Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.33-debian-dev, 8.3.33-debian13-dev, 8.3.33-dev

Index digest:

sha256:aead25ef85445a11b1c677bc1bced989b50958f95c95a54cee7c0206a7172bdd

Manifest digest:

sha256:1287ed4f4dd631bc804d097ea1f31ee07a6837893fa1bb791b5fcc1f148be075

Size

159.51 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:156fd8dc37b14c5d3b811770d13f66b6480a71291b4ee711c3943236228179d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:876126519c5e86d7af02be398e2ed3b5bcfba2e76f61295611973999aa1d3bbe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:ca16b3228720482c421b73fc1ac4f7346f94081c978a8529fdaf087c7bcaeecf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1a16157ea9505ae415f6211ea0de8b49ef6feb2d3e4e15e0c8925585ace602b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c26a5858baca5d8675db65d4b2f4ea398cbc34d5ede082e7b57987d129c1f864
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:0720960ee44fdacc455dce00b90d622099f4b70214f9be1138d37a4c04857567
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:396b8c3a3e5b6748a676666f0fb71c0f7a23b9dd398e8c969cf2cf7092b92513
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d7a6b2114bf9949911947023c82909bff746426ac42ee4c7a04d0fee1dddc638
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:812b98bb24df16ca73fbbb00d7ec64322d89f1c8de6f34f43b80e8c07a958bcf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ea4b3ed353c2588d17596b6c5b11f8a3a2dc42a7df83fc2a1be555b339774e58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4817fdbae42807bfa542ebfccbd30f7d4fb0dcf7a38fec4ec7024619741992e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:d0f6d89fbb802d7d529c648b89b9e272f11caf99b996350706a5205db550ed3d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ce3d165575e652c59b6ce3c771a2596137fba19ee9e3a1a26e33cc4ea26b79c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:e556e953187645f4750908f6772b928f4da6d422e64d7ec557bce7f246136836
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:76f287c4dd49d95c6123125c3c8018a3ad87b6d85a6603c627a234fa3af8697c