Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:2d725d309b5497238d16f4e684b92df8f7c3ac1b065d65843efa2b563044d3f0

Manifest digest:

sha256:d2a9fc768c29647d7772a6a1a77acf20a3b08046e798814cbc7dcef835eeb506

Size

169.04 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f193a7d15373ee830bdf8a50472f17e0967527d6b91e2a56cb19515102e09fb4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:dd2a462cd629c5b499c0d62fb221b50975ced72dd0760b9f94d74248ef082c29
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:22486217fcdb0ba4c45077146109661f5fdde1a3369d93362203971a02c87ecc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a3c0c610232fb91d1895c17b78f2d2512e5009ed7383c31de7dec5d61dff3d71
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:6d76c2218725bcd168a1a3c2bb77fabb77ed84664d2cbb6092328f2217c17ae1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:dd7bac7ed336bd9369ca8c829c9ae7f3e8b7e33525a86bc8f7d536b7cecc847c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b5c219e37e0b89cbd9e9b6aa10e590f330af26d5875d3237fa2d649acfaad494
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:0f650a3ed94ae5af7d9debe0c83658701ef6e3d68bdbf3cb79324ca9df340d4c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:bb87283da286499ec3adfc374f76587178b2620db91bf58e0ab62541d8fa26b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:672f6d556b3fafb51d579cafa98bcc9f9546770ad5ff0e031ef7d7ac434097b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:7e7e925d7774dee3674a9138c58076912ad0724aaee6991ad239effc3c8af44b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:6cbbed97785be9d196bfd68f66fcb1b6cd5c28a1a7eecbb44bf291c7b9f84e39
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d7c783a02d9dcbb267e59e20d7c72215f8f776dac19a923f7dcaf02ada1c9ea4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:5944955d347ca457a5110fcdb4596dd79dcc4e0836864151836ad6e42d0a52ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:01689a7230dad43eac1560e6f1f692008e3349ec8be3e26a4bbaceb7f5c84c89
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:cd960dc00261a86591b555798c4c5d9df3e1ff9d694ed6c4bb01e39ee0113069
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:45db15ee199e03758f812e5a9750f9842d4b1568f86510a8d44876daa366b395