Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.26-debian-dev, 8.4.26-debian13-dev, 8.4.26-dev

Index digest:

sha256:552b34de377382032a903bea8b14d28092c0dfbf78cbf61db10412987f491fd6

Manifest digest:

sha256:6466a25c1c7b1ee1e92b1e4fd7c1a73c5b85d63112c995c0a1429ebb60b95a6f

Size

162.94 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:8830d6f5471e715ea630ff194b3cc60333e238a8be9d825c9bfdfae9f138f4e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:843cb603b560118ecc5ddc07b82f3bc2a123c02d1e076376c468156274779660
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:c63344f0b3df61a05205fb949c481ec03356e46e0539787eadeeb278b74245c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:5421ccb20dbc244165af841934b624c713a6c42c889ea4350cf1d8adfd5a7669
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:41bcfb4d2bb5a8d9cdbf3f2c2d2cc71638fe0c7f0f22fe627ce34b3a95a23240
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e262ff46a9798295b40c2ced5fd8c00e8af3aaef499b43b6191e0fe235b07634
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:033e49d6849cc4683b6d3cdd27401526a992b5ba18888ec30962864c220afdb8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:bf0c54a0cc9310ee485bf487353c7279457eba633b1f731d5ef4a89d2fb35a5e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e8bc5608ccd4efbaa08d5eb39587383bc319d684d0e8307d7ccd172967512fc4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:55115a22a0eb3eff2420ac3244ae22f697d2559bb3a7e5b150fcd267238ad355
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d700d3901e3b50e764b9e4aea3913c88395deea836154d6d4b6e0c82d567621d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:9ea7bfa19189f9d013ed3fbf63e29e13a33866633d30a44374ae15c773b5d38c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:e26219ff9d2ce3b2be9e010bdf2f934015c9a13a1ba9b4405d52d44b1c9e5306
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6672fd0752f08cea76dbc2bef48f2cf75b26feed9859e4cd1c3485099f6126b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:9dd767aff9dbba1625f975f640c7aceefc834fd487da0b2d8df82a22a0ca0295