Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips, 8.2-debian13-fips, 8.2-fips, 8.2.34-debian-fips, 8.2.34-debian13-fips, 8.2.34-fips

Index digest:

sha256:405c9e75bef59ce2e7c81749ed0990a8b9157508abe9294026f68a65151123f7

Manifest digest:

sha256:72bc53f5a54614ff6fa8d48f6231c7d361dc6f4df51a00af5fa4a8323a214c29

Size

33.91 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:57411d4ccb719f47b2f488f3f4f6f3b146a069ac8291fe317a7065ed573ea0be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:6257f05488fae2222fcd1ea7586097ba3af4bfafabb7b91dea10d6e2dfc3540a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:6fe352fcdfc837d7b32a93d28f604f28ba16005ef06ce0660e7189a515daf482
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:775e353f911d6c5b49c50d8cd81b3322a91a060a23d6818182bf46eda70ffe14
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:f798adebbb47684535e29eeea3ae3670f5909d39cad90372bd1077a2e414d5d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:8e048c37a7bddc17ff509cae1574072833d47176e96ed5712042e8033b1b970e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:a77405ae4bda67afa8bf68bb23460ca6bfb13cd6aec64542ec05b02dd201b8ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:09170bdd516ca1e61f56ece55f15714e2d7004df20794dbfb4f4dd93fff841d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:174b517b3f49efc51ac77d2bcc5c7be5834994899e1b66058b38e7b9fea3d193
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8c7d964ff88454844adb3b642991f146a7c59c8ae4f557ac2b725f69107a0755
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:686460705909850fab0ad7ba43a2931162633efe98ebca40f1fde29608ca920f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:67c1ef0ee28a34d7d4e973b4ceb398e63dff600dfba371fe521295c913c48f7c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:654224ca3fd2def8b62c6ce5d7320708726db7c8df798cfe61a1e86935f4add5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:823c11434a627fada93aa35d13547c8870e566958e25b9faf8a17999d5d8167c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:1c0fa09dabf4ebf88c923c14811c3f068897e2e0dd2b8dfe9b0f11b79fe6236d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:026969d2f40cf1e27a4836cf1040ed9bbf811dfaed54c5a05679451c3110346b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:a2380e5631b973908f899306fd820bbbd198a97e7b0515487e6f6c67acb98c68