Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8.2-alpine-fips-dev, 8.2-alpine3.24-fips-dev, 8.2.34-alpine-fips-dev, 8.2.34-alpine3.24-fips-dev

Index digest:

sha256:3f34cf973f662a9c098967555cee944a17cbbace3e4af025aa314a36e81a7048

Manifest digest:

sha256:116f9185bfd0e636566d28b060e451cf6c63356c95c0c413bba20a30fda3ab66

Size

132.83 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:1e752e313934375dda2be934d2fabaf3fb4052a0acc5ce34ee67fa5765e3b7d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:ad3ddc1e1f9422fb62f8f2343329105c960d9c498ab391c65337ac89f9beaa59
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:bca388de8d49de2e55758bc9b115cebd563379a74ae543cd760cac5929e940af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d534105e55f5ab49b5f6c490a97d3d12b8b07b76e31c9c3689a91ff7960cc874
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:6499c07aa8f202ad222c4b1eafb65814c6a3fbd9f7a72fcfdb33d4e916be4523
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ff16a3b3b0f0b42bf4fd9e89db84f414e9ae693d714de827f4f9b9ff646eb29f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:879a8dc5d2cd42849a9bed7e1888eeb1fc2d40a1cc743a58fc485640b3475eb8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e7f85e0de41dbe5150adf7952a55b452ccb15fe867ca37a296ddca7463b93c40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:d62bf0afd8fb2071d865423b2ea426126c06992f473856e99955e09c28db97ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:466e7ae4fba62a504e3e228a528205ab49b8ef280c215d3f7cc82b6a2e126b6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:8704e84363b9f1d5fde911ab668eeaa80baa044efb51c69c4828c85b328d13f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:85f5c4c87a437b69b0c7ea6c7e97a9387bb5813ce9e6d04e1a5eeb23d5050b5e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:c4ace9eefca221d0d36ac43c986fa2e17e45f669474f25090b98e0ad01354045
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:6711fc8725e6857c651a19c83e9c80dc434aa72ba8327425d5a64e1451df8882
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:324c3f376a37f7af736fcfab73a70efec744667b1348ae70e31f45b9aa5cf127
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6ce7fd20a3a9695808cc36b02d6e1c923c21a3f892ca12c245e8870173345879
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:5b2fa90bb1118f20618e7ac39ba4b808e91552781f958d69b1a803a3cafe5f00