Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.33-alpine3.23-dev

Index digest:

sha256:cad836d4fc8c96063b914fd9a5111e0ace1f72fccebb56cb559e18d3b61a1c91

Manifest digest:

sha256:628e38985b62b12bf3e73ffad19a01873e2b1468aedb70b2ef23dc047d73740c

Size

131.10 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:6af08af3d8452e1c2fd33de1d8c202d5b82c323d4acca99260e0bef9fa35423d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4f3f8e48666aa212c2a5298b6749311c3700a9b5273275ece106b4312117fa61
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:18306a0d22a7882d953be6eeb81ad19cb9a1ab078af89a4fd8e8c5ecc52fb0e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:a23d49e376965be04510a078c0f52019e1278cf51dd1a7363b740db6818633e5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:16e8481b4e350af5d5a9ff15b44faec7978a03f57d9ed8f6a30ea9c89973e5a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:71c0c105b495d00b3ed1c7c7ebb48931e09fe3c6626fe8c0d62d3c7a40ecc707
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b262d840e14ccb1e17aad981c68775e83e98924ca70e79c7cb419e8efd5d122b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ce705f847ec90253c5823425db251b7dff174f5fe8dc68bf057f2fc3127ca1be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:65b51f916b095dc325e00cf1b6ae6f8d07de3191167749e8fc06f8964d48d067
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:fc3b0ec8c3fe2544f852368f205479c622e45113b45616b8d6fcdea1ff177b08
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:694c1c0b90c14074a99661eef68c96904d3e1716d0aa8d0e999d67ebba401310
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:5e0ae0e2fc25ea0079d4b6dd3412f171c3c59857d157305cdf27ac5cf9d96662
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:0ba85f09bbdd5f038afacbfe5281a1d9c30fc168357db35d56a75475f6604f81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:fc016ecb17877ca97ea6b43150225d34ba8f6fbe6fb85bd4ec4ae9457179cdbf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:faf9620d803eaf65573890b420c8a270948383cd271d6a47289446ab568ea56c