Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fips, 8.4-debian13-fips, 8.4-fips, 8.4.26-debian-fips, 8.4.26-debian13-fips, 8.4.26-fips

Index digest:

sha256:23e4a8ada8ed1530e3a16ea9ce38fef1736bf2da544cf7911ac8f9dfbbeace4a

Manifest digest:

sha256:017a20d3a564ed24bf5b3d5748fadd4435736b8ed5012e2423b5fb59a1246e57

Size

34.90 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:b6040d67661ae77fd588acee42f20499ac96a06f477011ee767dd39e5bc62aea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:367b2e5ba7477f08de15ad844006053b04dce0f5e8abc706225e201902529322
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a3d09c9423e66b1dc21bd8e8586e15da239e2b1e8e3ee4b4e7640e916fdd3b25
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:974215bbff81535f3868c1ad9b925c0f4ccce7cb02a7d15c2ee3df4df5af7f9b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:a4ac6512dc055d3f0d923231b21b50b23eb081c201c6a28917550d7f3bbd778d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:e94324c9cd7e05016916c1c062a8f107d143ac17b6144478cfd0770a6307270c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:acb67b1961623e69cb173f9551adfdc8098ff84e5abc37f59c5491c0d15162e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:803e98a08c1c1f93652f5237c7f35dfa75955c31bc80177609f10f65fd064e49
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:0109148ec9dfc43903f508eec7e33da6d9a01a1500d399041e21e9e0e3e591e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a5d2e6b52261ea5c51e0aa4defb082829ccdddcc9ca7c20c047599c7a5d3925e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:e09195bcbd9c42ac995391ff5cea884ba3c7230ab818ac40e8150e499979d5af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:c99c0a968b47288ad82624a54bc73eef6c7a033552f820d23826863a0d32f963
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:31f5fd2a0d68606b0ed0c8ac4e64f49cd89c0b4d5dca9fd565a1ac40f3e07771
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:ae6343d4fb996fee22e53a240d06ee877b9d77880c8f795d3774b25e8ef08699
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:bf66af28531b2037d1824c4bc4ea0968958bff7267565246bae525561a6b9604
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b75f861cf343307e40454112d62af8c4b11056d4372e0467b4e8b3f34f6311b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:60670261b06fab466b303b99262f22008dc64dc9a23e4a296415b2bf950b1902