Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.33-debian-fips-dev, 8.3.33-debian13-fips-dev, 8.3.33-fips-dev

Index digest:

sha256:0a1db4b9c59fc26b31f4cc047d3f0972373049fbcc12fb49484a25707f2f9996

Manifest digest:

sha256:46a7533fa8c28abeb50a38fbce11433473f1397a81851e2ad62b7a77a4c313fd

Size

169.73 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:8661da375d6bef6c298f2bcd71f1a66d91511c822006f7847e35d1827339fc56
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:bec49731855a38358aac499302465ff7eb0333452ea003aba2cf41e6f382a3cf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:276a9c22e80839dea671edc76f3cb21b085d016d7428d0ce3ebd197fce53bb8c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:3749010b6a73082b6042dafabe2753ab6a9e8f3bc3e73f580108e5f52d5d83e9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:47764c51718242835cf4cc8427934f939748f30697563b63459cf38db786c483
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:57655619dd4199f277ee8d94e3c90d75a53feb2b681ef8e1a362953a2c146ae1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:66d3d02b410e563ef0fd926e1f6fc1a061bd9260203c9245f17b82f7cb8a0d78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:266dafa99684d1fdf0888da294e6d0cb27436f5709c133929873c0db2a5e4d10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c46f77323971f2d8869c0484ce91459669b59887cc08478bff69bd6957d09461
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:5df16e72b65bacb06ed842ed009051e66b02e6160d2d0b85a665da17349331fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b9729b09a315161fa7b77b4c82a2a9aabfc31c0acce0cc19e4ad232beae9f6a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:b8e806c07f52a7aa4402cf033f280302dc92c0839286929e4419936d7acec990
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:2b3265e832ba32e4048ad98924ac74f723cf90c978fcd50d82863569c3aeb6eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:21895585724f9c715a2393c853f4067b5ca72edbec2ced3388c81fa86be5a95e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:9f7ca4b2076badfd9a1bf84929c7ff21a01a6fa151a560723d50fed8f66fdd25
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:48749c024a7965d9bb77f6d34ac0409a52afc5b4417e2b4775863891f0553c6f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:b485b0b539b13fb1dd12a76fd8605c854a3815258b4a8c712f799f556c64f90e