Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.33-alpine3.23-dev

Index digest:

sha256:bb873af2610861bc0f3970e09ce0e39438167967a9c5ed23bc6997cea1f8dc52

Manifest digest:

sha256:0fb62c94ab72d21aa8d193dd73754d047c9488aa968078786aa50f3a00c9172a

Size

131.10 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f3ee764811d814a63253e318a7b0e4be298d87e60da4b25a57501646a7011686
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8a9e9bc2b965650ab232321f0b90c5de8783c6b01b419d47cf94347505f1cce2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b3470921adc09378765a43870f0debe9b6e47d285c06d53e6547cd5e1e614c6d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:de3a29fe97f340512ea2dce2c203f2c24cda5eccdee8d1fa3d4a487848f28939
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:108f31ea2983b1803c30efe66ef330bf5b3af3bb653fcb927861464741cbbe12
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:436e6f8f4de53afd75930d6c177ba4eb06a5bb602eae4b4cd4500c3a8a33f3b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:eabea7c15202cf7de33cf2d8f4e9d852389070bd1f61bf625d57d00f82854d63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:961da64e803831f19426644400792b612911ecd1555ef7d5b076d28cf119414c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d6d2439ca1f6c29c06da5bec1af3f160f4eb9a606cc9710810d2ad1f747ee3bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:0ae80a75923960de46f34f974d43696e3aa88f9b18301f23803e7e6b71afc9ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d673db39e02d0c5375ce1489f027353769e85e68741724475dd97a627ff1fa71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f291b24730bd65d7766a3c75e78beab337ab83821cd6c1fa15edb72dc8795a32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:32bf62c322980847473abad63dee29e0c2729dcca2cd6edaa5b1f56dd267ff8c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:20848fe558dca843c770f6c677dc1381df0a0ed3e1d0f74ba11629aa8bbdc0a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:0275627d0a63553303c6ca2d9ac33d77ad3994e98841457de46bdf7b4335f678