Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:bca5a341e5152dce9ae4d2a8d2b96ec6248ce1f5a1c2e223ddf5ea1f94069d26

Manifest digest:

sha256:6fe96bfe0a2a88abfc1256dcda9d69634214bde2f1fc1de6f637cd96cb3a4392

Size

169.03 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:6ab4b6b861315c97b689997c3aef36a12c1d205173dffe8b006d062c746d540d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:40fc6d68ccc57243b4ec8561d12c059b99340414fe0db4a31a897769109a56af
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:9324e75beb48f46f36cce652411b712c538745348d69f895be98c0ed4cbf9e19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:852198d502ec5e81c1f982930f3130c9bc18084cccd60dc664078ec2454e5569
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:23766a164599c0ad9803a894f964e8e2ac2c4825905ff81ad18e2ec230ba8b5d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:542f601f7434e530c14d0cf7c2fc4aed3baa658c3f7351ee5b883693483a6df1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:f131d9b6cf392dcdd632e5c3a950f0c39e1b1354a1e93290802e3e6fd510f2c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:62a1781eb90aa00bbabd14cfae3197a5b9d7d3d4b8616e3f611fedc35994206b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:e7816f7d08890b29cb7bc6a93baeeee73626be8f9fd809959d5a3f2d964b7380
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:0618776c4045495cf5220a191571554b3675df3dc8d96f9323d3bc3915425245
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c8f3372984cea9dec550eecbb8ed86e0edfe7b994da8cab37d1eda346cdc7a63
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:838044067f08e2739b23b9a32c5ab279ca7e567e23a9ed6c806866de59ea7c9c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:75b09b240445b7f1d101190f4ac154827714e070566e0ee63951886f7b19fe77
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:00f1d283af3030f3efe1b535900e05459a1e19ade93b572265910fa29459a490
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:7a8d09e8659bb5b44877212f2d4eb8bf1c24e4b53a1006fe733bc5a358106844
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c81a840f9ed105ea19b8695f65f030173daf2da483f44f550dc51f38fc1faf50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:cf41aec978ba09d9a3503472a350b2005ca4fb5d2a585ac790f281b5bed2bd51