Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.34-debian-fips-dev, 8.2.34-debian13-fips-dev, 8.2.34-fips-dev

Index digest:

sha256:09835aabb60aaafaf1a1956f19640483900f92279179ac7339a72f878a1f3ae7

Manifest digest:

sha256:c2622e01c4b37cb94c7f4d73f1c0482c8e59ef85f91177ee1e8c787c95e66aef

Size

169.02 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
9
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:830059e97fa3f08516b789527532023032b2820adeccd9a948a745c07ede5cea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:3b0a8478d2e690d3364eeed48efd5aee96e625a377f93f2a478e1fea4045fec3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:526affec1deb8493c9d3f2253a73a1f61c78c3ea06b7c078ba9fda16045d449c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b4828eff3cf2c67ee410d95fb9bd80769b869a9f6fc8e7ce14fd3c4db0cf6f4e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:6b8e533d58033d2ccf15c4a8e1351a21956c050b90a3b76fb04d4fd611eb96b8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:a66274e59149c6aa3df42af208f7016bffa4d766204b758b0aea5fbda3d178f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:6607f09d9ee35664c67f79aecd4cf15e39deebd955cc92caa689453e41c51d8d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:59d006cd11ba31af51358b56dc6c18df159fb778c1d08d6f237c2e9de167e7c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:d766901f23cf7a9c7c334aaa11adc3372586d29ce644da52d6ca198eefc5c9e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:c87fff845b8c385edd16e9e67a65e4d197f81785f4d38dcaa80bf36066728b0c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:78bef945cb4ce6b0c9027b29914487f567b34e4c69217cd8d1e04670a36f5867
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:d706f172707f04c8a012c50d4e4e285dc30502419a1ea8ce110192210c2c7a9c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:ab44edc9f60a17680a0aa93b484983e475554d0303b3fc1093522428be66d954
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:176ad848e92022c18bd3c7cf047d4feb00d121139249b28adfb4563d489ba0ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:76a002fabce1496e91394c8477d27ccaee3fbc8f5aeaa9fa700d698ad85bdc26
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:95e0beb95f31585f066005d305b671a07bd8881a402dba35790bd1089aad3b4f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:9da731e579aab9dcd2c5d82a2325e7ff9262920d63856ad826dd843fa0da946d