Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.35-debian-fips-dev, 8.3.35-debian13-fips-dev, 8.3.35-fips-dev

Index digest:

sha256:8c857a116ed4ba9170886682ab07e9c0f6d29146b83919b90fdb2f602a779bf7

Manifest digest:

sha256:469d21dc64a7a5cd78ad40be5a4c19c037b0b6afb4648670df76b1e62cfa3bf5

Size

169.76 MB

Last pushed

10 hours ago

Vulnerabilities

0
2
0
9
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:96c0df973b54a07e31f9da735973dc8fb0af0e8d17e4b152b02a63536f3c212c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:9c070692e848493df23510c078eac8655d7d0ec0868a01b493852d4e074e91a4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:18f45ba5a5eb88aa325a3eb3254ee6af9daff088fca9fb83104e455b3d4a0eaf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:7e36293a255eee8de94226620c29016960476a7b429b602c694a3e37ae4e71b3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:dabdb449db5c748b1407555eca2d32c92b973c256f0428b207c6c77509e89749
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:05ec108e4669b240195535b6857c1e136ab1ee7f93b1ef67e28774a2177c81f8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:2681a2ac2b1c9a702026530cc0c8d9a5a02c73905b59f89563554bb0c6c3f06d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:b453b4eb07f677facb7a11892870ad90edc6a0598b2e4e3fdfb557661b410bd1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:1534d7c9370e86d338556837bbd8dac1af30b25ac7a6f7833ad639f00355c535
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8eac363826a5edb31dad2950708356d9e5f0857f27a4ea0154cdaa902c6c5924
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:38ec5108b1a992d9874296c1a0806db42a01bd72341246a13651ba22610cbae3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:0425d4a0e96be9082997dd79a5aa7e98a69391d14f8f5d2a57ab4deff99af137
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:566c946a507d342092308ccb24dbc5655641078c2d2bd03e46fc83464d95438e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:863de0d2254587ad4e6c196c74b0f886ef81c98df0b86bfddab3932bd2d4ab40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:4ba37bf9b3966d51ea631e6afd454f7ffd182829d67a9acef19238c714e8a473
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:f368da96e351e4e354760c556bd799b761fd4845781488e8dc31c78db4c864a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:64dbc2478b99c5516e98a3500dacdd2f06cda66843d70dcd6889e5d20a49b6e5