Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.5-alpine-fips, 8.5-alpine3.24-fips, 8.5.11-alpine-fips, 8.5.11-alpine3.24-fips

Index digest:

sha256:7a53f90d4c64d1addaff122a5b4ed19e0ea1442f547b189392a2beb6efd41981

Manifest digest:

sha256:6c3298cc23c9b9ba10eb7c37de9c0f117fa8aa16a0d351f7004c2ff6ed15d12b

Size

27.01 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f6417f4527968b1a45116574ca27eab14776a0b2b2bb908f6643a680aa58ee07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:93e0e54bd9274123224c4490b05fc0d5b0a2b20fec063cce67158dde0419c240
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:7b8455d164b57cd6b8d79902d70e21392e73e2a865285595e1af5415d2d378de
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:001d1fb67a0e334a10a60db8a006d41e448088562a9ca8994cf088d022cf00d6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:cbdf547304c55d1cb2644b4329231da29cb87a57c27f8c819ee7f83a1819d301
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:405fedcf517ff9c0d669d28d00a4091a05dd5b8ce7ea7ae144fdcb53ea94d664
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:27c299a24c0a1b02603395d34469a433e91e518b1ac4a171fbf2ae3c88502d0c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:22894e4161b74abce2375a6fd32a3ce6f4d4c685623acf16f8d93387553bf196
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ee63625f3aa6d647ca4d970516fa99d3ecd6d22df88c78cb4fd8f01ab0dfd9a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:5ae97b955f9d6d99862b1874c7d5a6974e0708539b9406b3f130402f4dea386b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:1e6f733581784938d3e5fe437e44c170122ad00bb4552a5f55fe68212f4595b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e1bdcdfd3371d59b1ca853c2481d611d8f908c5bc5fba1f24103ef59685ec592
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:9b330a4e2e08e9f7bdcde401a373af27e4f3efab58d42280a2205eafdab83ad8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:2a45aac45fc31990a70c6706d53891a6698f1b1eb5e92fc9143cd7171fe794f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b7e5be3e56e8cee21945f6dcfd8328ffe855524c1f3dc043ca0131a823be0e76
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:8fefffd921e023c3de685836edae29359f3e5579e4348519b618af29812f05ef