Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm, 8-alpine3.24-fpm, 8.5-alpine-fpm, 8.5-alpine3.24-fpm, 8.5.11-alpine-fpm, 8.5.11-alpine3.24-fpm

Index digest:

sha256:15544c57acf22dc7315e53f9e53179f20b3d50ad63a7b4474f1549f095447dd0

Manifest digest:

sha256:14c0689e2430f0baef9f52d5f736b8dbd734ac1303e69c2fcdefc65cc1d88da8

Size

31.27 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:88c47e7e22e22da1fbda796655443bd7e7f17c4a67e59bcad97b6bfc12c9fbdd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:78558080279e315a3b8741f0fab578f908c8c22daff0b5b9d1cd146d9a3c411e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:e91b72c68ab397e0ce16d2da42c41b1437a695277eabd054a31ad9d18ac3ffc1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:cf67680703beaddc22a782ab8de3248fd8a01dcefdae5772681f94b923bddc13
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:1e122b7e4e91b17a604cbab1f9526991005be93560f13ac07bb2905f7e91b684
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:004cec30b3e605592eec54133d247ff52164ebaf60276e9f9e88444cbd9d6305
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:904de46ad2b1e785136cfe635cba3841787ca7f3c267be5dae6a55c5a63793e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:3ad2a69dc8924893a5e663967f717cbce608aecbb30448bc7164f5869de63ada
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:351406f6de5d7a919fe7511a5d8eab3b5c5a25cdfb422d98f125d9399c13c842
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:286ecb52a0b61c158b9167eb7c005f8ac796e20f076b62ed6390ef6dae1afbee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:5e7b5e03763dccb7902f904a64d47d7c3f03f999cddce1cb75da5546f870dcb6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:14a37ef8b5bbd71078a5f8698f2b09ee88be5286d05174e00399d9ca79627a39
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:903346f608763b7b5f8545159c5da00dbe140fad46b7ab945f95cf3847b35436
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:856ab8f80bac60e5fb5dbf1b07b1ac50c94460c605c44495be48ded53ea94e16
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c74deac186e0a871efb004dd2a61bbde402d8b9e463fac52525dcb161f0c0126