dhi.io/php
8-debian-fpm, 8-debian13-fpm, 8-fpm, 8.5-debian-fpm, 8.5-debian13-fpm, 8.5-fpm, 8.5.10-debian-fpm, 8.5.10-debian13-fpm, 8.5.10-fpm
sha256:80ddfa8b9347a2c186f8f1bce066164ae686b54882d5be84f58d53aa48f50b5d
Manifest digest:sha256:c0f9036a14dded6a9c79f903bd488fbacb4760da23d6fc9dc5b6d48007cc1090
Size
34.38 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/php:8-debian-fpm2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/php:8-debian-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/php@sha256:3ead24073746a710aca17a5193a4a194718b198179d1199c677310c7611d09a8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/php@sha256:ad5a4f7c058fbe2a91bfe66283f4b97e51a851394ed3ef56024940d09913e3e5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/php@sha256:3606801c52e036e0c28c483f775dc3f137cc6fcff4e3b19b47c5033cf4df1b21 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/php@sha256:4fca64720406bc214fc5f94d5a02838e90ca5522489b5f34712d0a1b17d348f6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/php@sha256:e83d032a6b10a2e941d4d0fb50f953359ca2b42e327246f227d73afd28d92244 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/php@sha256:39292d8b20a10442d06a3886bd63f58d725c9bce945021b2e5237f23e6f87c07 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/php@sha256:f9ab5bdac22598f9b37aba6962625e7ec8402e2587ec662a043136a3910cf2e0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/php@sha256:fdfc6dc66b8c7bb2339ad35880e8499c5ee1af7cad99839258116d3078fc5881 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/php@sha256:f070c7a31ec0c18984f36b2649cc849608b33dee6fb7996eeeb3f745b63f6ffa |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/php@sha256:0d27200724555ef454081f9c1197c8cbcd7ccc1a1b2a7a57bb60dff1f4057b2a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/php@sha256:c8c5b1a967fe6730bfd576873201e371f4e6875223ba01e516a692859506369e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/php@sha256:b27786b0fdce55850e4960e128fa183218f89a3631705533f48442ad66894487 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/php@sha256:021110303996db334bbe6a6fd74072f6b05c3ded524ac92c87796877e65c1398 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/php@sha256:f071951a2e002be70dce5283638ba456a52e3dcf33a68a779402274b7ab992a1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/php@sha256:d71b985de9be9892b8a789e5175c07048d9916893f5a559a89cb626889a9e347 |