Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fpm-fips, 8.4-debian13-fpm-fips, 8.4-fpm-fips, 8.4.26-debian-fpm-fips, 8.4.26-debian13-fpm-fips, 8.4.26-fpm-fips

Index digest:

sha256:21e3a6c4da4e4c2d2d3fd81c9c84d6366cb7ede28153e0c9eb97987aa421625a

Manifest digest:

sha256:d2d5570b32cec8b658a8e25d5bca86a66f65427aa07c3905d1c15fe91c6a4278

Size

34.90 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:6b1759945aa822dff980dd6f448422eac4ce770a60692de1801762ce7b9384ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1bdb8863bc69f68384adfc11067e1dd9143ed593a00aff58ee9a53ff996a37e1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:4e214592c7fc9b2d5e24b42e129e0016b85c3e274732101fc0ddef6c45986d26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a5477e6ee12bd52a38cab9ab97834bcc78c8c3020bd4c01b2a59b29908bc048e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:0813b9f0d96f8be115740612707a1ad8f36806ba43a348fc1f0a50461681f591
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:34822e48beff4bb28b5122db6822021b5e0c3bb37d9da3318e64788ef8c47da5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:5ed2267cdf268e20e7063569d6f7db77acbde72574338e6b8376e3a50af5a75d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:4e6e5eae9580145fd4b9c1e1595cca36a85b1a37423f91570b9a9c1b92e18750
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:778acd847e22792bae99cada3906f2112832adc5e706b87cb35f798c07c56746
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:7471afcd3254600b301e4bd8aef2f0456841c7b90f15ecfc390ea5bbce8e8844
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:9611cd902c774989c6ef6f0532472a8f4b86b2a239690f756cd9bab948759260
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:9e961e7cc885da2abdd2f79bc522cef6afb23cc6df7888cbcf78a98723623880
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:991032e8afc2d7c6de28d4e045165da0853e2f09f82ddaad529cd6820a69ed5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:83020e979af32d5c724d70cded0e9b4723cf18f351a12b17b56e4de1b17b7f65
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:afd53429df72ee1ace60d6b45540a7126ff5e55bfd90236e245c836087b741b6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:22684f0a88480beee825a10b5b2d99afdeb2c494349e7a8940764162355b50db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:f13c4a136fbf9bc4d41878a00e83e66ea5c6c7bcc12cfa72e82bdbec487f4109