Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fpm-fips, 8.4-debian13-fpm-fips, 8.4-fpm-fips, 8.4.26-debian-fpm-fips, 8.4.26-debian13-fpm-fips, 8.4.26-fpm-fips

Index digest:

sha256:72a8a62a17ffa3879e7e3604687068b4882e9fae473e06317c320b74070f1ad3

Manifest digest:

sha256:55532e90c3e8fb35d82e83399375f211de1dc05af8acbda7f081bc3fe2888ef0

Size

34.91 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:645f4221d8de4388baeb4f96c827ec03e4a6c497acb093768dd027f94c90f932
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:33ed285ee814868ae4aff6d7c4af87adfb38a04d788e84c961f1ed423b8c68b2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:3f5a19f3863d59d299dacb57d6b5f16dacc711485ec987116dde21f16e700e90
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:48f14c27e80b3213bbcc8142e2a652b72353e30cd74f299e29210cbc1157d4fb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:31d89956d8ab44b47d89ebe5494e619c8f3458454515f567a6f0544d5258ba40
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f562de631c6b92cce20a1bcc99a7ee38d571ea3caf66975965c84a07813984da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:f93e9d4181835f3c815a27c8b52b18e7c6ab6f6477059cf84e42baba5b5fe5a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:58bcf1bbfb73442c50f24aa289a96e56e140aac5fe7f8f425967170167675036
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:57b8b0dd93565cc8689933d0fdc73ede602aa0ef3e35c48f81a293dcfb26be39
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:9ae5118b1253ce9ed47ad1f1fc474275d0220ca4b5eb322c0caf86d0c71e0320
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:3e84f8e3d8179a2ab63dcc863484bd41e5b4a3da284cc0bc4f5a42971120a4ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:cfaa634a03a0384f563280d66250302228ff4f09b3a6b357fa685cd85a86dcd1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:0fde906323dbcb66cf7bacb73b19716a4e587673c2ebdeaf5abfe429a5ef2b93
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:06a0649041ba8f979b1127e529eee43ec636fe320f71ebed4d0fa401952c013a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:be82ee573d50fd4b7b545ad5f899e289ddc9749e49730ff89d1043145ba63f2f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a72e7dd6de8178e9da5345d97017f873310c3d437ac045c2052cd8173035b069
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:0c63771e04d67a3c1a6f08708d5f5e863f586e5c71777a57440ad86171d68b96