Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.2-alpine-dev, 8.2-alpine3.24-dev, 8.2.34-alpine-dev, 8.2.34-alpine3.24-dev

Index digest:

sha256:7991491428283704dcee4e9245f0575ae8ba1061e3060e5ed55b0d48bbec0b77

Manifest digest:

sha256:280ee8f2733e3b29e987121fd95f41574627bc1d6c4c0d19005614a663f116e4

Size

131.74 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:8dbedb9a8637bfb31017e6bd83755383608b33548648174d0ecda9993feee693
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:e9f33f3cf0091562cfc73ea60dec32797b2a628d844e08364bdc06d7722653ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:0b71b14aa369e82221061ceff4bcacf611f838edab09ef45964df177cdf429c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:0e30967c2da5513ef76c94764df2e1ec7c45d71c35c793adede925a4ba8bef4a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d7b5c38b47f576b122e539ac7c44172852019b10140ce6813317c360615dcb88
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:a76c88126ae70edfbfa6e94dcc527bc172cd20e9e7b04ef6cb1861705d759ca5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c696b7ec76f322d551220b4512126dc5efd28248e8a29c6d317b84d3b3d40c60
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ff41863850d485f4a6f08d0fc186bc382fcfcf510d49236cb957209df38b86a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:0144b9ec082fe4c28e0a8e7b2d3cb1c9d12971168025fef5eaa85acdf9421a0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:08fd101ecbeed2b47bbd29a629e44d450f360ab71c16f42044d5fbbe7c9deb3f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9b88f08c811196826987213043a3577cc0351fddf47b403e3de87110701e2ff1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:98f63792a7501fc8b9b9f1718a9f4c1b17ac8452e186257dff9185b447928e40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:acb8d4fe5202d1a5389fba5fb168cb6032a25244047e98880d7e02ab92de7733
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:d25fb3f91fb69308faf8c3a7316029ce079c15e145f77de4d3167e66e8df7a17
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c88e5abfab6b00184b4f3038b5da29ef58419ed73cec1aa6d5373e15f113fbb6