Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:233eff13d6b9aaf842e7d282c150ad7f529aa405dc4a0bca815eede0f4c8ed59

Manifest digest:

sha256:9e835795bc3a08e69b18203b906ecd15a261f2c5e87de19e2699058ae7b92727

Size

169.04 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:454b6f20ff0710770428846f41fc59f3ecaba4552d47dc0cb4296a023baea831
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:91509c30bcd7a78573358aaa1dc6ad266be7dd1fc6aa6d1a2e0076a082b29529
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:3320dfaa6dfc29fe7b9acf79f0b630094cf6bd46b46cd4cf963814df93ea7805
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:4aba3bf6e3026ffd84072f941c043da88a1da650ea3b4c517916217e0fe1add4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:0b45c42a6469860f6dff17c47862dd5e4a58b19d57156898e0160393c4ecf149
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:fdf3fc2eadac09758a8455acda089984d6d5da95053e812c42f367b629e11091
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:69bc72d422eaf113c79e09bba01740fa022dedf70743bfc2577fc932206a2b07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:44bbaf6993658cc7aa7502fe631043294f40e0d58dc1ff2ad9b6f15496e8b828
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:0c86d87dc6681391543d95847ddc2d4464eaa09dab344d77175fe8fc70213692
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9a57174fbd3b6bbb0818aa60285245b114fbfad4dc6f9524022e5686ea9f22b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:9edbafdc22ee263b199c3fdf5f2e021118bee3f45f2d606f9dca5845af7f1b26
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:6b18fa17468fe17e5d497eae85871fcb2ddffa02cdc6ab11e8a282258b0d951b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:a46e4cef1ecb1340d87460208f2997b0a21fbf82063bea8a8e5d3996ffff96cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:fbb9ea231fa4a6c821d22ccdc34eb6ae9bfdcee0201f464f5a515f9fb1824659
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:0b0fa56a5c070b6eaec101d5cc72c8659741bd11073f781a8c0a464c304824fe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a1ea1b78e0749b7c1180dafc47c0953e6279c14a97354282a550a8b1d6cf9ac4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:395b2d02aea7540a7234dc3ed33dd2662a9fd6e0350007dc9356eda1f1e1a0a3