Sign inSign up
PHP

dhi.io/php

PHP 8.3.x (fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fpm-fips, 8.3-debian13-fpm-fips, 8.3-fpm-fips, 8.3.33-debian-fpm-fips, 8.3.33-debian13-fpm-fips, 8.3.33-fpm-fips

Index digest:

sha256:25c8a6dc9dde20d097f85059296c7b18a624ce878698d4c0dfbbd5ca17f00087

Manifest digest:

sha256:0aa8b339a683afa96f9c18e20765ed56117b1bdbf844802d030ebad8367a485f

Size

34.01 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.3-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.3-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f4b0d6036a1beb271fc8591db0b49f225d7d64ece9935dd5b7626b5793dba04d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:7e3eae338fa6e39404aade8dd34a83f1db55e53531fb01aa57117ae05e7acc6a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0fa681f9eb6296548bc4f59fa8b63de9478b3efefbae119d719ae57ac9df139e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:5a21129b2c8b90cbe591dcf16961bc8535103b24fab63232f3f1663dadaf6814
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:162fc6fdd94d6ec452ea5d49801f8ef0d9ea07da513df48c42d5917616714658
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:11f4b505b13a383d19fb9f194cf8aa62e40a3fb35a6501ebcd4feda9d2b2fff1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:eea1a76f34d1f64257d47a093c119f7825eb4cefe35cc53540209d3069de2fd5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:4004779658645cf36929b228a86fe49b37953ccf383f7302ad1f3bb790ed5d89
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9a549e9bf142fc74ad711473cbfc1b403182e1d460efb1114e760d60984dc12a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:2b81f31d7a9432dc5d59e5a1efce3ead584de936236795c37d628ed9d0d7f892
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c299926179000ae02cf3717e6f97d30cc1a2a29bed59366d9fd64acc916c8a89
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f6f5daaac81273829c78571353e923db9ac99e14244e228911b885b4f2419f40
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:7a2af09e551c1525cfa879e2b5b7c5db9f858bd8d914221b4ae753e3b96211c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e29d47a62418f3107f6e6214a5e8d83e8ccd71a60eaace500135aad6d800f553
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:022aacdf546a32e6e866445916989252d3a49f5f72017f1fdff5d4fc0eb5d881
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:af0d044a03d3323f723157f6585661fd1f1ff1c7a8a6316a7f600714428a1571
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:8c779aa21aedbbc56ea7cf5c3dd62e8cc5b5047394e9d2cab54e17b23d4e82d2