Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.3-alpine3.23-dev, 8.3.33-alpine3.23-dev

Index digest:

sha256:452b92e94964dc110b27989d70f63598176ac3492211d1fb77939f4212dd2921

Manifest digest:

sha256:b8f172446c957a5b8dbe8efec79ed34de23b70309a68ec81d4afa327188ba1b7

Size

131.80 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:e0c246e5e2bc286a0c0d29e94b82c74c9188354eadb077786b1571647cb3bce9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:dae539cba431f093830b9f1cc9b88e2e4ec2baba1e81504e994fcd93ab2ff9c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:040d488bc6902ff2a43dedc1fc29719fe0e40043a4f4e8f01f35200555ea66ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:27583a1334dba8dd769a2dbd847036fe4a0695a8f4c080a589746a46a25e8cb5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:4f677ff9b7da33702fa587370270a667439506f9d9cc59a5930be6e51d95510f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:49e0ae4e122632b10c4e9412fe72d2308ee782653ff94b8431beee0fea1bdb38
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:124d53d4a1dd06cd11ce78dc5b583f2ebe1a28a6f765fe63e63481d628ef6302
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:caac8c9dc70295175e3d68dd0ff1d48ff5f7929aab47d0da0592af59295ddc1f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:8780fc771384ae50f0fa010d9bae393717a86a60e56563238c4004ae7f812558
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:2c19f66a9f5befb81c6d65b72cc293ecef661f285d386ff7e02524b1dbd93970
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:7187996a36982611b3053ba9640c03fb17ae358527e049bacd86e01bc7217885
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ff2b12cbeb1b9541cf5dc2278f41f9b8b4116b9df435c10c6e1fe7ccb1e8119c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:bd60af3194d67ac050a0c9b7f73ba7867edb926502da93f1e937342b8bc6d488
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:092b626b76df9b10a07bcc2311c11d0f32d9547a88faa5ad71a48f5993840bfb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:24ff2439fc8fd8fb1424efae55a6f7064d4cbfdef66028e2e25f3037cc16f8d2