Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.34-alpine3.23-dev

Index digest:

sha256:8505dffcf96680d24f1da9c80ed393bad3a6c28bb57dd0327ae1b182be24eae5

Manifest digest:

sha256:087c2376d1e7a49c1e229e37183bb1527fdc41ff461b9348daa117b963d1534c

Size

131.09 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:7829d6dea78f4db776955f3b94adb847631e0b16f682d77a2bc9e358614984b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:5a513c072902c7ad384550760e15b2ed99542c3be28fb930a7cbf60a68fba554
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1266419a1cde78e1994abd7e302560f8c73326a5ab019e0d2e8787f8cd297acd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:b2fa58bec070221d8c29a770713f7b5d533f6c878e6ebab1fad578f928484c42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6f53165f4d628d00d9c6c811a77c34ac56d2fbe54b3208c4773d09994a717151
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:d3a4272527e55627aea553f3282cb57e609f6efb46a5a35a84949886f1fcf857
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:7747cb802260e14195487768bf0eac7a3208bc28ff14ab493ca5261778344657
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:cc7c1fbba078daaed94796a2d4795c9bb081611715bc3c06bfe06ad283a711b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b6ef9227a245a17903dbf1588e3b2832e38bec1e7409639d10508507b8a78a67
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:0162a43089801265094ca2cd3bcc6fae668c5819d35c3df0643c8db92426f35b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:2b29bc6aff998057026e6be14b6efcca89b99bf48566662a441f9dbf7655337e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:2ea0c8ce06047ac4669ec78fec39b8cf95bc277636705155b5d0957c532075e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ff9236020e632761acb8a32391db86723a654b0816118f131761789255c59560
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:01840e7f2bdba952d6c46e9fe461c61b9d7fae9a72e9cbc4b19cc36eee3afcf1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:1eb6bad65406b51be39d78d884cbe435294b7c614fc891a455c3b425db7a0117