Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.33-debian-fips-dev, 8.3.33-debian13-fips-dev, 8.3.33-fips-dev

Index digest:

sha256:848955ff7f8f5d96ee278ac59330a2162128fa7d33915ddb9a2dccaea81bf453

Manifest digest:

sha256:2c281a653fe873d912d8d2a6d60f490c854e851eb879698c0113f12e1e796361

Size

169.75 MB

Last pushed

2 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:c94f293130005203f06811c1d3b058addafcff3415226b974b8d9d200512af2e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a4c17eebb6cf995d0759188c7d0efa0f49c2d350fa206db7401d3a9320dd5445
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:84bb70917620a74936723287388e5f6c995991083e33dab6198e78d402af182b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:6f64268099800a00547b7becc9e69994fb6cf95060603f0c8c3012dc6ef501f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:bb0ab9db9176c1b61a5a6a0cb5d0d65b71e7acf90d228bd1639746641052d32e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1102444d30ef0b9335267be5b23fecf52b033094127f2ad2a71a14a1dc2d8403
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:195d8b722ad5c24316f8e222ad62094ebb99e7d79dc3c6234573a07556953d44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:abdd0c65c5fc9caf30df39d46b0f48b5e89a4b758967f902edbbcf61d113eeab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:6a08b4a66a422e9783984eddbbfff40e21bfba39056ad8d138f4da037e5bd594
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:4a5251510a583d3e32321dc9e5a96e1a5d701655909fd768da91ec094f9371a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:522e4bdc65dcfc666458eaa44ce6fa88a3861275bdb4847d43de25c907eeac68
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:bf251904a786ce3b1e7c210e8c7ab156cc20cdab4596c6fdc096f233faea2351
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:017f7108f9c920024cb7e6384703239b128008b45a0afa14cfee68ac06d3410c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:9946e7b34a38795440d8f21d8175cc431fad3fced02f99b3c9f81075512415c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:b48da6debf47992495ae7c03a4e3bf8badf4cf8c17fd4df5ad37fcab0223a1fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6e5f4b9c67a193ca112d572381cc581f00e34fd6401f82bf3df8ad7333b39e72
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:cf121a90f5addddf0909c1b1368a27de778b6882050c26ae98783bf34a4e2126