Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm, 8-alpine3.24-fpm, 8.5-alpine-fpm, 8.5-alpine3.24-fpm, 8.5.10-alpine-fpm, 8.5.10-alpine3.24-fpm

Index digest:

sha256:947481edd1bde16e55a21e72c55a80ec88428d9fcb4246ad243c9740bf361f96

Manifest digest:

sha256:ee059e12c9d653f4efe9b72a221fd6f0c22231d37c8ae9ee4f3d606c5af65491

Size

31.26 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:35d9fd185322586a71da7cc4b438e075f8bb28c5cf080c86ff7de5ee32d87ed1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:fd9bfad72330a92cb23592ed1678d22b54f39a1774e0cc1e5e2968c23713e2fc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:531a5cc9998bb0f44f7719631e1b90270123e3a633696959f027ab7cf0cb02f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:edd2dee717c75dca842634e0004bac2374dd344ccc687a960de4c3d20eb4b775
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:69b80f144da1e45fab634b249c2f2add60bc65746f89c08ea568d8a0d900ba02
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:bc59906a442c58686c35e60cfa3f590d7a329686afe25852efccc9d63784b02d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:5b4e00f1c9ec372444a330125cdd29e5706cc84b245e5bc864c42bb6b196659e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:d866ca742821f2123155b06cec666f8b33c3bc89cf7d76ac4c8fbba0fd5696f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:b0ee9987c8aaf3d8bd17025bd3cd1e3ccc131937493d9e52b9a5403161ce5778
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:a9916748d1165b86d911e67384a7947f0c82a6e2b8594acf3bc330acc57329da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:28a7d52269676d88d9570b9e3683eaa2f0a00b72debc14f178a8d15076965514
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:694235fa4ee6b191932e63f6f9a89d692ee24e02a7de9b71908d70fcdf468fab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:09cf7ac279787e88e9b8b6c8650bf9aad4784ba84e702e074aebc3e9ccfc12de
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:cccf0189b69556775806999858c097a2d1912d95a0a4979b9d44550ccab172de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:d9b40e5424275df4bece98ede659682184c6bbe562c66f6332359488b90d9d0b