Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm-fips, 8-alpine3.24-fpm-fips, 8.5-alpine-fpm-fips, 8.5-alpine3.24-fpm-fips, 8.5.10-alpine-fpm-fips, 8.5.10-alpine3.24-fpm-fips

Index digest:

sha256:8eaec53085a3e0e4e22770ae6123f4435f07150f457e64a54a92b96edcb48c6c

Manifest digest:

sha256:344463cc03698497916ef71740eb177db8662a8cb9ce4d14a0faf84d31ce6838

Size

32.39 MB

Last pushed

7 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:41d9911f96fa8d436aefd55058dd837a4264929018bf4811bd14e8f62e367696
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:3b4d8a254a487c89e2e6d3e1d0164004784c25d3fef777e4fa6ee00a4c67a021
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:9207209fb69f7423dc28ffe2c7dd68520ae799b2c86162aa96281fba9ee127f1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e58798f54c8ede5e8c7cad0e7ec4d9e6cebcef039b19ca41742b0ef894946183
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:19bfea098ffd10d1e69e09dd31a3cd4dfdea8bdb2026adbc33d33d9dae2ed949
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:698bc1e38241e2355d881c316b065e595a14de00d513b80e7ca41cd1480ab902
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:cc3c3f397f828f6815fa49f882330143dd891a1dceb93e2e6f337e6f79981549
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9a63efeddf143d16667170e4ce295fcc68205efd22c7b3b68a3e16d81347c32e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:07dc4e4d9b28dfd88dad646acc664a15ca3ea5bdafd8134459fe9b7844c26d37
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:577c72ff43b19555b80de8036711fb47682b6a521905e896b544ee4a73e1680d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:28bf3397adbb79a260ef20347dcea3e92e51afb276818ad1fe6cf99bac814f96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:f5fc4de9e7230de4addae78bdb9b78a743e313f8b42844b42df62d85f732022b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:688e5478049ccd7d6ec1b278f85b650bb25ee62adccedb12ce359609f74d4bea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:36571e4afd714dbe9aacd4a40c83fe4c9900a72a1b64b7ea20a4f222b4b97387
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:fc20d3f874f62ae08273545009f6b04a161ae459dea408824c6cc9d9a6eccffd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:1ff19bc18dd0f5be743cacfa75d0c5e628175a23a982b3604796866125783616