Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-fips-dev, 8.2.34-alpine3.23-fips-dev

Index digest:

sha256:6c0efa06a93f5e1699dc88f276d9e42f3935fb4e40f1cd7eea5d27ad65d4227a

Manifest digest:

sha256:67aa33279d7decc48f6df389ada61b14d66ea366e157c3574885c3ee7b774746

Size

132.26 MB

Last pushed

3 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:afbea7797369a89582fc1a531c072a3bbd443a6ef2201ee759ad6b1e433a840e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:79df043aaf54d62dc644397ee8e45e5c17f6e07e11e8604489dbfb1314f1e770
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:c26bae65ef90ebcb84589051f5fc6b0b97b8e519218848474e9d59c293671d9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8d3a35b5315611bec8e397d882592c96fcc1d8a3f162c7d2468e526e00f33677
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:8102748d358b3eea46e26dc127c04750da0e057241d01c8a26ff3f800d0fdd84
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:2f10c2476394877c1ab07e5459b41b4b7c13bce2eb21dbc59d92724e689f3b35
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c3fbeb11e7c80bccfbac97f8383bef17ff2daf6092ec59c4fd22038537d87da2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:4657ba1c9f8f1d4318b7ff7fc032a052b294ff23e3ed393a293539d1c4da575e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:176a84c326bff7ce3ba5fb31297fd96ef7bae18928d3e4e40275900aa3c2914d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:5a42a82f7df94b083ac9dcb54a0bbd38af2bc287dfd9ca610b6cfef17d3bc0fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c27752c736f30188adce404e41a153245c37e9170599ee97560cf9cc7026d6d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:26178baa9d5e864d3eea644c07b227e291f543eb4bda58941b7bae0a41dd2de9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4a3e064f12fd684a36c45c0137565459873fcc42ad94b861afcc74748f4ebeb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:add2ee52e92342e0523ce9e17b6b4e0ba2effde71e779f240d82a99080ce106f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d0b28d61b3b650821dfb4b38126f695f6babb20a55eb0f02964d7806576a2950
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:aa27e2170cd36047427ff3f31e736f726befb1074c0537d7a6563b69cb1c47a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:7a5d6479a1dbd6ce0efb90cddb7aabe0148da4844528ac00071c750c47732df5