Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips-dev, 8-alpine3.24-fips-dev, 8.5-alpine-fips-dev, 8.5-alpine3.24-fips-dev, 8.5.10-alpine-fips-dev, 8.5.10-alpine3.24-fips-dev

Index digest:

sha256:a4b3ad29f528f930651ccae2f137f9d95adc4a857d0179c23c8f5766accd19f9

Manifest digest:

sha256:6395990658381f40071fd127f0cc8539c0ad3eb97dc344e4a231ca36e01da8dc

Size

139.34 MB

Last pushed

6 days ago

Vulnerabilities

0
0
3
2
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:e53f3e16a6c3a1436165c20c295ea4d5d5c8ebc935f1a39e36632efea449bc52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:8ff65e1c91503e64a34cce8288054d7c7f7699c3a3a4a17ae5d870f3e5696c43
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a6a1cfb29b3f3ed9fab57e0aeee4b3340512d607b1d71dea533992e3f9029f98
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:6326907896c0d75380c4691cb211648b2f051fea6ab52a8d67e86c31d567ed03
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:cfee4410251a1b75c3fa75f355fa5073f1f0b2b70322144655d72e0647e45686
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:b62cf478d27138360d850bdfa77283424f263f987dc224c435a6c38111732f99
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ad24c48e7cea91b2e7a109427dcdd11c7be967c61830528b774f2d19888b9631
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:6206618c8c26d2e0c13db2693c9ece6bf8d33a3ac42ee207fd9904826a1efed5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:e2a49bd68c76eab5c43eb33244fffd8f5ca71fa7dd42c33b2ab7f1f7a3a40984
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:b5334cb9d9d6db8bd5c9a5071fed5051f6b385431eefb41aec6805d1d11b1d1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:fe4717be572d25ed4bfddd9c983795890fd5e42d908d64b544b2d48426f015db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:94d3c7c8ed4b32215db9288c025e14f0ddfe1a3db912834f341047e7dd8305cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:99eb5bea27d3d2f6141bbf07d7766e74d82d030cc6011788ba76e198b3af9ca6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:8358ea605edbabc5b26a3a0a87c4f2ed41a5dcda76ac741dcbc89c5b48e774d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:f439839bdd4d690f423c80aaa9c0648e8cf3d92e9f81f9fd30f0a6cea9f35146
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:975622615096ca52b9ce6b12617c90d6a8c22b86eddca6e2936f0f74f493d78f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:0dd154c1cf919d6197d9b33688fe0e0b3cd3f51dee8bef59794743fe21b8f95e