Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips-dev, 8-alpine3.24-fips-dev, 8.5-alpine-fips-dev, 8.5-alpine3.24-fips-dev, 8.5.11-alpine-fips-dev, 8.5.11-alpine3.24-fips-dev

Index digest:

sha256:32f001ae23ef97fddba35e0da77573aee5d6a8a802b41c3daa553ea03531baee

Manifest digest:

sha256:b397923af80ebb9d02d1df3b4335db9828d341ca24bc2666ad149fd7e3bc2737

Size

139.41 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:23379c7ec7d2bfa19c0f5c08e66e86e303714d2a15066efe67c1ef065a83d7ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:943603550e7ddb2bfa885724d2138a37562920072369dbbf76b2f25d6d8bc509
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a8cee88eb89ad8f283a08a96d79e6b929f76466e2d17d8ae33a5919964e65c01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:09baaab37f09a39d5b5e41500f63b074514087ef2597ad225e7ca5c02e0319fb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:b44e038c9a6a808b3b94d20c879dcc91a9be788a4827f7444cfd380d00823e89
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:472703f5b5e52ba5fda5e1b29159424599004dcefe62dc47931fe67012a623e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:006541b5e050246dadb5e9b5682fa1ced62dd96282fb3c81cafc7e0069fd1ded
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:e6d04f1bd7864f9a0596b1c749ab0e76823e2f300bc63661d0aa052cb953bade
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:804bb502a50a9c5de6500f91b48d4cd1b795332397f8d9f2651da0544e22d402
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:ed292c792a53ce79b5cce6bdf38b2aa79846073d7c6bf1292bed395b28d17c92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c9c6edfacb7cc86bcf4756a4b3d9a6e9cb71b484c7e4295e7912f3d6f9f25da0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:13cba4430aa8f7e17c9ea331a133e2c60d926fe35c6fdaeb41babfa56b185a58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:267f75287edb333083262a1b98d24f143f601ab8403f943e85d3d5da1d8e07da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:f8ce4dfe2e789386b79f211c475db95804d2bda4b455388a9427f3b297f1bfcd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:0baf2bc999193926d323ad2e88d949bbc308517097541afae47c64526babc313
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:256a80aee4e43eeab68cc73c29b81daeae3f426550ff82ebca6f855db8cc6995
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:b47d35fc62f8f21b6b23d8d33caf4169f1fd101111551c9fefb6a938864b17d7