Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8.2-alpine3.23-fips-dev, 8.2.33-alpine3.23-fips-dev

Index digest:

sha256:66f743ddce1c4031c4f8c9ea263059417df347e41aef1a759b933f7503d88289

Manifest digest:

sha256:dd556a8b6a56cfafc723dfe4472fd79fa2fa451f6e16ec390a3857f1462de936

Size

132.21 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:e24b31d874060af531291657542c9e00063ca061055cdf9ede3bb892bebf5c1a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:42ed30aeae2d42b3bee2460fef622665cb6932cba10f356921878293d5cc37cc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:394f499149e8c90c5621ee3e9ebc465c64b1cb09b304254b465c761e45966b16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:7582bcf0f985bb996b3da1e9e3bc0ee166dba1dcda36407dd32cad369ae0b9ec
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:40730b610f281ec78885e769d0d2a1bc3f215012c1a7d36fd57bf4423f2cfb31
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1846d021e46e1892719c6686938c85fbcfdb5130d7d670267ebd65adac4fccdb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e3328896daf3404d5b27a9ea9f6d570a5bf00ac358b69cc137911bceb25e9526
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:253cbf2e6368dfbce6a1bd812ce340ebff941e43ca8e2299c35293d0b5b2373a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b64c1a7b05e191202878b1c9fa2b5c41a0864c77265d1d84752cc0138e033de2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:6ed4fd971f25aebf338e36ba25c6b12400ebaf9d6a770fa7e17c9bad0559e405
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:8325a2bb69266090f744e5c013b0c2b897fba94a994d597a643dac04517f956d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:908d6b19fadab95d464966aa942d28b5635a295c88f6d9ab1137d4ca9135cf41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:84d51a78b9c47be3a5dcde0230809c50d8ed52e8737da2cc204417c5d1da94ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:88fe2e06ff27465ddfe134c551b38a9fc2bf943e3456299311f5db87740708b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:27abd37c81938569c2f2bff2490651e3359497991c22262c0426ceaf045ede49
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:d05d9bfc1ec8ef4cefa0e0e8d01e6ef8126cbf8eaa5e61c811bd0766454b5641
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:decdba210893f81904389da4f5c7c0b0b598dfea281d4e6ce568afabcc39c6f8