Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8.2-alpine-dev, 8.2-alpine3.24-dev, 8.2.33-alpine-dev, 8.2.33-alpine3.24-dev

Index digest:

sha256:025a06f6c82706176aa6dc5e39a0f17513d15f2a32d8d6242c2f2f441aca5c31

Manifest digest:

sha256:ca5a3e805c8e13df33b3638a92b7537277a1a4985ecfef034743375528d38eb1

Size

131.66 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:103a289bac5118a10bf93ea407eef69ec48773b192b7cfbce516c4a453f50aea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:c5a4819eaf85c9c5491487a3a3c30988b971a530f13993bc46504d7f2cbe6239
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:0f7e62deac1f04b409aaeb58fbbd8c9958b7d93022e7dffda4263c8daf232ffd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:15ddebf38ec4094314b023fec640b6b771056ba1ce2d176e5d10243dce41a7d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:dfbb01a28c7150c9aad5741fa3d365343224907194887e3dfaf586d80477f5e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:965ba7dc67b64bdbf1bb626de57b38461baf1795ac4e7b2ef601721bbf059593
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:42c6d60fb34926d44e9d87595ee02c3ca9ad7383a4c8db1f5df2bfc59103b188
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:961e3fd3cf970cc048769327032b98acc2f5d77ea0ce4b3a386d500093fbf770
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:459acbe78cab520194af3ca9800ceeb4bd80937d1c62cea66fed9b97b1eac1be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a82f9204de990a6225a0aa2f2128ae3728048b239da369971907b63025be976d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:878074addcb92d7ba713e2be0dc7e113dd691fb37c01ef143585874568347527
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:d61f832741b629271c428e5955e8d595e0de1c4797e34dce952db6194d115bba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:6da0d68709a239a165026eaa806867a2fb7f9b829ff4e65b054d4893b6b10db7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:78467dfa295597e3e35f342f51c1ce545d9eeb1d71dc4ac737ad338cc2f7ed49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:5564553f3766d28f4a227ad885f2e66b2d9c9f2ee6e8a9faa71b2de68282e32d