Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.33-debian-fips-dev, 8.3.33-debian13-fips-dev, 8.3.33-fips-dev

Index digest:

sha256:6ce6c9723d4700ae54f102f3c7bc4326ace929cf6d68222fb3b0a6eb0687a854

Manifest digest:

sha256:19ce4accff9a3e6c346b8c6c48b160f7e6ab00cbde73c2453a25f655145e7685

Size

169.73 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b6366f3c5a4c42b0be771e3337acff878c7d890656d1917bbd78d8c392ecb0fa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:aa22c69fb14ef86cbc0a9669ab786226ab572bf7db4b74b31e1717cf7e783167
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:f4cd6cade86d9850c99a5c2c17a6a90f8cd4e33e9babf7d5aa4d7abb67a590a6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:64a0b1321c45c623b983c86bc2c15c629e707558490186230241b5382f529cc9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:3df29a3b8763eea9b9fe9e54ee01312d71df32d40f1e85bd2128754b75ffe54f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:00de1d4be1574b049c6508a91c3fc15f0b3a90f8632212b65a020cc5f04b96af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d03da6f6e4e0b22a6f94f27c4b5295f6556f15f95684bc706dd30af4149467aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c0da1254fdedf77599f5156fa3b9d38767096c90dd1e1cf45480a72d768c9e7b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:3d22480ed5c137da9fdb59c96f6a3a05d939aec932bae93f166636ec845848f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:bd46afd98f3398bb7df2179fff7b21a316e00efd53a03ffecdf9cffa0b115b9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:ce85e3cd1c93ff1984167d6c23aec4145800ab01e17b31ac16b8c6d7e265d44e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:07e23839747a012e96d146008647ef552b99ea6ef7c843285144129906cd00df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:10005f2eaa1254105f8fe7ac89dc2679c009ab0004e2d1d60b5d6930ab26c062
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:cb1b7b4fca9aa2ea027fbbcae2ef567b3d2732bfc490216cfdecdf4ad81a4fef
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:b5e3e2d3e4e203ba552efcf2163ce3e5839ffd9e1dde549a1f7e8c15b4d53a17
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:20b9dd13780886c46f31ce36a449d46596397fd976a93e48312c16d4f81c7f9e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:8e5887011c7a3eb58c0ac81064ddfec5b7a0cb98073df88f1a06f0629b6c3b2b