Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:92ba5697d24a90cd091c62b420c8c7d19545a1a255f48e5b9b12e61e3ff8d20a

Manifest digest:

sha256:d893b508eccd08b8a34aa3297767e892946c397da36ab8b131fcbe827e45b234

Size

169.03 MB

Last pushed

9 hours ago

Vulnerabilities

1
1
0
2
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:53ba02fb8ca5005d05d06df538fa1f5931fb292a31ebad70d62ec5a813286e23
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:ec407d040bb945bdb87f397210fe68b5b8eb7ff2c760fd41217f3d50d3bd99d5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:76c7ef503a8cee34cfcbd230c2c967a51ea090c8f1dcca8f1bc503708d92b2b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:ede2f32644d9dc78035f5bcbf5b144a90fd83729b4126377638cc1fbd60c8459
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:56679b1f607dd278c4e1ba8af789c0688b88f2428582533893505cd009b06e31
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:fa782ef55338c29f1a24492e189855e9eed3032183184c35234253e666ceccc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:602d8e6a29a6c88cde0d7164ffc85e651073b1533cc8206b261bf59f50b02137
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:36efca4700078aecc9b447d940c0d70926fb89ad2dcad5c32280c3c5944df6a0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:45bd55d96f6bb9123f0ce4346e7892d0a21dad2079b8eb095e25be11d925c18b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:071ea79fd7e7db6ecbbd03c32dca752e0ad6664c6e733d6fab9cd1ea67b5f630
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:33590f035ae84057ed5ac91a48d8c7fa62491fce12a10813440cf09158bdb679
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:286dfc06ebbd84bf060765621f6a469bc5e8e8e57fe327f2c52014e7c248df43
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9c3046c6ca61a60be01a363d6e0b981aed22c0a151cf022910be1696365ca4f4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:95b56fecf0a8bf0224d9c957d1b652227230e76113a5fd97e4e273f2ddb9118f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:ce9a1724af6c4c940ece1d14e96b72532b1dcebd8218f0c546201a9e89d47459
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:1310e72e2e6034edfcee3f72542f68eff9bd274c291968d49e06c7accbe5a97a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:f854bca654338da5468217f258bb38b11ecfcf56a7ded49a64099892341ad36e