Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm-fips, 8-alpine3.24-fpm-fips, 8.5-alpine-fpm-fips, 8.5-alpine3.24-fpm-fips, 8.5.11-alpine-fpm-fips, 8.5.11-alpine3.24-fpm-fips

Index digest:

sha256:50d563dfd631051f206c3b04297a9e8ce1bcaa38682d8c40968135b16ba3dc38

Manifest digest:

sha256:3a2d33ca5ad493aa26ffe75ea9242bdb6fcae47bb2e29dad2f75c41995d84442

Size

32.39 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:a7911caeeeb406576a8d1b57eb1e065a96209450751688b7a5ecd97111ae294d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:74534efdee639be7903be091fb40690e25312e9e6aa2acadc37ee56f2e498c9b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:d2451069dd8edafa68ebf2bf7b4e386e3661796d8c3d1497de34b9fb9d3b126e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:9a0b0b866aded5eea471a6d60dc6c4b38022fc42ab9982ab573d7f68c3ef1e16
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:523e190b0fac7584cfe8568826ebfc364c64655f9ab68b444662c82deb48405f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:1ff7f316d915b0e2d3f7374b011b1d664c11aa5cb0ac14fdeb1e43bc315385d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:ee4ac1821f4734466cbfd66a5129767e488aca1b24abd9164299e472851dc163
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a572a4fdf06289a9be6d4742f6f00ad274db6eeb573d181d523d6ff6d3cd4551
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:4f4ece9da1a8fc7e199d47d3c63d8375798078fcba40dd296740277298767a1f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:d1d8f8adc01c5033c3428979e6b211aeae71a4e380ecc674f29446348065a300
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:396e8547d3af0a16acf82a4f551e4c4f4eedcb00a66833fb692c1a2e20f7dc7f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:315f6e1981d670f9b70be9d076c29dbacc97fe725663a507efa4dd4b592bffb0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:761e29a9cfde81b23332f99d0d55070cf3c49ed6c8fc846f2b58eb0ac7b2fd34
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:9b130fa776be7a1cffc60f9ae94d8d887011c8da9637275c1c85ed73969ce305
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:62dc0d6300288c9e9f468e3e34445177cfbe120aecd00f8738ab4ec04a10bf03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:04641ce152ac1735156c437a8ad0efbf29ff154991f770fa328a797cda5f9465