Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips-dev, 8-alpine3.24-fips-dev, 8.5-alpine-fips-dev, 8.5-alpine3.24-fips-dev, 8.5.10-alpine-fips-dev, 8.5.10-alpine3.24-fips-dev

Index digest:

sha256:739bf617a8f3d6a1d71913bbd1225cc163f9b76fdd3833774b2654b1615dbb63

Manifest digest:

sha256:32ac81a95f1e6e6589fd57427ffaa10a7be3823636f00d63cc4ea7ec540d4327

Size

139.32 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b98724b9f55c97db91b1cf918b8597e8dbcd6334231a54803d40c09b55c7d5aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:986f9fd494a06bbbd41df3b66498adc92de1d92f2e58634a1c617a551b8f01d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:77fbb7346885fe9c47c76185578a5cd65084db910638109eac9d1f715111242d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:50863b4e66799c8ef9940f676d48609c3676a94e718d2baf53e424679d7dbf9d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:0056f2a9a937e7896544983087537eb5bcfa069b727ea2311c9bb6cf1e0b7fcd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:4ed6a224915c99fd0a840579c5a02645e31878c0d539a22ea92db04290bcabbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:9b0189749f62952e4c1f0c838498645143a116d8adefc910f93225ca600eee04
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e6e7158bd9f3c84ac6f157cba3697e7345f17268b64cca16bc9ff35684bb1e08
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:c1ea280c1c5440699be32fd1665e32b200a9cea89207bab710896681208bf74b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:615de55d11c8bf46bf75c20a67e217c7955670eec9288139fbe6301b55cefc1e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:97407cafbf81d767790329e4cb9458a9e154f5e2f5981196c642ce0277690368
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:63c5dfcddc8169d2a77807e98fe2f9bb168d399282120f1b447a2a5b859ce460
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:e4cf3f8b3f7d0c3a279acf62c953cb231d084a20564d14ff00a5be1e5483e09a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f92e5aa37dfc0cc7c27530ced2a1e94429274be6db607eceabf92e54d0f5c25b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:263ecd079c39ebd5cc2994a0db101fa958c431f1e652585d70313fa91c62e7ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:57c334d4b1587187179dbc609dd6920958f52b26a6d38580a0256e6d1f86dabf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:87fe5af6439cf00d106be85b2b642c33a11152d27383599bbec9cbf1fc9c4574