Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.5-alpine-fips, 8.5-alpine3.24-fips, 8.5.10-alpine-fips, 8.5.10-alpine3.24-fips

Index digest:

sha256:ad6cd0c3f5876f117461bf90b072575b407c23e64802400923fc656b77275bb5

Manifest digest:

sha256:7bd2a36f9a1feb8bdaae5bda14662cb6ce82f7121f4243e25234ef8da561558a

Size

26.99 MB

Last pushed

9 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:819ce27bc4443d12a46834b4989b433163b8b110beab44ca811beac42a65ab4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:810e85f0a8906d092a7d93b8203492f3e9fed43ca4f5e2f671d541da881aeb17
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:9b880e4ad9c9dc46c3316af0e8b710c7a9dc43938d9667acf0bc7d815aaee14b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:f1c985b9ecc7173bda11ea3be04bc217fd15e6d4330ba3487bc9f1f76e5f9b2e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:362e2f1edc9f359c4ee355f756167f7f2953f31edde587aba36ee2e510bb3dc9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:d1e24f80de26ce0f8e2867defc98daf7454a6ea1ad0e782551052c20f50bb335
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:1daf9d52d68d58be72ffb36a3c361ff4965a5726cc6712f4786b4e6b6950d1a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:ad768ad84305dddd0462a69c1f2de5a44c813cc4ad8413aa98d73da958ae11f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:52dfc4f88071df5af698e8f9038563c0a2072731eb0e10552baf0f38ef5dd893
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:663784656235dd806d258fd77509e1b148e3842b5132c79cd764f319e8d30c77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:ad157016e5238475971cd5d49b454a1d9347b047b3fcf845fe7422732c7a7d38
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:89efe96090cd031e76738adbfa6614f26970592dcaf25b0f24bfb18b0639b886
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:504ab28ecfb2751d58722fec3eca560d14d19eb4f12a2ebb346192a88d220fc6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:1ba57e78a09c9efa0e3be6a853844ea838321eb81e015a2b5262ae381eed3a9d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:754a3a05c59bafe72b2ec468e50796a579b4955351c1967e2e85f69dd06542a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:7a746320ce5dbd70bf71f032dd7ba9d734a5284e212809bd46de04120b643a8d