Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.35-debian-dev, 8.3.35-debian13-dev, 8.3.35-dev

Index digest:

sha256:4bb5aab3b4581d9b536257804d65696b768328db4b0340b998c73a67e9d41612

Manifest digest:

sha256:9e201652b86f0e9d84cc0169d5c5ed21dbbceac45fabdf2593d0785e622a4ea3

Size

159.54 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:e19864dee7c6573bb529326c4574505833d8a3fb123ed259c8b0481f3d088b01
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:c3130d686fe167dc4c3fa83c7e102d625cd9f459c3d5eea096f9d6e63df75130
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1bb811837af0464965a564f003d598cb6f341b052a2a17bec8b25c4c45e2c2f6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:96c6191f96ea5f624c4fe82609e802cc4b9186efa8673c96c4eee554107a85fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:5c8f62b2e098c4c08842ab0474938fcacf17d8774c7614d1aaa1769f19cc6a15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:a812862a6caf5023ca918985039b2cfec6220baefd1312a1badb15bb2745a276
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:6d986b043d79e68c991f113bfde5bac7f98e39be1a45d579fc71372347bbb4e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:5260ef19384cf0f07279924b317ba0bf9894e66b0c708ce8a7daa27fd7af4b14
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c88b366a415cd4878d039cc5b214af2f14d7055037a42485c5e446b2a0d85d74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:5c585f7f377e760e69bd1bc9e7cbf06a12fa345a2dd1ab4288c56b25cdff72c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:305751a8b40295375aaa4c157abcc7674d6faeb85b1a197308cae3012c14713c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:766c2ea6b488346062b66b5b6720e5c0d63fafd5584caa595d9548075e35d20d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:05b7e47fc3cdb25ed1ccca13b5dbf347a892480291508471a342815821f27556
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:ee8f5b42b915d554ce416c62e37454dff6503a72242b719c4ac4944975e51913
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:4277ac8581e135a891d16e11757c5e089d123ea40f30f973ef715921e13ec71f