Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips, 8.2-debian13-fips, 8.2-fips, 8.2.34-debian-fips, 8.2.34-debian13-fips, 8.2.34-fips

Index digest:

sha256:64de8e6ca851d71fa9a0b81c598e0a2c93e64984e53d43d27ef552eabb7ce945

Manifest digest:

sha256:36e4da7308a616cf897b75d17402166e6560a806b36f687f1649b58e663af874

Size

33.91 MB

Last pushed

2 days ago

Vulnerabilities

0
2
0
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:5c071e20af2f7ffa4e6428f3c2652a40e03aa1f69c39636a34e658927f068f2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:544b31f3a3a533b1825f4609020975d88eb712e9d02f908720af7bcdf6dd4622
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:34b541220b4016a2a11005e5b4c77f2b3e3fbcdc0e5692dd2687b2f65d1fe97d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:7865d1707b429a2c9c8a13e918dbebddc295bc42f75b62b6c5a7a8c2e5f27703
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:58268f45cc54b5514ceb1ca781debc6ad32fd7315a3599d390b5c8a7352236cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:2c6cf742f5c35f8dad0351d61db1bae5e9069e9db48486db2e0c617cc6b06f6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:dcca04fd13f74b0bc502f35a50b94323a97d61c6622eb9e2895178c08dd78fd2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:ff3a0bbf0a1323d95956ae1713438d42a7faa99455ae911c5a75b2a57a52147c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c8f0fcf8112b8803a4cf811ce85a63340dbe2f5a313224cab9d92f5058dca2cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d68a0896694aa304210ff6108349758bc33d02bede37ce34ee419c2427dfdad1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e16951861f2cefc56f1f265aeb0b4fbeacb97f5694dfec618117e1ceaf13ba7f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:8f5109b32668a24d088bd9701a10124d35af808a6399410cad2aa9ce3de25534
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d0758e0f7aaedbe2a583b34176793ca00458ce007a219896ef438a917b479c2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:33abc1e30ec44eb9deb7cd3d8e93a49ff626b3f197d2173f1f0e237e64af6b1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:829d393c1e5f431551eda96ca934ded5fa278c0d1145bc260c6c428c35692dbf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:e3b54a3de11931591a3f5fa527c8ab1d15838468f529b765350d3df402d729ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ab77faa610fa620f0028ff64c1fc862d6e7612fc0e6cdea0e23df18cb7264431