Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fpm-fips, 8.4-debian13-fpm-fips, 8.4-fpm-fips, 8.4.26-debian-fpm-fips, 8.4.26-debian13-fpm-fips, 8.4.26-fpm-fips

Index digest:

sha256:966cfa1957faa09b961245aa99b7ca27d44080e2d2163361e138637309fe0587

Manifest digest:

sha256:0f6a4c9ef973b2275fcc3d91db5eceae353fc426ae045e012fc9d280c17e1caf

Size

34.91 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:95342ad3baf0d39d4c852189363e87c3f5a4b2ba98baa1df424119f4ce181ab4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:a299e5895cfdb3873c09ad5f449808fde66426a6201670e332e0c82d4ae5f0ba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:3c437cc23e57ef860cedf8ab9f8fa7b266535eb016e3ea6bc563ee76eb824483
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:6e574146098e347326f8dcdf1d842a20d04c70fc4e1720e7b10f37e1354251b6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:09cfca9a3788a377afb1bbec63baf792a8c47f979551e7aedb6e793a8ff38d51
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:40830cb5679ce3258a49cabb1eaa8488ed66b2a24598fcfc63347618c6e54421
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:c44042ee7a4484d3a77ee8e07adbefdfdd976f61f3889a136656302a6ca31ac7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8f4686d52ce2a5863d9512212f51221c59b7cbf841057dc33eabd82627cf379a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ee44c96bc5204e861b253400540fd229e6298e17e694687015f6e9def30df8df
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:04b94121be8a0cff0cfeaf30e0a9d2eed75aec3371b092da435ee57d6314fe66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c4214db6f0c0b102637dfa35ea76defbcb7e20cca6db548d374c6792a9017345
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:bfd34321887e756fab4774f23262989b5a7bcb529395dc3441b0a9c42785158a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:3d703151d1ea33edb36f67ce99837c061c0aacfcdef0f8b00894d5c2190e3069
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:19fc2cb42f9ba3700a36f1fea0223f2264aa815a72e98643c76b76dbb27aaa11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:e4209bdfe25ee9e01c2f839a71c18fcacbdb9101f85d7b07acaeaacb2de85140
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4f9c5d28ce60fad5f75452cb4c44f31c07fe73a48893233541084fe9f33f4b19
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ce2b1365a369653a35525bb2ad63275d3c8d8529abdc3a83155fef541bbcf18f