Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.2-debian-dev, 8.2-debian13-dev, 8.2-dev, 8.2.33-debian-dev, 8.2.33-debian13-dev, 8.2.33-dev

Index digest:

sha256:cdd2cd4b89c0014517aafe2a894b51ccd5497746f84934c83af2390c80dc3a58

Manifest digest:

sha256:4e85c5471d0287ee88f0389c4ed200e2a7de25156844d6c2bc1392fbfbbb4af8

Size

158.79 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:d272c949ab7caf4cb6a4fc3f59db0bcdafe290cdb4d6e4a7404494a83d37162d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:5fe67c9b6dfc13f2b448a0b6772e4988e0367b40f58ac42637fa4551f0dd1436
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:5083f8873e9ded96e850ed7904eb5b64777009a6ee1f75b62c23b959027d02fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:adaf9f89ce0ac215017f9e880b26b77399c7f54a51180739251735d6a0399072
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:850327cbb90be1746c7f6312a102a258e1275a3c73e13ad71c92105e968f09e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8f3f6656bc38d1f70c5cdd4b766e6e1aa59815a1ed95dc9d2028188275766f38
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:48e95271152d1e9c4cf9b6b8665dd62a4264cd0bd8e245851f6aace1eeaba6ec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9aa30d41379ad016bcdce3a4db9c96b245cd5810308b61848ad90446d3137d39
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:5e3e9c690ba105c2f006d95fb6ed1776c88c88f3cbc678887d04aa0567c27f9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:d7e06c8fe0f5b7260fc5746959c3c8a7870d3c172687cff4379c0b3d43391df9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:454117919c36a231b5471b5cfffcd340b687f39e1f0a48190db32a28f5077a44
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:b89f1eeab257a2ed6d099233244d68de138eb7bfb620650a458a35f1e37d1809
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:67ef3ab6f8dd5a755373ad8e53e2411aa0a891d9f02b2b74456df84db8fa3af5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:2616d18403ef2bb3e475f5ab6d72a47c83513efe854ad58b68960a9739d81df9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:edf86889947e75718817e19cc6742cbe3358424b110bf93332c1c5cb2a62f650