Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.33-debian-dev, 8.3.33-debian13-dev, 8.3.33-dev

Index digest:

sha256:5223d49cefcacd1c6ae81ddb4366e539e4184aceb9208cb39e4b751ee7807f8a

Manifest digest:

sha256:6b5e17efc49d21c4e05299aeb1a2228f92307243ba761ae613b58a4ffe3d4d56

Size

159.50 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:1f6412331c469cee26894bd9b2c7bbd23f5b3a57f5c4344088ed3f352c70a376
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a57e5ee8e99b787beda809daa9d4424ff3ea14d7bfdf1c7086ca7ab59ef0efd8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:37b787f6e46330960a4c5f0a49c91750896bb9f65a20feba82078856052ab01f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:89be05544f5a120070a75e2bdeb5f0f2411cba66cba85b49c00af5f6eb6bfa95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:93ac5ee1795ad3338f49620487d916ff1b110b16c40fd52ce4ff94f65bc1168d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:823d5098c51520ca8e63ace0c236bd54713792232a349639524eb999d812d4aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ec7cbec47bb61276539f0c6b35264e72487f6691d9a4aeec541c798716e90582
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:6c55a978323511efcd7308637a99dc7ec7d86aac6646aff99f665929b8b22cca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:012ee122474bc5d2ed4fea82033b1d30e9d5914c9a8dc616a92e8a82db340dee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:bda56b23148efe4c1851e0607e5567390160a82d4f33f1fce98b7b493e9a5942
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:42e3366e8db1989e33d4ce82255d9f180462e61a48b5b9b65532380ba5bb4eef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e3648de188e53af9e37d3af082fe326644f2f8836293916fbc70d3c73f8cb92e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:58b09ab9a4e30ca68fd25c89575959b298e7ad3de2edf67957f2a8028e0c16eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c40bab292e0d0a40e4859fb4418f71a7853a7b665769806bba0761d9b07116e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:33f46b9d3d8dd89a0362d0221a025b6fd9f2d1094a0794710fff91f09a0e7b28