Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.34-alpine3.23-dev

Index digest:

sha256:a0db2d382b5fe4ca6553ef078b9d09dbcbbe8eedc0661aebeb639b047133cce8

Manifest digest:

sha256:980abe6440e1c2d674f7feb7f2cabda36cd85718feca2ea215645f7619bbc9f6

Size

131.10 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:771944f1043c093f40c94ebc2f8946d9ff9bfee8a2054f3ac270703d29ee8d61
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:73f3916f06c5102ff0b1f1b4edd9a6a396b162a05559dcee63b90a35cae781c1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d9ee55573059186c8330f84322038db9ab1ab5daf9e15c9c4963958d12c5fa3e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:4ec4f95d15747906f9bf718bb69b139cd7e9f3fc8b6beeaca129f42043b27cdc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c6730efd4c72b55b261e0d03a783d9012037002b9ea4eb74510827cd75a419ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:5e2556e27bf7c2c59aca3bd84201ca02c183e902ae17f266f159549ad28713a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:f42da9057c769a1ddda3aaa3db65cd61d4d29c894fcb3cd8203e48f2e416b8d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:783e18fff72159bea2c4834b6b0913390b64c5959350b4c25977f331ad2fcca5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:3323acaddae45d80341eccd136bd30a4c64a4d8ec30a3bc34c9ca4f277c48293
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:105b8ed0338401259c262967b35ba6fa731c7fb4609abf95290cbeea4fefd58c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:f5ce51035e0625910f0b5b9c899b88bb4754e4521cac168639d6853632652da2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e7fd38d3358264319e5a849701a530cdfc728a19c199d6026d59649074657924
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:a7f5b3187922a43db54058982ca0c130f2808dc49c5d5ccc7cd02abefe126ae5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:66189407d292b82b98ccb4c037a2d5fdcc1cb30c6bf5ae24db000be8f9d3e769
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:b107d561ca242f7ff62e7360dfed16b78c26f68584ed34716b9646532fbf39c7