Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips, 8.2-debian13-fips, 8.2-fips, 8.2.33-debian-fips, 8.2.33-debian13-fips, 8.2.33-fips

Index digest:

sha256:eef66ec942100e9f6adf14725e5f459d5fd084bf18357a21ce228f8b27d73e74

Manifest digest:

sha256:bf54b32a7721aad634a9d5ffac628daf91abfad197d9ff6a5e55c30b0117b400

Size

33.90 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:73b194b93f3b27b33d981fbcecc8c2b56d805f7c5454b5ac8b8cd94d280a411a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:6799a8cb8677643783e8aaedb6b99524fbaea997760edf399582d43812e8fcee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:f08dbfde31864d1c2de9ab84fd19dc28ff4a26617a67048adba5e9ef5233e3b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:4f7b71e7051fea0146736c1075dec1921a2af6b06e70e63c185e441eca053a0d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:9971c0bb23281eb78792d1bed894f012415ca0e13f27d0161f2a22a8b1f5cf85
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ee7b9cd4c394a93d2f5842dbc36d89b0dc091797758115e766e8e48f92f0ad66
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b057f4af1db067582430243e87cd1b0b0f100eb626d53b2c6b72a3124767dcfc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:4ad7c6b64be0df1c9cc7915837351ffabce3fa68faea4978d117126d349343d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a9279eb5797eb32123fcd1521bcf27a5a75430f0f8052747e610bc2c3c85e2cd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:0d9b03bb9b315b12c33b5836236838919a726c040f1011bcc49e33b462baddf3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:736d287effdbfebdca2bf54cbf0a8fbb5ed0784db844ffa4310aa6404d98e506
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:5437454ae8852385a1f42abf0ee27fb922d8701046aa5bdc60ad79a003c99ac2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:97865df8fcb0c79cd1776f95bbb604c420e8849728f515eaf95d314c38386451
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:9d96d7dfe2e9b64ae602fbc601b3bee2b7c1d8ae57fd6d3fecd0c4183f373e88
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:01f38db10295756029c31e6c85f01a7347a6fed94517e340af65f34b36556a40
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b06486d9c52a305e7bb6d1c87ddbb8bcbf1d5337ac826fea7bc8031020aa087c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:caca756834a4b28cf6ea82b0dde6b13905becd7f25251cadad52c240dfcebe49