Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.34-alpine3.23-dev

Index digest:

sha256:004a8b369a418b97f574f7e81140d9adf674789685d672c0bd7a00ef9fc5ae02

Manifest digest:

sha256:0563e8b600a063d8023d2dc209e630c32b6b7ab18eb4660c4a0056335ca5f6aa

Size

131.16 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:2bd8297383567869511c460fe7e8037a33a41262ea3ea748183ff91a7ebab4ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:0177f3a0f282d491500be61fd85d4f326066a82b61e2e7d72b827f8a330210fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2f32a57283769ca0f67482dde0acb3226039c87300726adaa342089655019b41
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d7ddc62fdef183db039629a9396a18d8362ae8ad566a15b6942be52e352b65bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b9a434d414dc1f335f261ebab9ea2c1718625f2d5d29f3ab6ee0bfbfc561fe75
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c79931959a1208f39454049dd8fd547ecf0bc460e5f29ddf791f75d5417ec091
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9b04e7ac17ceb3767fec147b8bbe27aba07fbe2af0bbca1f50da68bd315c74ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:7fa5609b25ecdcf937ea6ae38364d332617eea7f4174ee41f863ea822ee12037
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:45a360e2930c7e9504ffab914390d6da1cf406968069bf3d5b0d51c9a7c73732
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:1030d51575753123800b545150bc29b84cce6f18f3d3c791cf67cf40103bb186
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:af109f3e7b13d50a5ff26fe64c3536fa2335777e8d60543b874e232a5444148b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:2ee11693357168cd32ebd54545aa6266449fee36924a7d55796e9e0c38e84099
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:2d149b317d3db3102f06f972d06955df1de56c1dd7555b15e82a7a54dac1977c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4608978e05bb9119bf710a7ff715e16286ff427f2d2acc9985d0c6e93c6c7b0d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:43eba096763943afb1c46dfa8fea99d7e94af9fd87b3c3d53552f13aab46b24a