Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

8.2-debian-dev, 8.2-debian13-dev, 8.2-dev, 8.2.33-debian-dev, 8.2.33-debian13-dev, 8.2.33-dev

Index digest:

sha256:a4bcb5939d6be0d846ff3c43847cfd5f3f07115b276c88523a0d3fa576cb52c4

Manifest digest:

sha256:d65bb4bfe1be9a164829bb3df707ccd0fb4a770b60408d2b09ce00559c70ea43

Size

158.79 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:d80ba85847163e9cd9215dc16ef308a5fe5feb4d3caaae6db2c8f17d6dbda707
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:c62d3ccc58b2b346dc994bd320479670dff26eeb552eeedabf7b5f9cc7fd5f2c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:7342da8b8b6afad50693efe44f72930604d62cebfc9d1005bceb30941b37ebd0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f79663d32b12d6265f285a6be5f180118729045701cf4c51a61b7cce27ea654b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:a585df4bcc836939b0a2b61cdd81653ddbb621ad2425e98580a9556fa0b9ddea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f76a33135ac2bfeaf7734b87bea85bff5c2ccfdf6ec7b7d157bb645570dd6c0b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:24af5e8d2d2e87c549bd1d606f6bcdddb70b77ebe706c5e6774b6b785744caa2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:b8c45320071d5c4fff607cf73f212013395fa193f920722db1eaa499af2c1855
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:135d457d32664fc88ac80109274c2faf1c8e668f49d5f9e82f9c4e0f5d4c900b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:80c2e33cb939e2eee445f5b81c99971f9b61eb596d3e7da8ac77d7f7ab1c8d42
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:fda93390a34fd6d58c60acf6e597d78f9d50bad40d046040688b7e6214ef723b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f2b28ca58d3696bbb281d3030273920ff1b2a15ba9b256841733c78b9d48bffe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:72766d956c7e6869f157e1b7eb4f945de802fb4710c9ca27218e31312f3e656f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c84f2e8c6566bda3866302f26f79f5919fcc5d77eca49cc61ef26d858d579583
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:7a015fa4746cfd83ed467a23a80de4d073a0320dcfe4d1f6dae4f55348f6a8d0