Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.2-alpine-dev, 8.2-alpine3.24-dev, 8.2.34-alpine-dev, 8.2.34-alpine3.24-dev

Index digest:

sha256:9608ea01d24d0934b10610f6915b85f5cb335f249e81a528ece7774b678155ce

Manifest digest:

sha256:a75348560730c4c706545d1344a7cd6680160a7c393981c353bc2531f0ca79e3

Size

131.74 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:9d6d272c2cd467cf66aab0ad15eef7431b3387aaddf780bedccfb0e20cdad9c5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:04a65c7dc66c7b01c74db770b827ee07e510294e0a221f9867753026baf640ec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:cc16cd45ec2a28f51fe36dfc5013ddc63e0905e2e4e156a2303638fac897f7f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:7a9a3292ac28e4ad0004475c9c88f359318580b1eee35871bb6a6e73990ff63a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6ec8d8c6cbbb40e07d8e0c7f11c9a1c41abf28929352789685ced2af6b614944
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:1578e0cec1b919da9b438eaacf2b24c3eeed4cab24f56365045a62fe1f1a9366
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:3e3d653d3979c4631730da9de1d861e20b9689ad9186cb64da748d899cdafde8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:70d705881c71acc9334d1b49945319c838791aa17911b550dd23a35c808967d8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:eab5fd97d4595bb00845e7b5f496fefe8b5501a725f19f0746bf78d03f32563e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:1f389fbbd441712175869d716884d03bdc0be9baaed2d7102d2f14fb094f532f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:c804266efdb09ecfd766a9f086daa44dabf85d6037e41ee4ea75d038dbb8681a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:487f7a8988889e8c132e995c61afda433ff9563efc6564614c7666485a86080f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:8cc3b215a7d148397c4b5c615cc029a8f2b84a8e737ef368cbf16ca8b3c5d72d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:332a910fb00843ba6c010932d759f9a1ff6aa42326d3c449fb40bf51a5515887
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:0872105ed9ee27f3a93b28ba2aae81bd2e8cb28b46f8a2883d4b002ce4d1d2f9