Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:7b0fc18dbd891b2da46f1b66eee97597b59602aa742492cef33d0d58311ae5ca

Manifest digest:

sha256:bb1625082667f60e2995aa6a5783a51442acaf714e41af780399d5663e5b918f

Size

162.91 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:03c8f0841f4b09b5c5cc817ca51650bf725cee520eb8d181acf4dbfed66d2c90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:39361c36312cf50421c02fe7868048c0b454f345013f21a68e176d18596b7c9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:cfae9bf0b4aaf29c404f371e558adb086aab79cdff9b0d444f00644c37e50343
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f3f26d1109cbbed6fc7cbd3dc61d28156fd3f853e169b1f2b214ab82745d9cdf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:2fef8d76927c3b3ceea627a0c5b931b9a3806a331a1d08603a7c99b63aa2a4dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:7786107344a58f320ffa2e6c0163a96f460a949792565195f76011b08310bbca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:e17cb9ee7350ed75cb4339f47dfef0b326828e8ec61ea407bff8ada1b6bd2c27
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d8af334e0431cf2abe735ac36e8e6ac40846ceefd7c549f104b03486cef50bef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:4fee0e6d24725a5d9ae69849752b37dc00ce85721c9d92f5e961648de0563c4e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:50787fc6ca3efcb7976ab2df8bc85a758c1d1312234a66e0f186e647e21356dc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:168be15f785f36668fc178bd73641e09acf1b8f4e3c290a1374707ed4edba0db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:c94b0bd0eeee9e2519df69d4998742e1924216ac6a66200c8fceb6d2c060eb67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:a392b9d8fd637f295160f99af37878e07d8f76453ebe173f476c943863657109
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:36688fbb9c3cf3dfd6e7ca992759dfb8d8f9333a9b48f712233d0a29afe2ab10
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:500f1503331656b0f8db1a2b4d24e46969135e558695099f2ec82b682f4fcedf