Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-dev, 8.3.35-alpine3.23-dev

Index digest:

sha256:737861debf9098626c31c08b3225d770abc92c9b8b341e7f25d9617d5cbb5cb2

Manifest digest:

sha256:480975aa5b3d0aab8445ebc329c28cc1cc86466e44d07ba2e2ad10302a9f1363

Size

131.85 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:910b0c0b5e49d4fb1a3222344456a859e2dcd682f39e3cae26be2b53e00862a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1487a84234c8eeda881d5c083594558094412e251ec4559cfd07d853e3b4c2fc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b2201cf412a0f5ce02bb05756985922a21dc638fefb6dba64467ece438cfc7ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:224ca3190dd9e27f7feb9c2e11cf84e4b567b9cdbea79610f022131b63dd3581
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:38b7d53f3ea2981fca45bbd0e60b696059b6999fd6e3426116a02f57bcf09c27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:bc36e2246410750182f4f14c6630dfed06d7e52ab38e4637b049f417aacd2c0d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c2b96742b7fd7383d7fd7a456c26cf8fd5f2b992b446347a443f0782c912016a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:aeec93561e25c57e650e64a141b2364822de2ecdde5c84b6833c75e5f0b693de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:1a75bc26f9fc25484101150a06056935b1a8edf46b7895f2ab0a1fa901ff5bbf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f01a01f14774fcfedfe061fcbb3750b95da2715a878a6834bbe55cb4e1fdbb10
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:afe82da356dc24a98c682ab94b8a5b2f06c6bad73af15dde162c0c47887482a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:8c85583a6c7896e3f610058fcb541f49a141a5c565bef8596950ad3b230a62dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:f95b826d7185cd8b0edaa03a90a9e29d59f9a0623d89ab3d773c21bff52e6386
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a6762f0a4e422bc3c0bf1412906bf1d7033db9ebd56921138449125cec77364c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:7819288dde509a119dd9ebee2db78c7668d2b4cbff4a578f6daaa31ca9e06cdb