Sign inSign up
PHP

dhi.io/php

PHP 8.3.x

CIS
linux/amd64
debian 13
Tags:

8.3, 8.3-debian, 8.3-debian13, 8.3.35, 8.3.35-debian, 8.3.35-debian13

Index digest:

sha256:21f1423e8e03f16e391210977b4692a0e9ee0267ccd4aeda6fb88c423a6a1352

Manifest digest:

sha256:2ee1f5777d0108bfdb70c9793c5f5eabc3c2588c302718e2a5bb1c26e6dd9012

Size

33.24 MB

Last pushed

19 hours ago

Vulnerabilities

0
2
0
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:c49ddada4c3388e34b91acdf1b4eaa9f549256bc503f2d2bc6fb1782e9baa577
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:040421702f1e4c654cb4a09440a0c832e8ae251a40ede01652eb9767e85f5400
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:40a52d86ff445c8801121414a1584e16acae079c0cfc79d5da84ab40a6463d58
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:3f17a44cc98b98da5252c3cb4f617276715da9325a192999b575379c10db27ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:72d7d964286c5dc8407aa58ec30b8025fc6632b5a64ff11e7da26334dffb81c1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:cce0106fbff9492efef149af50b317d7b2c6e186bfb83ab9c8f2a1d5d7114eea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c1daf86fd1d56f491f39a47763192f0b764b5c8967d434e97640769771589440
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:e4c0164b7110a815873ea2818f7ad43f46c748fb0ca61eb4857d48610815e5d8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:9fdca5704816b3f9dec21bb2a2f602e27b323ae3d3559def20dd9ab479aa0760
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:e6f84f5952a938e5a9c284b973daad095cd966ddff1055111f80edf2a1f51ab5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9ed3222d55a4cf909d2efedebb6d68de3afeba477762f22b2346865fe17aa9ba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:b45518fbd6abce790290b8b2d611356b9fe5bb681a33a386a54bdada3bf7eba4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:4de0816c2237bcbf83774a243baa079fe62ef9e4840181af0eea0e57247bcd5d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:43796d0dfd75ceddea99df42eae806345957930031c5f4e4b49ca7fadbd3f51c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:09affc1fcdfe823be15716a62d6b81a341fdb455d6cd821521b0a059d851b090