Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-fips-dev, 8.2.33-alpine3.23-fips-dev

Index digest:

sha256:410ad9a8d05419374d0e732757f7201bafc079a6b1dfdc69da9b61249e28462b

Manifest digest:

sha256:b2cec90ec4f7ce58fbe0ee973011e6f5ae57597e0d39cbf1505f5b29086d335c

Size

132.21 MB

Last pushed

12 hours ago

Vulnerabilities

1
1
3
2
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:2e40c6e9b922ede2835e156c7bf3eed3dc79ebb244296c94cbd37fc0a5c2377b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4014e1092c20a2000811c3dd821e6cd6e599626e311d056d7c02a51f650ee128
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0a514ce9686c8d9af4652bb5eaef60d5243c5739d5284ff0dc641f6d56976cf3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:21fadc64160a228df0a3bcb2905c99f965c2e6e1108aad5036ce39ebed6ec017
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:3c43ece48a686333d790af315e4b9c4a3ebc4e5b52a131e88a240f39ecf6624b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ce3fe474db33029bac8ea94796025fa38d12dd53b8b9b71adcd23b72368b12c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e857bb1f582c31ffd9312292adbd7dcd7191ad0797538d43ac0f7e9a6ad62b56
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:cea4100c1c9e3f4435bedee09b5f32c85eb8e1f4a1fe15f899830c02cb4f4a5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:f22b047eb7eaf2c5d590c2694f9b74ad75ee3d540bdcc9d9b2e42139b12b1bcf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:f613df9d28b8709d8cf2b0de9fd129b23870591e4d9555434f63f00d5e13a4f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:779a59182f51e9fc9211d6d373f77c08a12b776b95ec837332af73a4b7ab4e33
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:103efc90da47d103a0a053ddd9fd8d17d0f0e7be122fc5a16319f7beacc546cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:db83fed85cb61225d38ab3fdffb7152803dc01f6ab84343e753c1855edbd0d6f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:c5ce4a093be70611161c58672e6591dcb6d70e417778fb8b1ff01bdb48c91347
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:c022402379259a67ebc5081c5b6ba9dc942313cd1c29f933ba84624920a96427
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4e75c3ba72067e504d15ea71901fd916ded5dbe06def18d0fab215b77c5ec23f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:58ba1ed8cee4ec69e349e4f4b06a9293df5d60dcdc04dc024ebe5508117f46d8