Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.5-alpine-fips, 8.5-alpine3.24-fips, 8.5.11-alpine-fips, 8.5.11-alpine3.24-fips

Index digest:

sha256:e47f2a999cdabbb045f04830b715ee06f647e7ab1dec5f0a1e175c2032dbf17c

Manifest digest:

sha256:8148f15d0986c94813f27d334fb39c7033e472e0a9bc4441bc6ce2e47c072420

Size

27.01 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:1a04173f411f25298bc8291be3192a0b6210bc9e47652aaf956c770640192e88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:7e27c0aca4203b2565b5e994a0b548e203e9e2c798d08c8fac05ca326f443c34
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:b3610a3fbf7a902bcdb04c06d72b979f284ddd3b5fb17c1ac871e9c6455024a3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:8ebbe338a55c6c2c0acdd647ef4265dc391a875aed7929e1c95557ebc0121206
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:7167b4f6cd7c7606041ea69ba0c576dc4f56f6be8ee0e11a5e4c3f8d115f0daa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:8a4d3bf5ac75dd7b300a36f8c9e9c09677bb9d6d4964f4d33593b69b6de24367
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:a607b10bf3c6c47d97dc4c00b946a8fb903441cc7ef7d355d83c55acddee546c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:9a08a7a7de86e3d170cebf06f56bbe30e00a109948f7a49090e5f8ce5672ccea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:deb3aa325b429e47bdb5c1de9445648758d1d45464517bac6e5d880d81621af7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:c3e94115bef5dcbb01076110155083c38a3b4557771cff9ebe6c1d9a2ba192a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:bda89b417f9793e49119fc4505d82277ffbc206b8d815dce32581baa940bd389
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:421d68edf2b73c7c6eb6c73b23ad24e061081cfea1e7c17ef3a5ac3a9d237534
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:e514341838505a5d506411b235b31c10b083b7a5a788ae94bba047e25970a8d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:83f56e29977168ec1e540ee63cef9f855685e7afbbbbaa3b3e95543a468450d2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:d2cf9459952db91b356da8358e85999f66801b8e11a1fd2feac0c1449a4e3ddd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:04a90558078861c2259f7fa3b54a0889108037ce785127f4ac58b5367eb4e1f4