Sign inSign up
PHP

dhi.io/php

PHP 8.2.x

CIS
linux/amd64
debian 13
Tags:

8.2, 8.2-debian, 8.2-debian13, 8.2.34, 8.2.34-debian, 8.2.34-debian13

Index digest:

sha256:7ea48959eaf94c4e3d3305764eca61d8b2e391ac7b28f0a687e0a299f81d4830

Manifest digest:

sha256:845d691aaf39f0d18cba0b930a887b96c9954afbb586ffcbb5f07d9e34ea6582

Size

33.13 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:eaa27eb0f0a2af019a5a3a3688fc7978b2b7cd587ad1b44b7f0442853441cf02
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:d38a484b621193a130241487567631ed5c49bda4e94996da9c661d0462faac51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:18f0ae415aad7b9e256c2d7c25d132bfb6529d0507a326a3b260f6128a76f123
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:59c296977f2ffa5a9622faa03af15a1dabcf22a9da5531b436c81979cc00b9ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:0eb70e037572ff1ec30fc508d5254e0d43ec465f8971d5afd0b54ca58d0789c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e1f6f9f4d5f76d6c4707a7ff05819f6f6a5a732ac9f4e5453386c23f5112e111
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:0f717a7631630b19ccf11e1921f665f9f97b70b6825bbe102edd56445c85a12a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:68163e76ef5d9642b24650098fb939b5aa87a084a4d2b33003b1a1a5d7cac23d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:aa487b0b3ef3c3f0d81b2f04a5dcca9829830a1a941c476eb317cf06cb9b5ff1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:05858febfac59bb06a46911278f67063b1ae27564f8dba225d061e87336f52f4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:adcfb6a4b0e1fb7a8732e1b1b5193c5fabf62723bfd60652aabd9476dee52314
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ba0bee7baca3bdd80d930f88e525fcf7a4d16eec816e9400f7f7cd976bbb7baa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:f3e505c6ef37bd14d99345514fa9c5e0b4340c2be4a55f181f2ff20a62a5814d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:035f1ea1a5732509924d07d8896087b0e7a230f43457fc1bee6f8d3b49ffccd8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:2a0fda4d10ffcaa4b0832a08b82ab0d065cb31610acde8da03718ef6a4cc1163