Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.5-debian-dev, 8.5-debian13-dev, 8.5-dev, 8.5.11-debian-dev, 8.5.11-debian13-dev, 8.5.11-dev

Index digest:

sha256:9f0542775e23bbe05b8a9ca5f22897fae77f065e6e500b8891dbd4b73034ca68

Manifest digest:

sha256:a6b93533e2c4eb480b9dc265b406db0fde7be622d4febcb5c1529745f204dd20

Size

165.07 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:638b9372edd55fbd9f5637d2ea332116a5e1461d657b9d847b5b752255e65194
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:d302bead1d52e5445e94a86f0ee56a8ed7d4416b0e888860136be0d8a12b4d1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1b6c0a4c843ec20fe9bc086ed99ff974e3bb582ae4140d7c5a6dad3fc9f7f982
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c853b92f2b41d2c3d2f8115ef26a41e547e030ba2aeced1341681761987f9fe4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:1beb422465f7c2d3e03c029e11f18b85d827049eba7c25fd69def8a88c12faa2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:12cbc53f7bdbefda037748eb4858b2523db4de87d8a8a1a6eaedb64397965c83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ad15e609a7667e8cf72b025fe02e6a704e97846b8e230018b70c099ab620d59f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:0cff71d61267fa9f17a3d5a6cba6c76a84180d32a148aeb6f88a4161f3d7bc44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:6af43d2744f4a23ea875c4b2d389f86eb6696d581e6d09a4dc88146459898c42
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:af681e6152d06d295fde686d8e899bde2f6015204d31a43dd63a4fe37d318ef1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e57e094e4486a27fb96ec8db65746209f9fe918fdeee1627597444b55842df71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:70501d9ea8feb964bfd2a74f7314d414467608f42ffb506f11201bc318d6c30b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:6f9893e72e682f4a8ada40d3b18290d55337b271eaf8d0f9e21e435753ff70ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:de2ebb548fc4614dd82e45c58e13638c5d0c6032dd566bfd15d39437b7c52de3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:92b75f4aabf5b22563570bcc0889b7f06a916f5ff5c21826b84d9b9d37e7a1b4