Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:a347704643454cf9b995c3ce91c155817bab5ea25bc918d9c473a33986f640cb

Manifest digest:

sha256:f130e0e6f4dcd0f35f0aa9c21d79c3d19dc2c85d6362fc90d74b42a4aaf62f45

Size

169.02 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:731d767b5e83977f8784e407ead49355121e837e1ca19d9e7b469be6a7b72de8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:9be4d73aecd9b3b3187ab42c4ca107318e6842a0ca15a0f1500df0099e776718
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:4b5c3259cd7d2fef9dc883e16436be2ead6fdbff301c8a7d2a8e4c9279016233
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a289e310db7d3f32ddb323002f9db911a8bd28739af50e6f645adc22480ed751
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:3c8d8ffaed7c51f47217a0f3393b5678f21c6aa3d2b5c6ad0dc0bdb823eff9c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f804a383559af33e5244cb7c1fe56ad0c3367a14f60355cdfe4cfcc6e67f739a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ce5b7160ed2ceb01255e3559c69e248b01106ec2c9c1d305a074bcc079b7da82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:9a758a903fad24129e48ed60b385f40644e63b313a2d51d71d3f7acd7130ccb7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:add4e85a1c89f6a9ecb93d1fb46b6430a0f31275201aaf8f14b0ae266293b2a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:78aa57637923d15071aeb4e700158750783ff4b4f55f096f5397cf3c6004f4eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:81254f64434bf9e8b884c1bf9585a30ea1334c032dfb2c40fb6022bd0f97e945
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:7b80886c182b7d3f5a4c58f015cd1a6bf35f74032c1e58b3513ed66baa8a35ef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:b969800757d6752c206d978e4555c64babf72b916225ce8927ff80edc42c32df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:a14a01d899cd88e5850308549aab4d095101f5052bb630290fe8aeef5aea637d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:aed1a357572cd63ebaf4beda4f3ca8d05aaf33f0b1b3645d0d05e7916ed82b5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b7ee42e3dbb321d27058178dce7e851f0b73c2046d6c7984f205976fc388ef0b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:49987256f372c38f88dfd7caf16657dc6c4b045121c9ffc140f0ef7b59603e9a