Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:da8637a99c6ea95cac1dd7a5ce085ebe820b77b109661ffceb345b29c5387c89

Manifest digest:

sha256:8a2e5572590ec1dd9dc5c06f6b19578bbf1c055ef3d47aea5c80f876ff642f5b

Size

162.91 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
1
2
1

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:bd58c8f4778b4d5fb64645b5702cc22a0b34c98d5ed2ab12ff15225970ea0716
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1b22668deef68197b31243fffea3ec312bf9c6c9a989d56bc8f87883bc0646dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a2f02ad86488bf8196e92787f34bccaaf2fde979e92b3385e9770daec70cbaff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:8f06e24d7eb043eae8011feb2b626be93d236c1e1bafa1ff412c6be8477f93f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:fdf4b849531fd09c5d018372b3e6ea055c6c5256fae5496b69d18e715167c6e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:3ae8c390adae04f46a3f549103f699aac695abe5f7fe42147ff9a5dd99598e9a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ed84d2ba6ddf5b7e4f633e5422f1100cc6ec056b8cf7b036eab2829de771de6e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:cdc71354c0a377737c61efc732423f7ea7e87e5a193d40612e892454538bb11d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:53ce731af4f30866172bccde725df04b762fb96a72f7192fc1a7c5e41a5c932e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f050602157f775c2d8c23cb3799faafd7d8af0fed5f8afa6bbd946b66c45bb73
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9bd6a701ec5996586d07f76fef954b6f92b5b3768c17fbf5f981116107bd525c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:1ce6ed1454ff69b6eb5088be42b7116811e13031acbf6dc93ba472c1d1f696c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:e8784230fb4447ea35dc0a4b606893cae0c6ac4b96f769955b130b955680bb8c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:77b731ecd0151c84ea446f2f19eb2880325281c7f787767386e329418a11f0be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:b6c34f71c9120b709123cab5c3c05648bfea03a2bbc4ea0133f7cde6160fb24a