Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:78187c6ac871c422310eaf2ea15f7e59c3d8b3e1bd5dc960474c97d95f714d14

Manifest digest:

sha256:13557269b71dbb374e642639eaa20c512c7aa879b1c2f62b47fed7ab455960c2

Size

169.03 MB

Last pushed

6 hours ago

Vulnerabilities

1
1
0
3
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:3707446670ac397c5baf8b08f0f625478a1df5ee6e8cd53981114154150461e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:e33bcb5fc1a26e1028ac6d3e3d8ec45b2d65cc5b172c501f29768b66b60ead21
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:e2596ce9b02908496786730139e44737d0ac08e96123d7fa3eee1cd52978100f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:4d35c701b8b5296a33a668f9bcaf2d067551d4a0abcd9f23601c258e658f512f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:9836ecb96367759ca1896d33b2b459d86856680dc60b60820c15be389ec20480
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:daf45386b98cebdb089183365f839ddad4a182f5c3aba667f274607683e75b59
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:f47710e90901e267492a642688e8b11c5748c0f9e9f6d17a47602cfed8481831
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:7d11101365918aa10728ba002e81725fe4e7689ca471c5598d65fc8b02c82c5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:d09bd76203649f318bc2ad732f703d1418a422a75da8808d4d0d3588f4b9dce9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:aed0ddfe44a706413f598cc4977cb61d3b4b53e78140f478b8b698e70c2723bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b83951651423ddb92482529fa7fc989385f89d78aa07e1f9068cc99445bb2592
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:0c58975f230f3ac646a7ceda902411d05be6ba71ead888bc5e56c6678e3f4e03
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:f81a29f94242739d0913aed8cbc4d8b1efc5d007530234bcf5df677f62760b34
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:0e6c0ede5bf13cc382fcf4598aba926da17e328016a42165daf5b8a54056b443
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:8ca0fd912357678a52d4392e8d017bf45e3f2f548293a609ba7a543b44092c95
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:da8a2c49d241c1c97287b73bfd780aeefcb71ce6faa779d5b25d60f320daa108
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:afc6657a5887969c86cb66ab9fb89a58cf8e8f5b903a9beea8cbf5a2d4eeff9d