Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.2-alpine-dev, 8.2-alpine3.24-dev, 8.2.34-alpine-dev, 8.2.34-alpine3.24-dev

Index digest:

sha256:7a2d9d162642e2328477a6f7bb55a69f152c16f32b397c7e8eb037a096f2061d

Manifest digest:

sha256:9321cfd7b099eb9444b8c5b4890b7eec621306f9611a48b1522ed2272b7537c0

Size

131.74 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:48e38773fa74cd54a8190aa8f9af446051d08e035e900cb965019926193ccbbc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:eac3c5a5c8fd36e4f6251bf0b628cc8ab5f9be39e540a6c29ae76332066d7db0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:21939682a95efc4983625b9c57bdc3fd1e7187b1b63843877fb60b12f026a491
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1e0f06d6148a69cd41b48c8f9f8413362c25dfef1820aa9ba45af03d3cb1957b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:f520c954d7a6ee13114d6df32e95a00cec745ccb1121f2b738414cac749ea08c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:b8c05fe8bc3a663667bd5451fa8ffa7da1a916ef06c60b1684008f382b170451
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:bbf8ca61bce5aa114a3624c934cefc576c9d84798b7eef2281d84dcf17cfe0f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9dca571d69d64affff9315a84ea2e25bcac41ef0ee1190f5d2fb46820a5395ca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:149079e0fb62ecadfcad5a9194332e20336d19b6f969ab73b440f77fbf43be76
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:be4551a64beb486c98edd5aa7c4ceba94a1b6980a23dcb02036fbdabc6aa43e5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:15577c260a7b9a8357ee200e39e0092716c594aafb9f1fff97fd1c379c4e93f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:3e25f118a76a59e3ccc1e7f990dec700b1a5e9fc646968245011fbb45df82c56
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:0be065567f895e931a81b5fd95efe0df5857cbf1451be3311f68a02731032e54
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:3b8d6b2cc410a40c47758ca9f39ec8e2404882bbfe769e63b1d807c9860f0a68
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ee759291ac376539f6775117636c9cfcfb67b3f567cb57deb782b341c15988f4