Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:2cbca17e12b15e7882ca035e07708db2ff91758e72dcff2b33af769f26e02cc6

Manifest digest:

sha256:055731dba8d01a50f3a52b301a362b31775838db9b246152d462f0411a01d6f0

Size

169.04 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:4441f936b71f8b75726f8b5c0818130de2913032efaa3f619033e9772352be89
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:26c6e42cb045fb30f0c2b2a4614796ebb1ed13249e11ca5ea82ee0f0ed543aa1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a434a01dfbb2ce47b4280de4ac01fd9816a837d3d58aefa3540308f3ca9b2e2c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e5260065efdaedc43c37d1b1b808f05f11399353692fc01e50045e90072b208c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:4f3191e55debb3a33e1d0635fe6b5d405bedb4fb2facc2c5f0ccb4f979d1f6a9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:0bd45297f3a9009ea3c0793eaf4ce8e6c9e83adb1bfbc29129e2c384cd5116f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:8fc7df049053349a94e2dd50d04a3afa584b02033f27ed7f7a63693df0cdae47
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:ac9e698d68db77040c6552b760ad7a9887f5df763d0db4cfb9890bf1e316b8b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:2abf9f6873c981ba06aa05712e36777d0e6e9fb983a2b39962937c7eb0563fbf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:68c09f30da91312a888763059ac62e093094e3027dddb0e273705db04bbc68de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:63f4f9a49105b53ddc209fd9d5dab5baef2664392961f24e7cb93301b8d911a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:1774cd6f375a08bf2c5d907302df79f2cd1738af8822572be07c9ccedabbe41f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:8c283173d9b0734e1c87e6f6c11149fb6ba5e06da4c68ef75652df35a63e5825
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ad48cd4824bd39da2312e6be5a25040551a0438edff431476b75763a9995252e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:5cb4e8d05a4d391911e2071a4e77a45fb3746916719234563ba3f86dff7612fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:6986a48535d3c01361d44610bb420b790eb132017568530b28822974f329bcc0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:50875df2fe8e8707b4eb50ece5e3e7ba0068b26ac573d2742b1881f4b50d24c5