Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:f5d151854e5925d18fdcbb9c5940ac94ffd6d26990a3cbc0c09fe611b63a5b06

Manifest digest:

sha256:aee8e32bf0e0426e5af8ee613f28c062c63b3b4ee7ed1171b872e9b678207c57

Size

162.91 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:a5262e7a87b07cd81dd69e2ef4a7fefd1db25fbbfaf4d5ecb7ce675c28c42ed0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:24aa8b76692681ebd82b880b78e93b161fcbd05bc6eecc7a53a17eeaba2dee1a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:96576953bd42f48c4aeae8107fcd3f781aee01e2825e0cd98407ab8b6b8fd6c0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:87090e0ee20d66d19c4a1c4122b22567f7300ebc450ed99430bd568c97dc64e7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:efc47069934e0ba780aa090b3f2af6fdac78e4ee097fbbf96c2ca569ad5fcf9c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:d47d52b8e99b3fa40c66fb24045d2d58f478c7f30375f436734f8426454c0198
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:d22ca8c02d889c7fa0a110077f7b0519ee44804de2830dd8dd108ffe9a921628
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:fd3c056af7f4b79228851ae629bdbf8c350d3c594056f879b97fb9633d57ef51
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:0f7b015df8cfc02f6cc2a556cfdcfc90c5fb46c47e98d23bdedaf077b2eb4f55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f78ccfdf5528458d2634fd1bd00f2965b244a81bc81a537df01d41b591a074bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:8759a9fc9444113fd605ceb831260a5dbaf2a552ff1d459ac9c7176d0a54c80f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:2e21a1a16eaa0d8dd88c8e36193edeb984124149a721e36a800467157dae52a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:5d2b259b54c7d21cde6fb9e93952afaa08450230ead06a0667a6ff3693c44e77
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:ec75e2033fb620ec1e8370bab79c11a5ee26c1b30ebba1937f4efde8557a6591
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:cc15c00c51cfb4ded31bd1f96f4dc6afe3955c8a5584882d931e4fc83c87303a