Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.5-debian-fips-dev, 8.5-debian13-fips-dev, 8.5-fips-dev, 8.5.10-debian-fips-dev, 8.5.10-debian13-fips-dev, 8.5.10-fips-dev

Index digest:

sha256:7cc37429ac86dcd0e8db986564d9e8a78c26ac11208e4599fdbb85742c4cc646

Manifest digest:

sha256:836ddd286bd46f50ec23039739f7030907d291c5cc3bc1257cfd0bb2ec7d6f02

Size

175.28 MB

Last pushed

52 minutes ago

Vulnerabilities

1
1
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:ccb4f813e7e65ce3e377a9a5fa9ae1b6498a3e0d92d7e35094b8ffef4b44c420
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:ed10cf053e1861152468e9d72706ba39b4857fb13169fd7dfeb1f363f5c3daec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:2df804b1922f84e308249f6c6c6a9940734d8c41e9ed53aa578e9fb5e7f63eab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a744a874b8a57c62f07bd9061c228eb7e1434acb266b23850ff44435a5675915
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:8f1b55e8e9809e874136ebf43e9bc29ae5d6e37f00c0a7ffe524592bcc43963d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:43ed6a54ff45c8a3e7aa8a18cfa82a08d7b6cf3aa5a909bc2a19d0b43f9e945d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:ecfae9f893a708ca4fdb0834da147ee6a97a8b921ccc375ef7706c4b52df0660
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:6453de080e8977ee9c954c08b82d3515378c46347ef2607bc6f10d8dc5ee34a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:708cc7c29991bceef757e8f4b66e80fa06b548e36512514c2324746e05d0a977
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8e159196c476de950aa261e9ea4c91b26dc009e9901a710fdfcd42a21f32e5d9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:38323fff18cf987d68e8bac4932660a37aab29d2c3561b401aba2bdc26687d64
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:029a8dba43017f0c4a98262fcec6544fbe2571bd55c17908b367b364e3f7b5fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4f781b2795ed3faade40bdcebf649ee420e948d2d214d93b3e30d1d9fe236af2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:0c1c78dc587836cada76b6a39c60e716624600749a97f2485f07273978404916
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:8487f8f8f04462afc4b9a052e40ddbe7df2ca1de857f99b4ca87930049d72352
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:9b95c410f8dc3fcb1ff663b9f3b3e7084da5aa7e4393dfca798d6f004058ad51
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:598f40ca279396628c98d8cce31a5ab2936d536393fa56c7123b0694ee93eb55