Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fpm-fips, 8.4-debian13-fpm-fips, 8.4-fpm-fips, 8.4.25-debian-fpm-fips, 8.4.25-debian13-fpm-fips, 8.4.25-fpm-fips

Index digest:

sha256:bb97e15b2e78dd19610251b3d9bbc243ad62ac12f9a041b8b509e467b9f8ed74

Manifest digest:

sha256:fe82e5c40edb76af0bbd41997b7f1bf4e7784f508b649b5b4140e2640d24c14d

Size

34.90 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:ab2f8e0bb0979b0bc0b1597d08e54220a13bcab822cfae4381d538da908798b0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:0ddf16be7da03e4d40789ec9ec21d4ef56676aa3b979e23de5221f6c837fccb8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:82420dbe56bc27538eb7c755ddee37f2729acb98b1cca54d66a2c746e8192805
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:cad0cda827f9b179332cbb522ce37571e3b035b83359f3c3c644125fa7a6b744
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:42517904c7fe0d3e7af83c3849f5d1e4113f2d40986f8723f204e3a09ed1f8f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:e0efa04ba30cb24dde3147e02630766ebf5950673db559177ae36461031d84e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:e2dee6f519727f0082090dd68271ffee3605d076809d4bf4562726ae61e4374d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:16b979bc11d5643b85452d970000a15972ae842b747801c646c0a5b59699b401
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:a274cc236ad43d74e9b032486b10c33a49f10642bbe08b814737ada5f348cd1b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:f75890500d6b965102e40e4865132d38efe5b4af5993a083448297c63e3ec2b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b841870c6c0c0a3d81895de7772306e32fb0bcd8f2a2e30c560779e6dbcede28
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:11773da28708927752f9e257ec796cc84f134f321cc2c5a7dc10bdd1931a2feb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e10f44bb0a4bc8990c6014ae46123892676007dd2996975023751e8a82349c46
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:847d300fad28c3005d55b258e40979bcaf85cbaa5eaf59eead5195c4dba451e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:b9bbed572263713ac5b806efe63f25467622e4d53f145621d79ffc7571cf704e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:227e861d0a2206d9e1bdac2fb913ab2249397b6c3c007e497cee47d5ee41f9f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ffdd7f391e7d5d846cd281d53292347393c856128f267aea3f5fe22c005a87e3