Sign inSign up
PHP

dhi.io/php

PHP 8.3.x

CIS
linux/amd64
debian 13
Tags:

8.3, 8.3-debian, 8.3-debian13, 8.3.33, 8.3.33-debian, 8.3.33-debian13

Index digest:

sha256:fd51a7afc295c66ff7fe3a8ad7519f1338f67bc0b16fc89509b2be6f9bdbbaa4

Manifest digest:

sha256:467698cfad30d9833094502c5bc75936bf6e96bca126ea7bb036effddae8a22f

Size

33.22 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:77a921c284f5726781087a7d9ec027e86b6cc3f9f977cc76b0d21018861163f1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:dea188ca0ffa4d06a3540efa69a90d58aae3e0f6fe8a7351b555a22ee425a546
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:6f1a27589a44009ebc8deb12437e5c0b3557e370daf505233f5669edf6dea3fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:7cfd1b8780a7686845553f6f3bfe11e6922ab35cd91203281c530b2b989d11af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c3d42feeb1ed0bd806662339f35d66844f176a0cae35e5b50816374508c3c58e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:bb281f5b91336ce3101fd7eea3229d8b18e60d6bcd3ad93ecf2bb2d72538e934
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:820057ab6c42245e45304e4109415eb65e14681f84d6139d09a7f0c6d22e7df3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:baa363907bc2b989f5f56dc88fdce5f577128be882d1cf849f35b1bc666c6a03
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:55d81611bd0f158c26805e0e86610bca0acacba5e3d7a8e15768ccb0827bf240
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:aa59f63a68b01e3cfc2506536867254e531c1c14758b1ab2c7b43739dc5bad20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:3352ab3e13a0dfcf5195701e8fb78550ec18725fec9da395fb1913fe60fb54ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:cbb259f44b8e0668509f019a40f58657669dd2be5f7bf8ba1728f2d6b2991696
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:0420d2fa4f03341e324a421b0035d82f0208a4b9a245c63fb3cb8d5802f55031
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6522a184d78b30f70ee45306bafcaa2711413e021a3a498f57723b41f7b5316a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:eb098e4667207c871f4494e709e30ae9a2ffe60ac03732a998fe04104aa9adda