Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-fpm, 8-alpine3.24-fpm, 8.5-alpine-fpm, 8.5-alpine3.24-fpm, 8.5.11-alpine-fpm, 8.5.11-alpine3.24-fpm

Index digest:

sha256:9133f1a668819633c4cefa8cb4dcca8be6831609f1b01d0e897dbc50df9ab7fb

Manifest digest:

sha256:b41e1172fa7c817da1ab06733de95968baf9d8dc5e2b176cc3d5b474c708a123

Size

31.27 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-alpine-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-alpine-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:bd9709ef5b318918b810b0ff68c8ac2745edb300e8960be280ca519140827b18
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:59daf36c9b9e65333c2fbc40936e1f90df7c7ec3efe787a0f190e94f54ef55ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:1b076c23ce5b6a46a496f63b8138aab316f423ebef9f18e5d77f27e63a81d7a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:6b847a8555a93d5d39e39fc96a0409f00e54ca29deeccd4cd7bfb5108ef3cb40
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:03471400560e0e11996b15b23ab23dd761bbbd9e9fbd53e3067d4c0d55d35a32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:f2a353466d4a61d3aaab422c6310284cabce4af1059b673ec8d19a28d9ecb040
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:85bc9de97ecf0a53954f45800b530e45a2f13870387d5d7ccd6672948e8cfd5e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:6ec19cf7d44011065f8e3b4a194c3f7d38ec843f124ced1061cfc778624bf6cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:b3deb7b54d49bfe9e7c02bc3aa7e6d812550d8c16f9f3166b0ffd65b20fa046c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:0bc3923e93b245c1037784cff8553dba366397aaac31141b3c11c313d4802ab3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:fd17bab7ff9acaf19f1bd7b18246c0a3271ef5a452287ca60b1d33b0c18343b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:c6d2bcb4a1601ababe4edec1a390b2418bf228bd532db1feba40a594b9c5a663
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:3247d49c5c55e1442b6dde57d3b35bf57893146348b1628af8cec80c30991c14
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:f527ac80ef4f0b153f1b3cc10de50679f316fc43c206307c5937e3a5fcb8d244