Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.2-alpine-dev, 8.2-alpine3.24-dev, 8.2.33-alpine-dev, 8.2.33-alpine3.24-dev

Index digest:

sha256:16f11289f6950c4bd3399250e709b15cdcc79cc49abc7d3a0d7b2664a22193c9

Manifest digest:

sha256:66dfbcf139f6acbdc525141cae862cb7a8de1ee2fac62b5058d1e6e8d877adee

Size

131.68 MB

Last pushed

7 days ago

Vulnerabilities

0
0
3
2
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:257535220e1e42ba4ef47448b4fd2e0a0b69cb278953042ec43341eee2372db2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:60139c7d463fe7eee9423cb9adedee5ae1e027e30d203d5971d825aabfca2c8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a3203b60749c9100ab27ab0b48633bc7e9a2c500489828ff6df92d38a1c4f67a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:9beb7580c45da753969b637a8398ad018952ed02563d15dd068c92a964a7d03e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:a85e1be568037889669569b10f12a4db85e7bde45110f8e66ff2ba38ccfd9d15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c7975ac12ad384ff63547063f4e15f79b27977743881586a2293b246b6d75f0d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a29597bdd462bca4e04fbd90f0e74fd80bc315576ddbbeb0011a25bfc58c8b22
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:bf216b4e9b6973b65ad29b6f341d70974abe2f272cb83065269f465910837135
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:7c751e23a547d12cb92fa85865c62ae5f75879a7b89fff96ddf35f107c5ebb0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:04a867384d2ba1708f1c1e87547df64b5ef540d7208454d3e7fe52c4ce869235
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4e9abcdb54a1278b9fc98c5902fc04842c7ced96bc5a23d262e3686bcc6756e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:10943ee98709f8155747d9b2cd3b32b2f33ebe0396ead11af9c0a9eb35242790
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:f144c6509794799fb6a383b3e195bc945af65c00ee4965e388c8cccbfc8e2130
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:82469b814a3a6d303e0b084d79d8a25441811502433c10408bd7df8e25c7e8a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:191cd591f2fe211049ae90b4692ba1c36e0cf15c1239c57842644d55c5e050d4