Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.26-debian-dev, 8.4.26-debian13-dev, 8.4.26-dev

Index digest:

sha256:9f7c3aba8703285f0225f03a7f3fbd2d3fc9d115c5553bffed206f34e109c56d

Manifest digest:

sha256:352423bb902a839508d621cd81e4a43aa1c430382bc259cf784c69cd36d49feb

Size

162.95 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:c5bff038408f864910e55f7d0fd6c3975794c6943284104aad35f583c2a2ef0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:d35f633f4a0a6cd877f1c4a213c74c21e054bb03436a719e5b6bc5f4e9575ff1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:14b62d3a504bb570b3d6270bbc9d9fd4fba16a402e2538f8789151e408eb8066
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1d441cef55a6d72e1e0d3c54f03583347a7b92284be2970bdf7df3be09fb07bb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:cc9ec9f786d3daed8d633651832e01f53e5cf4708bf4bcc935e1cb3e18e37995
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8b8517776721cdb3b4df4827bc33a3bfa43d47cd4cdaf6a05d55d8fc1b294f45
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:3609e4f4de5f4f77537425351cf21521481ec55801e30a762af54c369111d1bd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:b8bb6bc3714b8f319e5bf4760587f35458c4048f349cbc8162527d4077f1cdc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:080501818a0a0cf5bcb7d17f45d84ef9570225b0ec318e0bc8050a56facff17b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ac205d48565e99cb4480ca17534d847ef5eca4495772f822998a9eb8acb850a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:603d66829ebeeea419f5f3a2a6bb4a9a7939445144c62e01f5c6035095400f84
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:d86a381f13a3213e3645e9adee80990d21217ad3f151880935f3d64d9a102aff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:3369adfdcd88cef4bc3f73e514dbe8d1fb974ef67fe62b04ee76c75121ed9b1a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a712101062a687cf23d77053da98e362a3aa8c865b7537030a6660ad554d4ec2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ef9e4602f13de98ce81fb6d0b49a91125cb5ca3dc8234de1e071f02ed5010525