Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-dev, 8.3.35-alpine3.23-dev

Index digest:

sha256:f37354b03a70ce93666dab828b31654e5d4acd44d310eb5bb9d7eaf5f74a2ca2

Manifest digest:

sha256:2fa557d5fc937fa647eafe1782d11f6424c1feaa66e66b305b863b35fa9941a9

Size

131.91 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:1d7b06b6d4ca9b7a4f7b352a4cdc5d424f4ce194e08ed75b2caf26c7f4a153c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:34f1d825786dd7f65af0572b389adcd53b1a74abd856e37a1631640aaa059519
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e9e1c5ed99704ddbd06eee5501853e4c90ad4704602e62e61ff95cf9600cf97f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:946a5b98e097db6a559ca990f5b599690815aedf0b7f72a476d1c69d555971e4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:aaf7fda5d3f3f816d454d1c5aa68d87189b2cf896b9d8d78fead06f786872601
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8b812b71d3bb2db826eaf85c1e8e359869b7d906736c9bfdee502cd1780fdfe3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:5d9d8d4a87cd6b109ca924ce1ab42ed3fefdb72a28ae53d2d869094b6da6e8c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8bb2c288a64d1f9d730125c7d254902c9bf13134141da2d1219dbdbbdb1c2811
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:2a9b9d3bf7e9a031f625649cbc216011ebc496763f61fc2ba5b0e7d29ac1aa77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a3c8a03190d0b1ea357d2584245962a6802e3c2e0357ad88545e0a0dfa154ace
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:00a6e805f546f5318eb0cdd7b7039a2ef8d3a3045e9a3bf682c81d30561083e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:87f498ef19c75eeb84c51d5912ff987d6152c13b0c5b8ca2294380b6321a12ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:578eb5da7b10fb84bcf6d7452705a2a2e1ab57a173fd8643edce866ec32702c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:0f63a6f547182edb12dacb8f69d7852c415286dd1c43ebea64c4e4a3d879041d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:1312781137e1674925ee8b6cde08bde8e50f5e41d53a4c0c20f64677884ac6b0