Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fpm-fips, 8.4-debian13-fpm-fips, 8.4-fpm-fips, 8.4.25-debian-fpm-fips, 8.4.25-debian13-fpm-fips, 8.4.25-fpm-fips

Index digest:

sha256:1ea9e423dab5b51e562ddbd9b9af6a43a08958bd7ba8bc51e1eada81355476b5

Manifest digest:

sha256:2e00e07675ef4ac61e6e0e4fcb0460ead44ea36fadbf20070be990b2563a9fb4

Size

34.90 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:805dc37d43623f5aa6de8171eed089b461ac6d7dff5cb7ca29b2fe207494f085
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:96cfe5c4b1877096262ae4ad88ad54d55f811e3272fd627072a82f7c713d43e7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:04d9b4815e9bbf010d8cb354e62095c57184b6f11f534fa3d45cdc299a321826
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8aaeae6f1022e3ea779067069a0b1477160af4bc6893d1ef449eacd7bf694171
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:49de3f96b773a3bd5845451fbb7346c330920dc9ed862424f16c13b1ed741626
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:0dc74230fdb86b23719c73c0fbf27b4e907f5e715c9db2bfe0bc02c9fd9787a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ee922a18a19ca67974c6181682ead5a3a70a517ba2efa5f06d8f302fe5bc8ebd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:efc43cfb91f2f293136cf2cef06be616ed62f774923f59127366b420adea69f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:2823ac67580b76bce8a1e6604482465d388192a51965bb4876430fe4b319eda6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:c20764cbfea4c92075e7358ce48bc07a38d4c3dee7febd1ce2163f07cab75201
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:4acb0902cbdbbe1e8a93f2a8bb021cfc825de395b9ef743c682a30c21f0829ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:cf95459eafeef13e2c577ccc00d217e72c2bfaedc139d1268af4e3e7677e7888
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:204b65640b9a83775249b2dde298df72f0d743ee13af3a8c97b51bb74a7c764a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:eb5bb2420d67411b4c0499828cbfb5a57051f1879d32e8ccf0f0074b039a59b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:88f0c8385a4d003ac3f6927191ba2c02f1247562b323cc36e8f93b7b033a705e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:c5f40fbc71ade5c4fe244da730b7219c705c18e478b8bb17d1a03b80c498f6a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:b32e2df738b1a28a6cdcc587fbe25fd5e1b8dcafcb1c09b7e9efece2a57277e0