Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips-dev, 8-alpine3.24-fips-dev, 8.5-alpine-fips-dev, 8.5-alpine3.24-fips-dev, 8.5.11-alpine-fips-dev, 8.5.11-alpine3.24-fips-dev

Index digest:

sha256:24f301a450469233fb9206d85e87ce9b18da914a54f8d78588668ec78f332a54

Manifest digest:

sha256:ddc91be1eb4a0529bc5b57468a76a23f4419e885230d9a9786c116a8e15ce8f3

Size

139.41 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:15e3c9d465e892b91611b5bef6f7693ed42f12ede15296a0537037d6e1cbc02e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:071b8990399b9c003e7d14e0235da580380adbdb924dc07eb721b78f66e9c2aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:3f788d38d943f6817fee3e5ec9f2dd250d18ba538c4c0166bd2a279568d39af3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2fd8c853f1a49a0752cd8bc64ef1c54a07504a84840bce242fcdf3be04abb498
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:789762b4bf36d52cb090c3114f105d853531cd73e929f773dea882df3625d128
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:46e1aff44b3065a0c7fd2bbedeeaf838bb7e677d6b74801e9f5a2afe606ff1d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:86eb1891a0ca0fe8e9ba53676f36de8d5df743b531396e551ec955cba913c544
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:f77de0c998e53543a5b010a2653540c243589e886cebd836f58bd42fa5e50140
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:56db0fb3895629f120ad62c6ee6801a5cb92416ea9a73abcca7b4d649ffa99e0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:aa72929d469a7b6d1c11c8ef39fc57ea7dc9624d94e5fd0d1e2a873a51acf433
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:ec4bcd5a7c619447fa688404e260b2f8ca97d6f82787f4be5c8ff9d48222a6fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:1019ea7d80e3a0ed8d0a496d9be0f11f53a9a117456597eec188631541666dec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:c13f3f60d48ad02523cc3ae64dd7116e78e74ee125e83a2ad7737eb2c59ef6d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:754539d362000d941db8f8223a1d68e175f6643c3484d907642cde6b2e007734
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:7e84cfd3d61efca916cfeea5d34924f188c0fb4f2b62032e961ce4d63020124f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:bc4ddd8203164718676a6ddb21e2377fb4e155e3ae724dd3c517ec2ed43d35a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:eed4c6d9699d34f0558b44e8dbaa51db730f1d8b47e8e89a0fe1e7c24e9999b0