Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips-dev, 8.3-debian13-fips-dev, 8.3-fips-dev, 8.3.35-debian-fips-dev, 8.3.35-debian13-fips-dev, 8.3.35-fips-dev

Index digest:

sha256:1d0036ea863ce218f7150a5fa4893429dc512a201d33c35feaee848e8ff7c157

Manifest digest:

sha256:abfade4ab944b9c8c8679af902ee1a50866d9186b98da9b2f14ac9c684611fdf

Size

169.76 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f3d60a88b337e9468db947d92b2908cfa39e50ec00a4c01ec0079d1bb2dadc56
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:89599344281590c281f2c83bf8eb029dfe21369b1bb9d74a58485007b15b17ad
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:4afe57a0f65c83a5cd3c058305f03d50adb57866f42b5f4a748a7d7683872f74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:cbe2d66479bc40517c72850678dbe6d5b7d696337ce52e17cfe2a51d64ad0246
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:1a438b3ba377081a81e2d3f1cbf068c586b2ed79b656f5b13c40e35bf00210d2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:b27e26c5bf2f6380d4ae65dc9ad3433d04eba4e6da8149b20e84fa34fd4d84cf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:3ac092caa926ad0b904daa0c1c9df0e7f46f1859300faedd054c7a8ad612b23a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:30a7c5b03b6bd04535f27ac7e088bae863a6df8423ff08f95c07107be0cee3b2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:0aeaaf8b769859b07ebee4cab18af3e2e985b952654c6fae362d1cd159f480d2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9bbf296762027c97d43a891ea6a456527a2117d3e1e3e20099d6591d111dc4e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:7e5388c60e368a782c188a40599ae4a799063ee0600c2c89f17b4555d85e4cf4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:e48d07c8c92b4bb7eeb46b99d6e4c4920cb8c4b0d352ca0e42818f297e6fe995
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:ce8fcd6ee2e96383b236393153626dd6e8475704b4f8f172b239cd5856545f5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:da17cb5b298c1efc25ed795a36bc16d4a50c284d70132eaf042a7f8b615a2323
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:869a8384ea76b1df9176c5705bfe48d6c9a397c90c0973ed326edf5dd4907973
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4425cbb24043532a5e325158b2cfca3355728f1fff824dd8fd809da3624affc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:209fb58c79879f6c78ccbac364754e0899549757337319ba789a969ae0433272