Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.35-debian-fips-dev, 8.3.35-debian13-fips-dev, 8.3.35-fips-dev

Index digest:

sha256:5cb5e2abb0dabfefd6e87dd7167a6ff61f01c05277b7c34c36ab8effa76547b9

Manifest digest:

sha256:ab6d9725b566aa4636e0f6b149756d0584677eefb53283c8d9dec3b42707e6d2

Size

169.76 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:d4963714a722a1069ae4e0b736aeeac943f7806220cd0403bd65f28aea7ff164
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:3a6a0c86258c8e1879b09dae0f074c74d87904301648f8b3b1c6fd320bd017c9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a06bc4e5b48201580114d9aac259ff35c3f2ba519bf8746d50aa6a9d276d7ec1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:14326f782029f70627577d4bac309eeb70a32002ecd92e8997088eec7eb6c10d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:8c21baeb913bdad72f20ad5b10d2b613720ca92e3fcfed9279e6a2f9e713547b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c4db5519972d86748b862e27b8a8d1a8e9b41877334f7737782c225f809ba90a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d841b9d5c4095f7c075bc279a54e209d2eed8fb5d78ad0602f91d52d370237ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:46c1f488e9f1be751ba277156afcf6a82a3a21080d4a446efe56d02156afed83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:7de554a579f30bddfd059d9c7e79ad425d1a7c7be5494c757b467ff6c414b1dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:85f7cebf444f868b69c1fa71191c9e350160e41788d65ce821ffe123adbe7b80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e4feae3b32c6c4e9a51884000682357cd47adb5feef5767ec0fad4d89ede342e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:bbeafa5d128346041e6f3a3e5ac6fb2d61cf5176b61ccf5a22989a228073c6b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:157ce27372f96d0cfab49aec03e2470be15e30b802054293f7c4b0293c55d693
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:fdf8427bc89dfe7a4a346dd183d8bdfec1ff2923469907b8e7cb9322423b6ac9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:5f2b189ca836122187216ef12cb9681708d14910b79213eba42b7c235e4f98bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:18f73113767df45cfe39d6d16bb885886462a5e389a81887c0b9f88e9bec1a67
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:0c05cd14f71c324d2831544d2c9edd7863507416808887fa824e75e0297d6c74