Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.26-debian-dev, 8.4.26-debian13-dev, 8.4.26-dev

Index digest:

sha256:df5893a2add7de98c834c4b69a386e7f3df3fd352a9802842e434a8796070be9

Manifest digest:

sha256:8e1c9b7789f6622b3fc7964c2112d1a9e254738a2f24cb7b1e92f2ab3881460d

Size

162.96 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:150d5e665c2486f97df51b71238d52a75e417e2bd59fc3f4ef271b0f2b9e72cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:38fdd5035eb1c6f4b766dc5a960ff50ff362e34ce0f152f6451b73142b5be55d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:776a83d92c2c544cfa8938e7532ec98b43fe319d9f52e9061b4524c26ad8dfc1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d67a612185cda9125575b97ca1ffd11f809b4fcc5bf973aa06e3a9cc2e4632f7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:26973f25216dca7db74d6c10610d3fa983792f40b494849e27d24d170e7495d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f1e402fee58317ad792f1791e0f520a45d841148576370ac96cbde7a00d84bce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:80978dbeaf85364482d2c70e8120dc9ee0a9d7cbd05f91e909cac317ab5df6ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:0dfbbb78684cbfc3997e425db43d7154091403f0de3d85605e347721c89b3df0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:caef506ec03a4e8bbc53d10884064bc27070419e4227fe778ad2c7233d35338a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:dcaeddd6e96348e78d6d2296bbf838d4d5a1d49f66867425eed0c08abdfcd89c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:f3b90a6d6b282c429828e99a42e6b8ba926c4f7829765491d0154dd6a8a7ba75
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:66260fdfdc1a1507ca21460489800a3bd2b6fafa48eccdfda2843341819845eb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d95e0c66df5527874ce1da4866c51b06599f3ff6b03209c5ea62ad7f01d54615
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:5c972040d422dea8dc9d6a0509a9e44d23df0340809de7457b4e688aa02470dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:20743567216fbecbe346f48156a0267920a194a17b2de4163c0c727f9c599e54