Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:d4d7679321f3b908c20e1df9a77966d42ab9f03bd399e0d8e8a6d276a764f687

Manifest digest:

sha256:9bd41f2883633adad968746a8683ee2866db981fc3a0a648e272665ddaab3585

Size

169.03 MB

Last pushed

22 hours ago

Vulnerabilities

1
1
1
3
1

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:cd954ba4805219d210e2ab95ea58c915923bbc41f20ec5b2e0e56f150cb0c52a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8e1a2e62d57006b293141cfd907516c74ce51d87bc3d4187e12cda9fe35cf46a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:ed01d6424e1ed17765f213475ea924c86777ecd30d3ccf064d27d724af2bc512
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b0bdb6d0fab7fbaa59c0f0371a23180ee9d6617c60a5b9f0712d265c457f4804
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:f3f50aaef16e8082ba88b7c69c9be4035c6ba09707402b597ef6046593e881d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:da63b9ad6a37877cf94cf13b9f798cc1c6eb9a51890983456eb629e46e14c3e1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:962a3922ecfa3f04657cb13fffe0dc712e103aed43cfabb5c78cebc79e265ca5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:b5375d04e6e8731b472345e5cfc3fda111b0ef3263945bdb57b46464b24d62d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:cee07037896ba3086629c051d70be915ecc40d3ca1e1a32eb247004b9464a8ea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:99401c4765c558d4beddec48c7f6385697c8b36712ceb29338c3156cab663419
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:106daddb191557fc388f372e864ec06e5cdbf2b313727aba643ef13d918abade
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ed4cc6478de54e238d1c007d24b72412a177eed6db966207ea2e57870f3603b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d4e2c890ee02698b536fdd11c0d95f08bb0bae3e955d3e0ff5d140989e83597a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:bceb3992c020cc48703b29d7a84169099d413132d56df1491059a486e388bd84
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:f91515edfe7e7d824ba54aaa849bb77096cfbe8253e6aa351c0858fc1ce16ec1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a5fb5e19bcff2bba8c877430684ba12f5fe56c5770d819dae3710b1bd0d0bc57
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c1e0739eaedf593a6f026bb7b89abbcaad90449133579ab4cbc7185912b408dd