Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.33-debian-fips-dev, 8.3.33-debian13-fips-dev, 8.3.33-fips-dev

Index digest:

sha256:c47dc4fad816326bd3b7b308d46da95a9600ad4fd133364b97a304b417f188de

Manifest digest:

sha256:a72a4f7b227062881461e213d154db70a8c9960319be96de3900aedc9d3d817f

Size

169.75 MB

Last pushed

12 hours ago

Vulnerabilities

1
1
0
4
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:6f568134070a5a7ec072b9b99b42fb1edc00ec00401e5a0a001ba36d4680caf6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:02e4a67e70b8b1c54bd7a2a47305ca120c06f9d8d60ab06c1aeb9ffec29f046a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:536e659193393b16f34c98fec39f197a24a6f767547860383ae85c0f2b1892a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b1788387f8837609463687ff38d46f6b683a85e6a7990bdc86c553ad48753b17
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:a15df8b333523eea83d7282732c7ec96a3c4d1ecf75a05b6cd53f5a22197bf13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:bb0aaae7710301d6a25a8f1b12cf9dd43fdd98152075574aa7783d8cc1ceb11b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:4feb77f00f3fb8a7f574bf28d6fd30539999c0d9cd78736b582980ac5e35cac7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f1e8083c01820a408d567969154cd3ec17348d94b6d728ea6525fa0bb85762cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:621d6c38ab6c54ece6599f5048faf79d07a216b07eea36b6ee0400954ee51d97
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ea580c689495632346a85168afd9070f55cb83d721461c79098373bf19088809
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d3080a0a9459b789eea82e43b21bff2e6367649be737d601f42b31178ff5aa46
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:599653c89c4fbe1f6f02bff37c0103cd6bbb50628118a051dc3604b4d0526291
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:5c0743d4908335750f32507ee94a37d4c55f0719905f38a1c3c2f49cf44138b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:d935058e61b8234e567fb303a6cd8f7086b3667435a0b043fe331f2e332de132
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:1ca6a12ca727d476b6641f21fc57d25a562b0398628f66cf32d96b5e644edd32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:2f1f8591d81924e53768a7ac019868e8588b068a0e7c4bff86527d38d5df5d56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:a55073eb16b5a1f88c2fc7bfa9a44e70238d1fa048145c122db639af3cd8cf01