Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm-fips, 8-alpine3.24-fpm-fips, 8.5-alpine-fpm-fips, 8.5-alpine3.24-fpm-fips, 8.5.11-alpine-fpm-fips, 8.5.11-alpine3.24-fpm-fips

Index digest:

sha256:2c610c39ab0d2233bbd65666931dea0d56295c9b8cce3a2855b181cb33926acf

Manifest digest:

sha256:a28964016df70cea7ad6a16d3fc7164926db39a4f9c0723cf0e6bf1ee061d0c0

Size

32.39 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f653305b3e0a86563d940aca1ff5a72602ed44d646572083f059cfe3c716e58c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:fa8b1f1c0ee9c742dcd0a9d1f0dbbfb9d2a62f68f106f03cc0ba38741f102a20
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:878e3ddd48b3c34ff632d0c1ea270057fac8842ab8f9c384192807f6bc5bee06
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b0f9665e5bb5c7ac4d03753ff5acf8405e3da6f74995e32f7a83812dc89e614e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:f7822696f2643360067bb3ac195fac90742c0ef34ec324d479aaaebe6902cc35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:71b7bdc0fb48e6ec6d63ffd315c52c6c70f4ebfa000ed69cce5e8e94e2cbaef4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:b4a8b13923a8b560bbc742359367f2bc5841a756104bea13a23bd34eade5d837
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:8c7b8e8114603aa2b0aebf5bdfe5fb5f528552740873cb671faaeabc26289161
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a7866ca8e3e9ba09af799157a2a7dd38262c2a50d954f7e1379f4bd871cf7758
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:6998b6b5565a15c25b4c8be3ef93973ee8f41b8e1a4d3221f1666d3c558cce37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:93c3372e33b76df18affcaa1505ddca6641a85b5cf56580ca24b73a9a692083d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:ea7bcc9e6b29d14b65f1385e1d583f3abb2d86c60a77a97d3106cbad30d20d79
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:d51b2221c173bd99c5cfb4878c73cc7d82aa28d69b55b6953193b293a81bd215
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:347307f7baba0affb55b5522ed94621f220f06b884d66dc3a4e71cfebf447453
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:2c89336ee62529914a02624342f5d4fc5751986f112c1d0e5c680dfd01bf0a2f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:020c847a68cb0881e193fec056770eeb96b0a90dcff5523aa89cbb7bc4b6591f