Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fips, 8.4-debian13-fips, 8.4-fips, 8.4.26-debian-fips, 8.4.26-debian13-fips, 8.4.26-fips

Index digest:

sha256:37c047f640acf1c281f96886bd525317c4c4137512d5cb26b20cc3778b24164d

Manifest digest:

sha256:05b237d3f1e5ef577d542e23bb9efa4ff25c837048abd200e85d2fdf2ca7c9db

Size

34.89 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:d61e53b42b9e234b7dc619bcac54014b53126287320a365dc3764f4bd0a82446
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1b748f9b332f05626c201469e5c7ff32d4b8abdd6e8c735d8432e5846036a2e5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:0b8bc18b4b278f18aec86937125fce42e2a221bf0f4502b4863fc7015a9b7a93
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:2d881f084b709432e9b5a9179848534c0318ed9f9dd9e95a984aad8f06cfadb7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:771c59f4cb4b841d11163639443b75fefe37a7a709a1e130af1052b066862e63
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:8321a33df3671fce17b471130848edf59342ffbd31d56fa2fb0aa1e22a333a99
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:580055ce987a3ab3f303f794a0e4fc1f3159d0e3cf07ba36734d117add8cea50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:1f0c8f2c8852ed922bf0651847b1e9840b124de84a11d6deee4f0ae55102fa6a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:2d9c42fba0a686de27b451a06ca7117790ba8f3c1126aea30e5735374e8cce20
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:bb65174fc5ad6a9112f1555122ada43e54fc4701ca81ca90a91ae3c5c79f6946
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:73d22ff602ccb686acf983ce9348f638265eeae90e04a18596598404456c6cb6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:2d15e9bba00018ee69a4b16c67ed0630367fe5d6e960236b4b0f7bbd0cd993d6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:9ddb06a03b2fb7244c282902b5e848549e7734f3309e8077b31ea9bd3353f554
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:5a6f5ed9f5bfc3696e9616051209533951bd6af8fb951b75479a13f820eee643
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:7f10a322d8fd99a3805cd87025f056ea3211f08244f9f7f9244b23126985aea2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:fa76ca4a971e966718cce07b383efe311e6d4a9d0cb7e5e41d3bd7b7582d2169
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:1cbb28961b497d35d23d6ed95d90a803fdd4918d41eb91592a8f29afa717ed3c