Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips-dev, 8-alpine3.24-fips-dev, 8.5-alpine-fips-dev, 8.5-alpine3.24-fips-dev, 8.5.11-alpine-fips-dev, 8.5.11-alpine3.24-fips-dev

Index digest:

sha256:41046e09857dfaa256038ece224f1f10703e5e4d0820fa72fd573b64aa269e87

Manifest digest:

sha256:a3eca097d6f1d51ca4eb9845e4eb1d0be2f969898c5e563fd42b9775c4244a14

Size

139.41 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:bbe63a5fe2272c5714ad309ad05871fab62a456f367282e55cd8efb865d25818
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:0549697f7c957522e5dcdad77381ce399650d94b097c073cf86673f0dec8020d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:c3a56b187e865dfb6c8cc686578025d6fd8cc2b3d010d3f9e6320f141fbee550
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e2a35af5ffa92e39e4d2a1ccac0f8c5794339f4204d0f43e29bd4e000aa8e94d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:b8c6ce6f6950296052fa8687caf509d84b8c04725fb08cc93f86c41211727d35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:c32e6ba133b6a3f0ad0760e1f82507b5e830cbf27b2878f2aa06fc7e776fa836
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:1d642553a6f10ecfa3cc14a54a0d4a40e03b0f3d791b987e542b554bf205f268
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:53d81051139e742360e9d3d24af184b937131c263616c28c828d09a55c908dae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:417e9fb06f53c10b3b2fd3f20a275327488bf5f841e8b161b4d6755b24469792
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a830362691a1ae5fd1834079b0b67d242a641d10657b5cbe00713d99dbd84c7c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:3ace30e88669cb7582c4e26f2870a52a934d703dfd1b8c817e6b6428c7197532
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:6dafd27c685edcdaa5e331dd5511c1a5005ccd3b51c9c63a973971b37cd4df73
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9efc5ab803092c1dda499ad0214c106e676f92d569e436d934dddbff5bbf6e13
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:b5bcc98ec2bc50e4b8994dcc6db2c560f514193b4f3cc9f9b30133f8edc69de0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:d21d28e1cf86ba965b40282b3103b2f6577e44e1130d65a8939277ef81783956
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4da5c39db2516a56a7c112b7f397cc447d0165ba8bf55b6fa78a00fb36304f5e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:a3e5805380bfce49038ac2e9e1fc63fe678326ffbe40b95a338d04099b3d9aaf