Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.26-debian-dev, 8.4.26-debian13-dev, 8.4.26-dev

Index digest:

sha256:448700c7a87bf0c14f20655924f1064538dac0e8d492a1f6bd1e4e568cec1704

Manifest digest:

sha256:06333da87e0f8e4cf6ae48445d659b30b8172e574650fd779b55bce69092eddc

Size

162.95 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:ec108b918328347e0cb2a303b96eaf7b73e3865a54ae699ebe1a94504fafce57
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:03425682085b9512e5dff9079cbdf2c2cfb4ecee4a7e5e31efd592183af4abd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:6cc7856c69809f1816f4f0ef8ed0a9c10163ccfc586b36304f78847d19d58f02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:a79ba1fc6b38b8781f984888dbe81cafe350d7340c3c4348ff8661a7577fbda3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:46068adcb1e6110c497a49ab1b2eb7698fae1d55fad426412677167f4b182428
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:ef1c7da754112e8e0e5b509bee9f554f411adc467140e7df3b350b578b7e2c47
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:8fe3a08666f16f10d9ef5e21b0a0dbd4946b8ffedbc8443374fbc678f5a60c44
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:936726067b770b9b54efadeb409f38e8bd5094d58498252fdfa9d2ad26c8754e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b19fd7fbcc872175bb030a5262576f73c5d3359dfc8a4069fcfb89078841ad2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:8a877b811bf4ed4f608d2e79d276b6219128ee58cbf58231cf7bb3d2303be008
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:82bdc67e796a3b16ed654dffd578e2b0a43837f4b3b24a93da927748354844b4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:5cdf041eca9c25de00d281ce6bc50c2444ba61b18a70e9651c50cbcf6ecd2593
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d3e3ac4c47de710c63e35de95e6cd718970fd5757b4da434f107926f7f49f0d7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:fe46838e676f8be9a3ae1b31a11d5c0b64da3bc969f7407ea439dd2124e5b10d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:f4240aaaac19e49b1877b6047f16a1792b5d7913deb6ca7e5f682ba567e6735e