Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8.2-alpine-fips-dev, 8.2-alpine3.24-fips-dev, 8.2.33-alpine-fips-dev, 8.2.33-alpine3.24-fips-dev

Index digest:

sha256:fc7ce21406ee8e2bc71e4627975038e5fe27f32f3bf202e9caba8f5a50297049

Manifest digest:

sha256:053ca4eb87252c8f252b69ceffab3f70b3aaf176a681a1596d84f902a0bf21d8

Size

132.87 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:40658fda705e1134cd93e2536a5f2e46319f0bfbf7157d9b7ddf598d9cc8f198
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:e5478a63969a9a67abbce4dfe07c06b0b73452acd35d9c667c6e34d77f5d7a4f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0dee945bcd255cf0236e4395ed910e7af4d9841dedd3dce936da37be55036dc4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:9679448d943fe53882d02f1e89d9aba0e4f757f3e93bd319e751604f868e07a3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:58b2d0c29cd58dc2a73eaf8f9cebcb6f538a190cdbbdeeff6679c3a3403228ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1fd715e6986fcc6266c6ff5406437f22f2d530ebf59c1a57ac975410c6d0994a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6f07c728eb3e17a1753aa686105cf050e068f8056a47bc0eb81627a3e301a9ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:7cc78ba30507c14797d5e2cf4e348c9f646bd4f8d8f3100da360f9e9ec0dd52d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ecef3cda591167eb12a7eaebcbb52229fd89197213420118f680fbc902a18aca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:c56600c39e49dd5b081cb16c85a5539835390f58b7a7b20ddf289a91960f30da
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:fcd715dbcf628403acdaeb93e89ab48c203c670138ff6ec95d0fa175d889c3db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a03a34c77cbd6268917c9044cdd5e96de3b36c90735d1055a3cd865a72cfe361
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:5c7447a7fd46c518ca8da21d3ff07f005645293c5f104b21ff33e43f67ffb795
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:2b1b2dd55aabf498da0a789c6406a35fa53b9769a1560c0200fc6535bf59b07f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:1db5cba7728525c4fc018e731f7e6469c69eccee87c5de47a1755789fbb48295
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:18e9ecb24197d1b590e7cea7baa7a97872df4d574c98c0cdb145fc6e832b83d9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:18ac21736e343d43a82a56e1eab3c16f4aca21690397711a6f77bfa524db5a75