Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:e403c95c88bcc468568623a5e9fdc7b6f03c65986a72b7983ef5a2814b7677a3

Manifest digest:

sha256:70b42fe46f17d0d1026f5f1fc85c8da7e7e465c27dc94bacd63eedbc394e037a

Size

169.03 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:1e341d1639109fcebcdbb7d291368fcebe1d9fd92609de8f0cf37a3bf1e23e32
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:c813818619643c83a1d84ce1f695243e0f002ff42364efd9eb0453f219e8e9ff
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:f4f548058e062f7d380c511e2b7e3b9210a91f89e5fb61fb34d0d57d2f648741
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d433d6406119447e5db8ee1644a14c02a1b1c27568bbab7a8e25dd9c8785e218
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:e96e2fcf9b6b4b2663424f2102b72acdaa0ee118b85fe02731031fe72b3eda62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:494ea48fbcd26806216c8834ffa9e5af81dd8dd099c29b8f1929b0a5adba68f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:5b35d058351a88dddeabe4405e7a08abc443f9562dc3d5a59f43f47059bf604d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:66797d74775c60d9ca234477bd6978fd766b262a0c9e3b818f757bd441bacf21
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9cc41b2030325fd3e0084a1967533b41fd41629af8858867eab9c7dc7e2ffa9f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:37cc0f0c96cac9e60c0ded6669d80e57720c12ca8cb1b9c5d800c917fd3dcfce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:81b393fcda553631dc1aec4b15f3fc27addb0ac13765eea3cb02d88d1c26e3fa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ab3424f99edb0e80e388e7e6441f4c34965df4b11eae340afe248a770ee35538
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:72d0505f3a6d984fd29d8b79b5be7754b629a84f78b6ada684def427cafab667
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:822af4a4e618a85460b77542cf93c63575580f70f52c424e69cd1fc780768bd0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:212f65272ee2d8672c5b42a025a5b76cd95fce275a52ba820b86a5466952f5d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:e606b8d83582cca5b3328d6ec361317474df1a0dd8cb164afc00b6217764588a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:64c09e8eda6452adca60a9d8ce6c2da306a4e933fbde9bf2813e3b60db94d96c