Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.4-debian-dev, 8.4-debian13-dev, 8.4-dev, 8.4.25-debian-dev, 8.4.25-debian13-dev, 8.4.25-dev

Index digest:

sha256:dcacefd09404e092cc1b1aa3f01a454ccb5d387b4b29175a1b185d96fea7ca5a

Manifest digest:

sha256:d651733e6de57ef1efaa3a46939f872a3fe6b1da50a7cb96ff3957503bdfdec8

Size

162.91 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:83b347efd80cad68e2cf795f1250543f119fce56182ea361eb81bb3046256b7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:b5917e6eea50679c4e35f3d742a4989e792f853756544096326893e01746204f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:17e49afafed3dc292c4bffe0c2a6d2980e22f1bc4c0c9b63fc3288bdeda08819
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:54c687f7d564c067173fad2b189467181c445354b58588ba6b5df4a2d4eb4d0b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6363c7705d4e4bee9ebf68f16e07bc6605e2b1982312bb490e91064f00a8b082
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:fb9be46cdd5e6cc61038a7d78e5692dbf8a3eb8ec26fb8730f23cc1ea2437df7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:bb2146ffd7118360382d79070b865eb0138e98ce442d064ecdd46ef99d25b565
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:309b8ed8c72df0de7545e4ba61e42a42b507f0f0309f3afa14ec949c6ed66846
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:cf07756fd51fe8799c4ac8ad5720c83ffa5a57b8b88d8d7dadf97afc1dfc25e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:37663f9debc0981ccd42c2234199d2c6d94dc31491e3ddb406cf9e9703ef76b9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:1129739e66b0eb5bf9635e984d9b17f625923d3240f676d4a6d55640a214fd02
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f2ac43d2f67d962baabec988f848e50954dd43dd1fa5c2255289f60d3ced90bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:a889aee264e3b960c1148c3620267551b216150812ea0b1f8462274da98aabf5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a00f99ca88fc335f1c475f23091200b8bbe1c06ca19010b88078fc16baa10740
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:2a6cfc243747af5003803b15cb955114a739a09c05a77b9811bdd40f62a4d51e