Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm, 8-alpine3.24-fpm, 8.5-alpine-fpm, 8.5-alpine3.24-fpm, 8.5.10-alpine-fpm, 8.5.10-alpine3.24-fpm

Index digest:

sha256:37b9d18099d2c113d273c0071b7a184e13d3efb29b47c35e319dee3b714ce8a0

Manifest digest:

sha256:6b364447c2a9eda7f6b8965bef856d772695c57284961726fa7b854953d064d3

Size

31.25 MB

Last pushed

7 days ago

Vulnerabilities

0
0
1
2
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f3d79c6118c2f95d8ff5c8ac4a974e5bc527d28e41cd3d21982bb656d569e8f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:21eb79cd94d39626de41602af61c67965f1bdc322fb05fca16b95e9cb7e319ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:b0c091d4667465d56f44a8067d3a380f9fb07a7f9ae297687eeeef9ae705fe4b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:6408bc4f34d72631b2417fc13674242395c38a891dee6d027b7a7bf083c39ba7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:a1d12dcf83d594f649fb9ae667a11ad09a96e954dba6be4344488d3a88ec9d9d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:4b9cf2d66d5f2939f1fe8a72b0e52e2559bd309a050c9c117e4398e01ad8ee43
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:bde4a0b0312ed731062afe8ee48eba9f427cbbcd5b4077dd70563d0b5744ae52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:71e3b2603610a40f85bde0d3e552b961826e993d62e7c09ec8e6e1543da01278
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:d6b5f48bc5c461ed2957c3a49b34a8f7bef99ae7ce37cd3f0cd35c417c159f99
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:7aeb7675acc5674103d1de95486c12cda8651fd338be3bee9adda3480487650d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:c487c346c7ba24de9826cf3e0bce00da166d79f9691436d2ac1f62ce29f342ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:4d0bdadf61862b2e92fb1eda00846bc01eded264b6d04e55c1e9b43548328313
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:83ef3f0f0fb6a4fe418740f106413361cba8544e0e5ad84d463a7ab5234d25eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:20dddc29a4626546330f9174fa7614c848ea68aa6766a661498a2b9a1cb048f7