Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.26-debian-dev, 8.4.26-debian13-dev, 8.4.26-dev

Index digest:

sha256:728d856791bdbeecdecc6952b9ab99cc62559e6284670e05b7d02d6cac8b3232

Manifest digest:

sha256:c05d6e5d16e41e8a6921a5d523cbd40c72fe22b3744bec722c75c7eb6a101129

Size

162.97 MB

Last pushed

7 hours ago

Vulnerabilities

2
4
0
2
1

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:aad037eae0065d9b10d19dc0cca61fae639febcf2fa851a0411eddf3802a9c44
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:f2c858e95cef97d61cb13fbe4c43129b9b5fda715264d7258f0f173a2b38fb9f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e02ca0e35247f076831923e2d82dabe6c2bb7d25f1674524faae5d5ae4608d68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:6905e21278bbbb93ac34c398af8a67b82fe3889e9a3bc1a2a3a8fe755959c8ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:dd63b1cc620b96eafa1c2e598271f236c7b27b9695cee770b04f885b47dc7fa5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:9fd6d508dfad02e1d1355ac608b8d3a91ad2eb62b249e67cafbc0fb372789baf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b79a2563151596af806aa6799a7520d0765b516490f10981fbdddca1e4fdea05
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:efaf8632bf22323db762a41aba46b27b3da9bc34b6cba5b1c0964354b70eb479
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:09170602d09d1304f6f74eb8ea2becbaba098a7362efb3782bfda42290b45561
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:61ff8e8ae15f2a26de28e7d1ca1f95ceb928a258214e909768826c90c1b67394
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:565dffb4e23844f634660ec6f163b031a8b9701d17fe342ba969a456cad6f262
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:4018ec548d53efb19578a8c89dbb29bbc86a504c359187afd415ada0804ab0ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:a8c7b8c51ff6c8bebbbe9c73ae8f834914e8ce45489d81332c2ec7757b854892
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:2fc9eade8dadd25a2fa9b75505d9493fb445753ac921f15afc4b605c1d7e174a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c02e3bbb5e8917684a7f8fbc04aaeadc36e9b4d5ededb922abf73a93a40482af