Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:9c72f05c11bbfc38d0ff4c4d713700118a1c2ecdb1e8eb8d7711b8e7df183395

Manifest digest:

sha256:4f5c990535c59ced3a149f16a852aaf733c53bbdac58e2da762fc20d8697235b

Size

169.03 MB

Last pushed

2 hours ago

Vulnerabilities

1
1
0
4
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:38e7d8a1e998df216b2546e9ea8138329dbea24d64f24426ff205a579908fb88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:f9575170fba9482bf9300c7efe8d74c8b8a1b7f14bb2cd1ee33c5a961e7b6c9a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0a6103a1dfe8cba81a163050a0cd8a931a43782b55433ecacb26dc95aaf9bfa6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:4e652ce8deda2bff6ce2975e189c45e92deefa1a2f2222a573347af613351afe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:2ce2654037abea1e578468bac73c2afe455811f15e19cd15ad749a48a934764a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:0aae49c68ec89ee536302c5b736c9736182595589c92d6096a158116771273c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c5a823ba0ad501a82680ce467d4554a8ccb34ca69fcd3b66a7fc3ff618d90bb5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:fbb70f63afc3c80f857e8ef7eadf506f6f37d41ff0f8790dba7c976e452fd0b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c67f4a6649dbbc3ff5aa353e9b7a076716276529a14a11c96b33cbc17e5244e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:f5009b7d72c70a361ec1cc52cfbfe33f69b9ec2ae54b0c9cf2c4a4483771424e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:00ff596205657a0e63e3bf2046872304fe62618672d5da03cb805be25510479a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:80a696ca679b3cb7e39dc799da6214f67a878f8355c55d8378d0dca83e4e14b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:cfae952411dfc516fa13c7ef74254a9bf4eaf3556123e2ada2178bc4609d2c51
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:584302790ad47b252b58c594bd388effc350d23961e1bd129b7d66d6fd79adf7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:3a546b34c014a12854453fb5d27966fed4b9d5110ad357641ce922569ed96f46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:02fc0a5e434dbcacec684f49888ee2512ad81d7654146a6fc14c7cd0e7cc3bb5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:38639f972bdbf083af90bae93d38de47193355b79f4baeb13d6ba4dbde454aea