Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.35-debian-dev, 8.3.35-debian13-dev, 8.3.35-dev

Index digest:

sha256:7f3a9782f734048e88a53894c1286c7a04ba44668e5d6167c5e9a7d570192a91

Manifest digest:

sha256:270cd28ea6b162f13fb36135510286b15811c52cd5c989612b0ba395d15ceb5b

Size

159.53 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:3a040e98f27026c8e46c0376d75c41fcff1fbf33d4184aa1bed2d7bc2708a066
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:eec6f1bfceb6c8f0e9a57cb5b2ddf4be345bed98c7548be2df826a7ea80bc517
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:3f025d9638e2c1ce143a105c50530a6803921dbf0d0dc36694a7e7daba170be3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:165f67cf3120524d53a5f8e95f54d1ec616d064c2f33abfb58fad6661f433357
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:3eb1a3e8cb1e1c7692e2acd4a4eba4f17173c1bedd57985bf62609634756d72c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:ba2eccb6fe797fd3d715a70394e500364a6e9ca0b37f3bbce88a73cd39dabde6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9790c06378aa72295652e5300d2740d8b24e07e884bc0eef5b9bf8fba17e8c97
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:efc28d9bd146abcc36f8647abbede32718e5e31a2b8878f8978fbf457040c339
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:71629b613a103db6a053d77d692a0c48bf3ebedf80ee040e3af38977855c28c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:71b81c6d2c1eef1d03bbe99870c214d4c4c370d17c5349fe70ba11280f9f1e66
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:33985c5af0cd0a7865b878bfe2157450bcdc4de08ee7b059ed28535ba728b599
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:737386473c31d7fa82ddcca041adce0225e17167b64a6b76eb14d4a9126866b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:07e53e2b832e32c462ba2a69db26129a3d8c017904dd085b2109da502cf1b086
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:7b0fc4f33be592c528626aa466707079b379e1842e495d26ab36aa85c0ae1ee4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:544e4227ab15fb7f9a45964a457a4cad71b973a9e23e799d8cd93ea4af35457b