Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fpm-fips, 8-debian13-fpm-fips, 8-fpm-fips, 8.5-debian-fpm-fips, 8.5-debian13-fpm-fips, 8.5-fpm-fips, 8.5.11-debian-fpm-fips, 8.5.11-debian13-fpm-fips, 8.5.11-fpm-fips

Index digest:

sha256:034e37ef211c70d58e4048d6fbe0052cffd7efd51ed9c020ec47875808ff4558

Manifest digest:

sha256:1c3f30907cefd56bef7c93cf99f652ea45d4ed07185711afe63114a46dc537d5

Size

35.17 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:be9edda32d62929cc18d811788c46bffcf93dd480a596b1055390ad07271f504
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:16ede439dc0564a414c6272c5836a7f23cb6cd9124cf5205b8723d2ebeec16f7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0e8974c0d4c96eec3655e66a6b95839a4eb8e5938c4c00f590ad71935f354714
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1ba2afa97c6307038d94bb56a55a75684b203c396e76aea0fa332e2f5aa84013
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:96f6af8c28d857d0be8a83f02c307bdacc3ee18ef16b2da4276d092b2280b3f8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:aa9cf0409d8b7e1df30b7cb05cfc1552f794d15349585a61d0fd53248660c0d2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:811a7fe9a5d927016d5cd1bbec10e192129a892b8ec1ec2c3e5669dfd5546b8e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:6f8e823eb493bd54baf580f756df85377153ab24f1844166f0abfd1996980c02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:037a74d146ffab75dcc541e918f03d72d97e2ce087260ccb268cbbd89a12f9d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:441d031685130e39134e1419fe4df4fc4eb6153c9eec8ab91906180bf73e6b07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:8b9b93aa440b3ffb7ecf05836266aca661d358514baf62fcb1a0b849877f1db3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:8a13578d153c0643500432c9d628751df3051e40339357009f44e11003104771
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:1ea797621cd5ffa9146c65c33f5f2edf6e9533efde82ecf9a449fe8d662bc98f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:9fe4fdc1f719bc810c2e1aa6a2a61bcf80ee4e603f65fcc3d2d132e7b50cf383
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:5a4e676a9cbe1f8ee213b58ac3c827720dfe94164b2ec1a580cad812d8399630
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:41862b52b0a3fd0b84b52faf6c3aa3e74329040483e4e83b036132430ede6f8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:6e30bb7d74e234f777a295c9a09a9eff4f8056c9032649f8288a8d0dd46c7263