Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips-dev, 8-alpine3.24-fips-dev, 8.5-alpine-fips-dev, 8.5-alpine3.24-fips-dev, 8.5.11-alpine-fips-dev, 8.5.11-alpine3.24-fips-dev

Index digest:

sha256:e5e70e9136fa78720a0896572944e80bdadebc6ad38c722196cd99802c98e94f

Manifest digest:

sha256:5cf92502634f6bf2a8e9b257fb8674b375e7f6292bbbf6da14aad6209c67d634

Size

139.41 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b7e7a99280ed304239df337c208431e1c7fe065d6ee001b1c8ee2a27893c5b8f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:e05771c074e9430673b61de722f916a509269668631c910d0154f335f62a1173
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:563eeb31e517aacc5fcac536fde27364ee56df37d3d606b1f70f2de102b12a3a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:d10c9201bb21af96fb189e218255b0f84d16e7803c1d80b943d20c3dff6ac3c3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:3e4e54782fb71d2262310b3e764f81fc18a5b42035fb3ab15023cd9b701b3826
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:5ed180fb1debfe6cdca894d5fc0e27994f83f02f980c704ad49ed78a0b9fe6d6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:f50912e44fdb293ea82e59b393fcc71bfef9ed97ae87a0c948b7feedf08340e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:adaafa1c5739d04c6c73ba83fd3425c8f8472e715ca55464f3a66c6fad269c3b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:6aa9632fc76190c193578e645e48f9d164b4a331b96d6045bb70f72f4a5e1c38
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:94b490ce64fe76a3e997eaebf8d836c46520f009dac8ad3f73818f2515cf3bd0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d7543f8e687d4ea018cd05f84336ae4cb76bd44814ec39e7f61e9ea3c156405a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:669cd412d3c821a323397159716552ca6517e831d3b05a95279f2ef3300c7ce6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:d171ad41d96f42b7159d944697efd472f200d5cdc099b33947af98c4dd95af71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:8d3cc3fd9235cd98d8273633110f976261a507ddc41673fe3e3ad1ab1ce061b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:09673b193114c66c8357bc968da72a9e9f684da42895e2037969cb536b7d57c4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b99421edcd43919ecd0b6dfcde0afb1cd8706c26fda5ab784e45aaf6c5b35519
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:910fa4ed36fb9987d0aaf7ec9c801be9858c430cd6491aad613c1f464a685421