Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.34-alpine3.23-dev

Index digest:

sha256:32a79d4c70aa146e4379fccd33bb7b7850b8c2f80ebd53cc384bcb011e9626cb

Manifest digest:

sha256:2c1f20bdf89cebb5f3a148e09fed0425ea664068f634715ab1ee81689e763ee8

Size

131.10 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:7a7ce29fbaedc1168bf93581abd9212a8b31f4ff2eede8d3277a3af0b69cba38
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:79d9854dd098f6f719b1eb50d719a7d0791131b4c182a9e34884fcf1bf40bf48
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:71021005127f5a6301391a378e9e0fdc638162669b6c92efd625fd2541b3a167
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:79b08008e488c15f18d3081a5ec1fdb89e7be62b042417581146c1efee83b682
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e948864206c54783cbd05aef7f59a63dfe864a5ec6aa9beff028e0d8ef9b1a2d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:d34f78eb5cd4b5c4873b1ce19dae4e953b5e9e5b77dd00f1d366c61c8a21cf5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:cadc0ac714a86e713df8f82635a8ab4ff0a7df133b454f23c0a75b79ab57e1e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:2f0649a747062e1a456ff5bb0a7a462e984ef9ec03f71f58c2a728e4990599b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:5d4d75a6ad18a64cf11b115bb3345f4b24a9d40a46728a149965ab8c47868d34
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:e627d04f89f574137c2356c0f0683d6b5a0fff4590dffd8925c76f03148fe49e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:f0dee0ec0203aa8cebaded9008f83b1714f1a3cae4b12d5fc09fed32f6a8d6cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:463ec57c8d6c653faf6fc6dee76f749eaabe8e2180dcb614d55e086cd0aa65d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:de1a3ab322d0a8d4504c4d067749532a78f3be064f3c516f2f0043e360a43662
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:d4a72e100eadd52db06b3893a340a5ff0ddc8e6f936a08c1896c030d60399b7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:7dc724c7a51af42a630ef8d160f92e7594c543895220c49717919f99f74331ca