Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.5-alpine-fips, 8.5-alpine3.24-fips, 8.5.11-alpine-fips, 8.5.11-alpine3.24-fips

Index digest:

sha256:872478a0786ae8847684fb2c87462204e94815b4277649eb7002e2c5890fcc8b

Manifest digest:

sha256:573a4d6fe2b7b35fcb822c3555bb8353371040c165a46d21b234d2bd4211fe3e

Size

27.01 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:a4847d635815c4c78aa73210f8c00318489128d0a1f89864760a2f769a244557
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:c8c0a5bf1659324e2c090237023d32f5a8800b50a52b39f015300209a3572b44
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:7fd16e0063865748b11eb06bef390fec3b424fce36c3c7614a8a16b7cd951e0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:cd21bc0ff1767d690b3e258b7e8217b187f4f30bed7f8cd3e766fff6a9de3340
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:241d57a74f01752a998421bc5332bc9f0a555a60ebbdf403574a207fc971c6d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:2ecf7343748a5117f1e2b420e77d215c79652f16a78fdfe4b4e5cd9f4888a70f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8543d9ac85d1eeaee84e257d70df837f5eabbb4530ad46b7e4294977ec5b29bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a06106dcf439bd078035349c569d1de540d6bb84cf3c39d7f812936abe3e9b56
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:97c66828f4fc8e62a40404ac7f15401681dd62ef8bb680d45623fbf438441415
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:3e2f1602c07ffca0ce5972b74ce129f8182c8bd9543c77223c47b5ad9f3ac573
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a3c313929ecb96c1a7a39d2d9f73f2566a2326399190985b9829eb72275b9a53
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:8afdf6a9c65795281b6205f701243f4bd79f2010f0a3f6a5866333da05766b5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ce0741fb04a498ee97019bb67091ae3d8aeb40a064a861463d44b6500f6e292e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:8f3938d255273b55383cf647c03eaf68dc6625d34765db7f47f5b8c7b64e524b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c0d33a9e152c3ad7c244eed18cbbec57d519fabe7b53f12489286f2df04c9335
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c1aa6ca851f36783d80c881c4229778ee718020a0d28e310d5f97ca6d244df49