Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:387635b9d95019b5a9144dc3709163f427365a6796229751d3de8d81b05200de

Manifest digest:

sha256:dcd6bf838628974e09d34d3880e7c60a8564f9bf9de8d6b988eb6b5605e02a48

Size

169.02 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b2a501a40dd75a3443d5d49f235ba2fb06cee642832fb2f3a261aab58fe7033e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1724a525d4aa6b974be89d0e1c908a78c2fa203fdca6f55bf7d09c8a746c4980
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:627916c492455737e6dc7bb6fed3b363336ffef43ef049bb8750002d38a795ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:7e133ec82c556e6d50e05ad9bbae28b4502fc108b86886f39f028d11d93bdca2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:b2c21b02d50869968e40c683989eaa8652f5b60d742d1cf32738d10daf9db147
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:ea96aed74b59fc6019155af38884c9099b66fba58e0d1ce861ff8bd2702f989f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b5b226c502e7c9e74a57535867a840d4d16aa5d7d89e14685869722b1b2704ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:a518a343bec3028fd1753c951a729d445358eee1a06d5c60c0f71e45d590ad41
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:6f1fdf55e1d5cfd0e92f19749fa8a178306535a111d28676625b265fe3b04a90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:4eec4f7b608395abb15b9ed34b9dc2695910793c5f9b884a2f33766d48cf2b7f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:4352dd9f02e812e004184f97d8d4d7c2255f7abb2aed8569e6d37a46c9dcfe18
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f452370b25b5e0e4035018d605dd8fb7f3aeeaeb912420d6d1078b9200d931ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:87d00eb5ec0010401ab6d6ca5c57829f97ff576bdf33f8e4099b341b21c1530c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:4c3d05113432f0a7ed040b14a949f4a7033c311d3e642392aa8a5a60214c5df9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:7457c67602c7b6b8a35abb556c4f56cc33dd1acdd98afb805a2b59b4905ff95c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:ee60c00dc1caccaf42481c0620cd0196fe870e64d5960921532ffc3f5e87785b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:aa3006c2958b2b77357a8271344b60778ecffb6bc3208a356ef90b99fddf8b8b