Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.5-debian-dev, 8.5-debian13-dev, 8.5-dev, 8.5.11-debian-dev, 8.5.11-debian13-dev, 8.5.11-dev

Index digest:

sha256:479d609e103be04249398380d9832a8f84631101616adce444f70c3c2c7ab1c0

Manifest digest:

sha256:19cc371d0d068174664b3bccf610082b7a6b3ee485f4b5614eb9c4527b1a07fe

Size

165.08 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:2e5db9be17fbf1452b4cb5dccde5a87a543f984cf0a9e0ed09c98c57165d70b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:b83443d1aa80f0ff6b969153045b584a1c649b91d3eeeee3481abbd5bac4e64d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:9a66ae7d8e7a4e6f92c7da78f576d62d5a222c4b484a0f221deaf353765346bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:8e2fd48ce526cbee282d1421e7d118f6fcbd2436a92347f5d60599f7b8a03f16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:61beaf965c91f223669874a1d1c887ecdc0eac61722bf7d4afcbaa41e57dfcdf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f4303ccaedec46a97465ae0edd4c1f915b0306a89414bd53f92930e736e27f5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ef7b8ba06010e53868ffc3cbb45a177e6bb14e34ab5fe9c9ded6c31de96a777b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ca992ea4c0d41817a866d05d735f757593c7d35058ad8cfa9e2fbdfa8c021e80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d6f7324fddc3e0aaf1609149247e22b8fe09539a811d0dd75791ba5cdffd671e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:b2cfd6cc84f052edc4afb19bb52cf6540621275e25b08f83555ac7c992f245aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:273469d533b38ecb57270dbc4848d8f32a6fb1930f48f730db1f4e0eb4f2f9fa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e77e1516cfe091015dbd69a96145dcc4cc4a0e354215cf8c254717efbfb63b9d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:5ff30a5e9fffc48bfb8f285648bfacf02282284415e242c02729a324f3096d8b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:ddb51c2dd417135193dfa2af00f6f4f121953045e66254d7998f48cb354791c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:da5776b663f2d799939db3fc69d404050cd0315b5c0013b4b3721097fde65114