Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips, 8.2-debian13-fips, 8.2-fips, 8.2.34-debian-fips, 8.2.34-debian13-fips, 8.2.34-fips

Index digest:

sha256:eb377ac2f2c053e0720c41a28e0951c44f52f89487bf8af71c113f20e4cf0fc2

Manifest digest:

sha256:b484973cd82e7ebb27ac0a057971c6eebda4acd8e7bef11e52aa396866c65bf6

Size

33.91 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:782e5ef0b219c05bcc885bd0ea5753d923d90c6efb43be1daf142a7086e0fbc2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8de204e013b94b087d134e5725db0c66e4977899d67d98181296e43447c156a5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:8792384d32e13353f755e5c26338acc4b59bc4415dc0e0ce48df3270956b1737
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8ceedbd98cd2e63c94477aab4970701b3c6e72ec6d63f6021d1df403346bb1e3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:91d12bc8571e0b792e8c7e16971b9a1dcffd8cd0ab4f60b7cd16cf902807aa63
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:5e5e916fe1ba89dc1a64987f0a4f548e317b5fa473efda448caede3f30c60476
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6a05bc2ff43732da8ee1020570260f6d1deb7a838c1bfcabe1c6dc901b83ccc4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c9ecdc5db49f20b638d4480810687ac38e5b8322893702e78a33c35844bcee72
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9a7482a59ff5d7dbbfd4303160974d41f5b20f2ace5ad6a795d46e60474a3e7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:35e2a6f49dd4227e18fdfe284d0994a65e194d3f18423d50492443a1dcac811c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:a9e4401353c93ee8baaa1f596c52158301af496d0f5ec54c859737e429fbfdbb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ffa6de39e01ff3e60c67139f1676755e841ab2118cabc54e07354b1c7acc41d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:ba110bdc86142d7e2e650b6329963a7dcca33adcc3ff867066ddd38735ad4f14
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:97275d66cd7978726aa5db5609fccb00c75d074f4807448944462656708d8630
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:266557173ff604bc486a157b690cd0ed63cf6e93675acff22d5f241b0411764e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:3110301761108357956057bd0b9e19cc1f9268ec70c379fae9540079d9069e5f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:31645adc81cdc9fc69a4bda78345d8771c4edffac8d1f2a2f36b9cf54a63f75e