Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm-fips, 8-alpine3.24-fpm-fips, 8.5-alpine-fpm-fips, 8.5-alpine3.24-fpm-fips, 8.5.10-alpine-fpm-fips, 8.5.10-alpine3.24-fpm-fips

Index digest:

sha256:a1f3b57fd97851b140fcdec0dac65b40f06d0e16c052f1980a8c91c3b6c20b72

Manifest digest:

sha256:3dbdf4169af4ae496770fe08e5c1889fc5b3d37fb3e98463eb8075b13e5b2b34

Size

32.39 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:6ec65b8795e2c7fda88e088a10df486e81800a6bbc09e90dee2f2eb7d9df8eeb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:4e3bc6ab8cab15a6a1f94612e945cc48ed2bad7f42486d099b83596fb340419d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:39163ceaafac037201246cdbb0eddcac71344d23a9d7a19e939a2566f3e5aef3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2e48d8e0d0f65ab8950b9e97949266fefe87d32d5df27afcd37dabd95f7f7d57
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:e2ce910c2e429a73bb3820fe738be8a6e9ecb89eaa25543cf5fe0cabb36a8db7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:b354c19b611f6e20ebcb8fd34c881094e0c6c49003fdef85b35159d725c3536d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:b37f4a587178e454a6a7de70c97f7d25631a136ea654f29c9577ad5374c8f074
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:50e95a6ee10ce7cb82418edf9ece4b330dff24ae94c5c8c77e5abcd10013bceb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ff99ec3722b5cbb2cdc1e8e75c46891ac5775857b9afd1700f2874f3b18b744f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:18a9228ff5e271cddd5db2758cca7c3f8f30931b68c043f0100a5aaa676ef102
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:88003aad91113a85b0910c9b4e0a6c0937b92bba5a356968ed041a8faf4afeb2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:245df55ff737ec4e46d7e4b3dc86d381f72df26d1d4a35d1a6ac73fabd2e3288
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:fc9d6d656bbb15dff2558ebcaf66f672962b96be7086cfd5c190cdd39d6335d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:0d6a68778d1e7a9d5fc40f0548bd8ab31387d97a930d8470905c7e58e34b9400
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d69cb704cea68e868487bdb0f5e9a488aabdc7b44e42248f0540dfcd9f1cde16
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:dba66785fb58ddaeeb01e746fea3a62a4572ad6045d6f04d4ba9ab4f292ddf65
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:eff8f88ee43085e844900309c7ecf5a6cfd98ee75989800c05be235d4231a539