Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:45b3b6ed51fafaf8ed4735aa24a4b698d0f64236f8855414c5bb57af00c8773a

Manifest digest:

sha256:afea5c764857e65188ade338ac63f5de227a7f59e88be808792385453b761132

Size

169.04 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
2
18
1

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f412a2a6cc7a4132dcb18204c90c59ca82b70f6a3c6e59c5be7f548ba72383dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:50467376606bc5ba3a50117e006d6639b22c03cc084c9ab00c90b84dcf0225bd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:9aa03ec6dd89ebb0bdf35a08c3612d167e3a0a98dfe273ff0f3e8521459ab924
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8884c8a6d35d07ccaca005b2c0d19c42b45e737ca0a578ef3d33453060c597ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:cbc622317be6b7c1e9eed75f5d30766e5f727f4b890eae9ea55cfd74441211f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ac83be8dbdb175d1f7f873c62ca40cfae1afd544d7f68d59e76a52f0451f24c3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:d66b59eebc91fe46cd4445825b1703d1609a2e8c236ec9230a020999d61eaceb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:c4d34557ea5c00795bc86973649930bfada8bfbd5c0a2dc8803f6e166390108e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9abd74604a32df1b3fb7404a2350a17f3e7c508b9df314f725ef09368e764d82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:1de7937d3b13902ba1d7dfc2c0ec091b1fb8b9a8407af12b7cc86bd44d8bd50d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:38814148e01fc8731a221eb3fd59009d3dbe81839ad6a96e76ded3e834913c0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:66d816ff29cf8982a982a7a95a9c9f632eb24870367073d456e975551b98093f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:1a6f45451c2acb91b63b2817d38813b53990c676880fcea2149ce6705e4c70a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:36d82f430b25f53c9ae42f3ee6d31b964ec733acea21decd80e1c92dbd801843
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:da79ad008c44ffac8a9556213823ccc209ecb392b9e8d5430a2ad2c0d7727b77
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:9397b91b44ae563fb8141b53956db2a7a8638f611bdb51f4c103621b6c0e2d3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:1fe17dc7bb4680ba7a94f6fda996e5927081f262eac271faf3e45748aa315cdc