578f774f5c5bb42005f6505a50fea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:240a5274c5ef7bbed8fec7f4593a43a703da25e8c0c44c31ca27b597bbb0b25d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:5abf9ec597f8d4550f05e8540308817da03227461a288c21c346204c45344fa5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ec9b6265bc1434595b4146d6167949184f6dc5585faab8c1ee53aadbd4fa764a