Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.5-debian-fips, 8.5-debian13-fips, 8.5-fips, 8.5.11-debian-fips, 8.5.11-debian13-fips, 8.5.11-fips

Index digest:

sha256:fc594ca774e2264a068c8f2037a5b2703a33111608c7562b53326b5ec20b2cf6

Manifest digest:

sha256:24e86b8b23a66de37bde731c8ab1da24e46181604fc8d1b422d005651f77bb06

Size

35.16 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:7608e6e825a48afe2202000a6ffbb83376c60be07e6aaefca58a476c38db8407
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:6f5533d92fc5531f02f7b2cb27173c4c7424e3c4db20276190c9593e159170b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:4a9e68fee0394ea746311d3e6dd282e299106e3bcbff4a24900ac9035b49fd8e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:4412848d334576ae8c18e408a4b60f8f460e58b6dad8f0d435bddbae0631c0f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:23c8606072516caffbc8ac6e9ef753b62c12b7c97110d1d23327d1b9bb9f10e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:62b5ffed31601ed18cf4bba2cff13a77c73560673e038c841a6dbf07c8d95a83
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:3068a0be13795dbedd154af4ff9d3c16fc99f9f5c17f746fdf85e1a0b2cc7401
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:6e8c813fd658cfde7147f5decf43f9a6e3d30c02bdd0f982a034d9fa585164ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:0c9629f416f1d6b0e2af47092ff684f19a056a85f3e6667ed48f92808e3e920c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ffd0c423d8289e5d6cb0839c5ef3f56d9fec148eab09ad36fa5bd03ade6ba722
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c563c7ce618fa4dec2bd2d467be6bb99f8259bb216c9daf377a54a14941cd098
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:c99bbef5dbc6e776f05c58d623a7a50fbf72064a817d477f84d448cf48f3009b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:a77d7e30f39d703ecd054f3f85b8616287820d09263d2f444745f14c2baf4033
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:3d56051d6cfd519dd4a8c2104697378d4f752487afabf14277646b36ccde0edb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:4650f85b4aeea866987c0441ccc8d44f7ec4af8e9db378578b07bea7ab6dd0fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:bdcef2bc8ed838419ad08eedd75f92f02ec4c7052406160e2676556a8bc14c17
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:3d4fbdbe54909b90163550586173cab0ae5534ecef5940f2b88fa9096dfda3d4