Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips, 8.2-debian13-fips, 8.2-fips, 8.2.34-debian-fips, 8.2.34-debian13-fips, 8.2.34-fips

Index digest:

sha256:84ef761543e1b33a5b1105f85b7778f2035a208f14e31c968f07db2846a90129

Manifest digest:

sha256:d068bdf1cde11fc4f9504825dc211e3fa66f647b9f0c6a9c5fd632665f21ebc1

Size

33.90 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:10600e1757bb26bf69671439d34df15d13e21413225da15f779f3b659c0f3c93
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:d6b3838dd795a7a38cbc72a5c77a07d41e80e1b5a2fa74d6b80e120b6d7f7c9e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:d7610635c07aae8ef962424037d634afd7b12295110534a9534f5060dc8e3a11
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:4f62ffa64f2b64862778013b6c669cf6a71cb4bc763459202cce8561dd9aac9d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:b5039264bf5f4c9f57fd4238b97f04bf99755cffb70543d7f32ac165d71db4f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:24b084ecea86d39a443ee376bcb79cb786c7d3ff8ef5048f7386d5e86d0701d7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:29e55aeaca680adbc493bdff6439135c2f423cf23246e8bda0269d921e55e981
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8fa732bcf704e0e9ef91f37cc8b92d8603362ac66532249233e45301b4192ce1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:16a7e45a1e299f8e7a5949bd767cbf0f3773acf98b362dcc83475f4ba1c77d21
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8edb6fe9145656c12d1ca43573007ff73c90953274210f23dbeeccddd84caac5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:1eedd33df90507c62f84ba8da8ab7285a785855d3019ef6f221671ac4af78125
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:6d1814655a042ba0882cde33e95a927972c967c142571834c1cdafd691c71116
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:47d18e55ca703cbd556330588c4bbf629cd8f14ec368dd67c050bca9349aeb2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:103516abf4f829338ddd16cb765ca65e62836d0be2b1e925ced8b3711b076f11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:da686174ac65226e546f830ab64f77da4c8adee6bb78eab2ea3c59a65952520b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:9af3e121a0c0136f7f1b3fb68646ce217b132033dce916d8bf39dce94b04505d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:0182897f852385759cd112f057b4d9da21414900adb47ab2e21ef2802cb87e11