Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.26-debian-dev, 8.4.26-debian13-dev, 8.4.26-dev

Index digest:

sha256:b96c3bde92e463c19324fdc7b4fa6404d7e7f0eb52c7bc1b8eb3ac8c2e8974ed

Manifest digest:

sha256:11ab7c8605156f6eec711aa49f02cc93059246e211d63e577708fbaef392b47a

Size

162.97 MB

Last pushed

20 hours ago

Vulnerabilities

2
4
0
2
1

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:dee03c16bade11ced340a0740289d69f2bff7f06adfb79a1df02807366998a2a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8c07652481d5f324c8ea00714fdb6cecac79912298597d133a4ada5c4306cc04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:138a4cf1872a26acf2aa6b152b8150ad7153ace4f5c9aba471c4a8a00bf49870
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d6f9de4e761eb19f6172258015bbef326391820b7da86204b7d5d93b456181a4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d88303729dc0896e5de143f2f5a3793059f076bd16687f2a02d936a2ad9fb9a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:89a0b3aab197f8c0fb4cf34294a8b0e332e4465a6f1b27228494596db8046f66
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:35375658710bb31b0df81d057ac9aadf112c9eb4f67e7a14e7250b0924353fe1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:1b05f2d3bf2cb43f61eeb8801afda98751c42fa058905917746f97c1a838a97e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:4ca245c2fd58efa3a53a244f420fd3512e1bd04f4b0f127d0f97db03eb1fa107
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:3e1a777959415da0746dd3052a6996d77814813fafa073ab855e32f51607e30a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e29831d04cf6f5abca68ebbf502d6e475a20820dc52c3dcf5f800e39f447a501
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:6fbb3f5b8d6205401424be8c0073b2f7398e6ce2bbc9e5a1947b333fef5286a0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:e4c2c2fa70ab4bfd4b84697675c929e66909ad82648e1a194f646a956ecac379
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:0d20e194bcad4af53d457c2c306141b6fcc4a706cfb7ae0a7f355eaceb9103fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:8dbdc763708f266e15726a5cd9c004893727ed426eae21a78557f9b7261090ca