Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.2-alpine-dev, 8.2-alpine3.24-dev, 8.2.33-alpine-dev, 8.2.33-alpine3.24-dev

Index digest:

sha256:6377c3381998ae0e9d832626cdde3136e5beda49633d959fe2bca9ce6a849cfa

Manifest digest:

sha256:adac9bebd7acddfddec0dba6dacb5a734a0ab3ce072ddf75170ed39f4c7f867d

Size

131.66 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:a971a17c798f0614afad4f7f62e52d527f4f15d1a7702da6d362892887c38aa2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8831ae7208881f6da0e7340d02a552e3db361ded77f1f48c48b3e977d26eb8ab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2b82a7188094f38b98f9bf4b635d0be8318e6383332a0dea3932ed0d434c3235
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:7c4b6a154b7d31631e82495070df5e6aebc6cbed203d268dbc57bbca2fd52e7a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d359640bcd49b8fcc57ef76a995d6e068a921c110bb1f4e5380e0337c95a7e10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:6216b01f8218e7e3cc2d0f18a30126654629f71be3b080e16c91015680df5dd3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:530359323e741eea9e27cd45d0168f0515f71299e6b8768e509daa544df39695
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:41aefd4917b8516e0a2116ffba36d6430989bf0d4b3b2525514a92855c617762
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:9185d6c98a303c08ce83bb7ab934b1f63dd065b3e44c2818ac8aff7e2430cb96
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:fd5aca2fea700cb898c7aa5740c9eee6bf62d48ab326f81b7e2eb72cd905e96f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d4c1b48c86f73f422ff5dcefd42383083c5bfc5860b5ae38ae3eb21fd2d3a535
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e208da23dfa82f675409b96cd50a244c861e43eb42297bf3ad98714fa429bc0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:6389c2f6d4512902e480dde3a50da27393fe9bd4b5202d799190bf886f9769db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:f17c29a6a6664e363ea27f8a830d5b4b30a08e99f09c6b99bce8410cd4cd2ded
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:d064c0ce972f407e3dddc5bf24da5d2790c5055564964d536a3eaa06b46f5871