Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-dev, 8.2.33-alpine3.23-dev

Index digest:

sha256:2c63cc73b6a37d045973cbf8fe1277507d462025970f748539b965cb72d27195

Manifest digest:

sha256:39f6fe239f08390a3dbca93198e7bdf439f38cbad62c24a2507afb7439df8132

Size

131.09 MB

Last pushed

5 days ago

Vulnerabilities

1
1
3
2
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:029ccd582e0731a5f1877fc57bd0f039f97825832325aa90ecc510580eed9292
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a71f12bddc7be2ecca154a5b1e8e9bee9ac38b9011fbbd42f1f22d96da76997a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:17db847c46fcef97cdc804c1424a6f9df1157cc425e536d2afd46f70b8ba84a7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:bd44adc50efdf5954d2a41c7b29d911034b50faba1ce8091e5bddffd189d308e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:075f45091279320d1f2fe7e12bfb1f8ad8d678968083be665b875c5f5f0ce5f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:b657847d00cb65143f670c78de9d98af9bae5a9a04a2681e94d7b752f2094f6b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:848a1dd7f0597348a5876bf770b2fc427ce8590907d967921a98cc0232eb3c9d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:116dd0b20e08d6826836d340c8c5c4d07eccc76dc6adc71419287696a6ea2648
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:421700b93dda5be09efa7ba70be5295ea1f2501f953f9ed16ea52c9320125b94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:767abc0df43ecbc4a49c4526f3a0b3d0b778cef9066b9773375909e3852d2a4c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9c91b399ead61b71529425817139d6d6d5c47c8b26537425e2224dbc09389732
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ab60e2618a26067e6f70916ebc6f22d1c7cbdb9c0ca129b35c930b2d7f1c4774
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:3e869f7eeff21c878de916b9830790c66f3c3ffa6cc9c9f649f52445c6ebe05d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a5a01f67de86378e509406d477ba3caafb15cbb16b059f0de4e1b7d1804376b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:29ef385fa10133354e0fe5d0bf3f39c871985a4c2b953f541dbbc1c8c439ea32