Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.35-debian-fips-dev, 8.3.35-debian13-fips-dev, 8.3.35-fips-dev

Index digest:

sha256:c676a437fce38e092227cd6a5d3bc6b22dac48fde257e3f249e8a3180d1fa919

Manifest digest:

sha256:1cc03d90885be76a51ba5eece5452c32c3fc6dbd2f440d1df0ab5a06cf6ff31d

Size

169.75 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:db055f23609e1dd01e2798808923053343a73b03178b1229baa213c77c3e78e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:e81f9b7058417bc82baa7c38cca9facf51efe397558b4db8f9b543187286ab5a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0e666b716b64e2011c7969985fae470e0b2ea445776d400140e814f738af67f8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:5ba6bd245d96c022184247d76d181e79c67a13d4aee4ba6f5356380071d5090a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:0479ddae61f72db783d9e80c7824f19c00ed64a44319f96dcaac51e6e9c67325
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d400b7cdf5a710877a76e04a463b6cb542c494302014e2a871fada12718f48b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:fe4d55b98f9605894583d0719a4861459f82f85a591ac17272bcfab30523a38a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c57aee040f21b93d3a31005ab672e3c2974edff0763d40d8b77f3b15f94d7d3d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a821acf4b642705b218df390fa1cf0e087601e911205ce6f98e3d94f25333196
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:2246866d3e094843c5401a57eda6eb1f6691834335c810b3464caba1d106fa3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:f055313d92a946bd9aa0e62aaac801c8575892fe33d229bed44f140d364b698b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:4f9d59126851c247c55cd767355a65a6c2bfb2944e4c6b7e550b6ff7220755fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:1f9db347168e4d6de24d25a8999873df1d173efa4475364bbdb2bc64ce1d88e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:cdbce9153eb84c84394d64cf2e9236fddaf548187ca9f3909f1aa6c8c504bb29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:43df128de494f7adb88485945607d79a5ef264e40a28e75bd35dab5e03d7ad10
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:bc9c660cd68173494c9d508fc9f902538857410b3575f53fc06dbb405a67ad33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:97af8c5b69dfe27dc288cc7db886d2dfd01419ab8874061aece18340856a55aa