Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.5-alpine-fips, 8.5-alpine3.24-fips, 8.5.11-alpine-fips, 8.5.11-alpine3.24-fips

Index digest:

sha256:de27264106b525f9a121c0cb4f99dc14684e36556c1af19e7f705769801d2520

Manifest digest:

sha256:55314d3959439c51a9e798801181cb364fdc58b6b62de979dad3dc049c040a1c

Size

26.99 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:e7125234b64aa4971507b3b6fc4d676a48f238b6a25245c63bd67bf50c66a4a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a4cc160e0a36b91e4e08d834711f12fdc2f156387bc6cb4581be09a7920d2197
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:4bbe24f6923e4f8d4021dd1dd0f895d69fe792ea7e627a53860266dfe01fb219
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b203e11cb25e382f3f65958e3c4175f6a69eda7e5dc6d05fd2f98de716d5df2e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:1ffbc5dc9bf9993ef2ca136cf8e24687de8a2789e3c7a757331033aa3cef39f3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f17f73e4009b6901974660b6036747314519658db5ea4d251fe4877c6a7e807a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ca745bbee7dc19450313a4a27af58086cfd7fe3ebd37c871a68de3a2abef0a9b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:49800c4f775da83cbd082924ed4a18c3225a49598d89b6df5587d1b998f5a689
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b968bde3c58f98eb9f83eb95cf3f080d3f1b624ab992cbf2a92e96b6ae47cc6b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:01b0ec3696bb49f3e850686979b7823647f361b77abb733ebfce635697e7f27a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:9a887498ced7fd0bbf5a67ca0d4212a8e3a7471a4584fde036be235efccd72a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f6729376057a1f952aaaf9bb3ffdb5206bafac0374cf66915ad18a4dcf6731e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:ecade29102bf44532e4fe49fb15db1490732888f6e399bb3d1b873671f557435
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:a011b47f55769e10dc2a90d3edcb230290a451a691ad31fc6c87a4af38701a3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:bd1fd41c03d72dd4862c29b949466ac4f183ad4eed5cb5eb8fe7055bd9be3a8d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b1660ce5f7067ebc5c5294c23739e1c7186f0e283e12e37c439e5db5240c4b01
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:25288c9c4a5f96a2d01221e02cd7a4d111edabd422a70f5974e94cf8e7e17750