Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.33-debian-dev, 8.3.33-debian13-dev, 8.3.33-dev

Index digest:

sha256:6a75d26b3cd86d4671d1d48ee618c121f76911b71505c9795bffe04e0c366f30

Manifest digest:

sha256:931629b59b9782bb830a6da34152e1132da7d30a5c7b49d0f8d8ce25a5ab2842

Size

159.50 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
1

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:58da060052313c76d8c3041b450c92185db0d41cc22b986472d4b7c47ae3441c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:2e56f5bbd366b30584c00156adab020737c636514606868844ed0f1c387379c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8e11df39e5d6d7f0d62aa8258f2108665bc141f9ae659d10acc2d5816b8a4a40
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d019cd5baf250012eb2f08d17026ea68a34af5dbfd12d2a2065b869fe38f467d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b9ebba9f59e395e596264830f07b2c8d3909b9036183c6deb1ce7b6c3aafb14f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:2e90bfed541ffc317954e0ec736d380112b813d33507fc0208b3e0f7061833ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:41ad854a853d0fba4fbbd9a8f7f63d1931e9db38fb7dab04eb570a57a12f5974
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:dc35d359c7eba6b354db65a71791adabc06f40f82946f9ebd80f4616bd5b8886
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:2228e812075223f13857298bbc38bf364bbfd06916465d0c2c9425b791b83beb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:26395c9801b1f361d4cf92db69cb090370e75012726d573738096ae68770c1a9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:01dbc44f6c01b8f859bcb7b28b0110ee9c78e5181499b36d06b7bbf28c3b5b21
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ce54ed878addbd048b1463a41eeb5bb3b6d5ff1a0f1c169691f89c48ae8d92be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:79c4a9be27717907c054ef3f8ec2861ca6eeccc96418928332206784a876daa0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:369d3f0531ec1a56697438bf36a7f4e4ed27599fc4517975870598ccb9833362
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:2e17f10c937f5ad0027c3f5c27f2c42e109eeda1ba75b5b4a74ba5389a9bfed5