Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.3-debian-dev, 8.3-debian13-dev, 8.3-dev, 8.3.33-debian-dev, 8.3.33-debian13-dev, 8.3.33-dev

Index digest:

sha256:97502f017acdcb17eb2eebb4ae078f3d106fc0925dfa2aed1da478d7cbd00657

Manifest digest:

sha256:f3fc90874d284171ef55733aed9a179a5cd098a212eada892adbf228065565d6

Size

159.53 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:eed77276bbcd39b46c8c9059e93249f44fe360770f5f5ae0ece9208d9120a892
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:67758098e2e4da23be708f72543da2464fe14d76769ebc0c783490c75aec7c08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:ffd9596a7394fc1c24135a38bcebac072ccce0a38924bc148a4229d1ecfcafa3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:eb230c8f3aef81d89da50c4cd0ba7b00c4107dc6f48298e0fd7c8a8f3d21c065
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:1defc1c80b21f1b6f38e76073857aaeef5618e3212148838669475a3188c8af1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f63a0e99957306bebd0a6862c6ce98eec9a717729ece7bcf44bb529ddff21171
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c4e95d81e04fb2328045cfed5a73f5359c05a73d81eaff3f4a2441beda832303
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:1fe495459755d697e66d1284c1341c494df803e8f8b24c3276629bb699087c4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:eebf33fa57045cd2b858c96177c60f9946d01b490770612445aeb9cd016f17f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:c221c1a104b1e23c05141367901d4e7b31ef95a89a52bf47cf13fa559cd45c09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:2c8759198c153bc43f31982e2af8809f3f7e972bfacc0a4c4cf56d1064b16755
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ab36c2425c287dd27c17f02d395f995eee1a1f62190166b685476432b0048b3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:30938b31a9c4793be5d604f03ef9332e10a32478268bf25604aa37ce54d15cf7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:02207826a944b73a1f27732cb226827ca11ffc0db4c0be96fff2684a73f1b138
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:7f297378de181915a5ad605f90c8669cbd1e9ea39cc1adec5d0fc699d3a50593