Sign inSign up
PHP

dhi.io/php

PHP 8.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.33-debian-fips-dev, 8.2.33-debian13-fips-dev, 8.2.33-fips-dev

Index digest:

sha256:c61065bcc3e6bcd26ce1412d57c5683bbe087d8de0885611fa2b222577e51088

Manifest digest:

sha256:1651c824222619c950bc469a12882da7f1418c8d99cb15b3847dfded5c548009

Size

169.02 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
10
0

Support

Active until Dec 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:9b77755f622c283be6e7f4963890e5f659eceb65b9be70417d00ad706128f99b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:3f2bb6c8768fe52fd78d41935289a2b6a5ae86b780f1d418425e526bd8b3c01c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:14bf1f81cdaa2adc83af124c3cfd96dc84f46f4c3b1637b65a1ab73e285a0e19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:979fff9a8e53a79b6f6d8af05dabc717232b8ec5bb6dff043b8873a364b58f57
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:107ad3e1938a92c7721904e7f3824c77b62ff599e077096ee8ecfe1710499411
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:812f56f3772d26b584ba556055170e0973ed35740a6f771c6f54db6a4cfdfd79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:373000bf21c72f7bf0c124cd8dacdb574f7b34b5a484fd2ffd499b7de5cd7192
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:9cf1823e43ad85cf2299f76a70a331f9548bc6c7f139822cef5f9b9aae136ff0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:47d21ec93d485f09cb4c947bbf4488471a55f6ba92a319e5adaf540e1aff3f73
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:42b6aa23152f3e626a40905c49c5f4b1fcecc98f21f3f07ba23ce5742c931cd8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:4e06925c2671b60c492014a5adf7403c3b467579a8d601797070f198e2518891
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:50523ed96f6fd9a3a454992b45a6ecd64062861bb1e6b493d23c9766f4f9fabf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:6b01557a227953311bc5c9904b5ef62c8e3d088923f97262f154108694766b75
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:87b055a00d91a621e0cd7effffc2890a25069efa134641fcdf8304f24e453d02
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:cf113472e5a15f541327f0521f8196caeeebec3573f45e60393d1f9297ef3796
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:bacd018a1e2338f8460f6a4626c6b4cd606743cf896b13942b86094d297ab6c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:56e5e9729b8ce9e3a86ddbea5784eca1b9af9ac5efddd159e90f667cc9f9922d