Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.33-debian-dev, 8.3.33-debian13-dev, 8.3.33-dev

Index digest:

sha256:a540d8fcd0ffd1a5e1b8ad1e6a65f99f9c44adc18be75243fa967b94edd8e36a

Manifest digest:

sha256:49f1f876b88aedde8b89d7872edc873832dbe384441a01905b36e1efeb0e0f55

Size

159.50 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:3062ebf29069fa351e8754b0cd5f6c73989811064e2f0f39f255d46e87a1621b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:3e4877b3f72f6a792b07d22d8946af850f9bac62121351508cb677118fc67072
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b94a74197208ba27ca290f2831ad0a3a8cf6abda755b2e0a729d216587c20189
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:285551ac603004718e5e8be08929c623a16e3756d8a6cbb4f0ec34ab4ff20036
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:96c9e35de2c45c833ccf7bef1e9f34e7e94e2d0c42782baaa8d71625033a380f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:054dcdbfac25cd94fe8e78f9a2ac72a84616fcf9ba81c1f40c93d0c75a9b6752
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:24f9027dd8ba5fd5dd9b3df8dbbedc22f44073b1dd89cd9cf1bce4bbaacac656
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a818375bfae862ad4af13237a50d7e32beee7635a6ebce3b3b7fa5f7b9110de7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:4c5ec59089bdf1e849260485b24b0f80b62d2bc4dafb95b96c2cfb7f763bdd69
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:86e8c0d8b9b331cc56d1f76e7451c456d36802177d994dc0b3191d6b0c6f40ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:df4d3d1c0839fe9108d673505fe624c9a313c4582771deb10153853927386ff5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f93dc49c929ac6cd4c27954a3e673c78529717a19b975a41c6c994570b23d5e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:a528d2a1bc4174e119caed0e9391690345aef049cf17712244bede86eb96d20c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:5ed9c8ba04a492035b462a76e2a6870ed0f715645cb4303a6c1be2fc4b7257f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:60611ce22a8599d4266367b1f2f17744e36dc4e1fc1af874e3f8ecd390853bea