Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8.2-alpine-fips-dev, 8.2-alpine3.24-fips-dev, 8.2.34-alpine-fips-dev, 8.2.34-alpine3.24-fips-dev

Index digest:

sha256:fd1c5892085119e6728ee6a0a766a52abb31ffefce6a79302bddf9e31b551128

Manifest digest:

sha256:c023901907b121ef268c54f99850bfddcc5ece0b5e8b40b95fffba2712073f7d

Size

132.84 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:99448af69b823aa06d2bc8baed49825002a2e368fa05ef4c874d069e408245ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:bb1c63b586399da3ece1c44a95e4c834fef85904dcd3e486a07727f9dd610f88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:970c9b0c0f126c1ad28152cff0453555165a18d60dd10059c5c5b403ef6607bb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:40fb2cafc37e03cce7cc2d024a51dedc786f5a21932e5a8c09a39edaa0a44f7f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:0078c36ed6cf6f500e0388afba168f5db005e2cfaec83209bea75750c7b7c7cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:63a3bc10947d28ee45a1a287325383fc9a36a602b63f445afe2d811f81f0dfeb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:8cf4da842abbe99578965ea487e9e294c0df10f36c43629b4af995b05dd283c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:ec85b12f2f58b6e15f0c43faa7ca9c3abf4eaccb6aaaa3d088240734fa8bbf07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b030150602ee351a9b1d24ad8dd10de7e6eda5c3871c0c61ee883df424e79be7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:16c98ab59d3ed70e565848d29e5a96c171709ed4cff1adcb0e4f174a8b337c3f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:cec25e1f2f57012f66c6799837c259bafa5eed67711d169ed8799abcbb0093e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:6f006647504393f998b21416da5d2fa2b8714b269b6905a90b2c14fd26ae422b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4b05bef650c8a6179122b1401f7a3fc9eb881373666bd5fdd9c608dd19c9743d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f5bad4e0c445457c51b1ca4ff630bc838dc6f286107f609a4e6ea45c111d5529
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:220b04dc404732a144395025ecf09d9dd2c074d9d656b306496b30cfd3f70153
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:293ea63aa410e4a54ac54bdf15bd4c9ed67ef034347ca45a58f1fd3e251ec272
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:b091feba165b7663d374c21ceeaddec314967b11ac6bcd39ff6a41de8f89136b