Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.5-debian-fips-dev, 8.5-debian13-fips-dev, 8.5-fips-dev, 8.5.10-debian-fips-dev, 8.5.10-debian13-fips-dev, 8.5.10-fips-dev

Index digest:

sha256:176bff6487814a1e5b230a8685f159e548b37f2cc67084bbd365d3e9f2640765

Manifest digest:

sha256:be8752a4c66001d87d5a2f9f916654265693f063fa55b8b8048edceb33075a4a

Size

175.28 MB

Last pushed

14 hours ago

Vulnerabilities

1
1
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:44f47ba4791470a259c2246191d48cf7278d7f0b5c7a872b280e0dc93aeef65d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:16ec1b12fdd5a9d693881b7aad733539d472af5edfcfaf6f60fa1cdb6ba3ba9b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:d208eec1eaa281800f023191f513248f3d54f6eddb8c72410fa1cabed674a403
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:6b286ef794a9d7255db124ff2c936367d7bba1c9b2664f84a2eb65366c60ffd7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:1f1f356dbd6c366b15b51a22837050dedc8cc068562fb99381b8f0ff5260673b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:6996fe451d8794f1f49741b2d9ca1d595fa61e86483b78544deff118bcbd83ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:7384b22bbc14d1539fd5a5e9223374b746bf697c0cf025db2d96f86031009595
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:36c8080d6cfe9c0d1ff104fb2da5dc451710e40ebd5df5935c131cbc580790f7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:969f6cd8846c7b0516bba21e33a238915446b6d1a7d2dfba4bcd20ab045d02eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:cf2ba3dfbd3b1af6d78b8ed5ed7405ef2632dda269a8f2b09f80b076710cab1b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c32acb95d0f298ebfc26a8ae723cadbe19f75f927be1c2bcad514ade5b9c9896
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:eacbb691ca4b512bc7ba164fe74e82053b9086a1acd35f0d8ee8f47e27da9fc4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:1110b725a7b9969f1e59d825628ceb6f5b32a46bf6069963dc514fdffc1ce2be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:07811b3a2cb955040783fd8ea4e21581d64cc3281ad1862e3f479a0e2072b1bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:e635fcd21f3461450f113c99232a0a3ea55ea5cb7de3fb43b2edd562dc5e5f03
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:17987846580c4c770c7b66591600b348da871ec61523ed372061ce1ce1faf0eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:d54ee54e0eafa2279bd75c4561e2d006764a0d9a97f1b71102a56e26acd6e738