Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fips, 8.4-debian13-fips, 8.4-fips, 8.4.25-debian-fips, 8.4.25-debian13-fips, 8.4.25-fips

Index digest:

sha256:129e6e1cb97baa4d5a4dfacb1c7e0b60b6e67bd6f3e9c1ac02cf4312db52333d

Manifest digest:

sha256:2dbdcb5426a08286ddbc5fb4646b54e5afc2fee184c05a65bfc9072ae4ce6ed9

Size

34.89 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:376127210e1384bec0447d7d0fec62ff5ff47c7c9b627183702b68dee9add97c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:6519905f4df353136a3293e6dd63b6dbb108537840602f21dc5e069fbf4dffff
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:07f35b09f0944c244fe90009d2776234c49d85e657fb92c9137e7fcad96fe01d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:a22709af589fa681a16cf1c018b11bd7775a51bd95bb87d35161a9e263b82f1c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:78e589430691e9f5a749c1ed466c1d744e315c159002185ff6932a1307065fd7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f97af94e366129c27313ec3dcd54cc8c86e529634464d6e2b2f0e9d65e3518aa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:641b9a5be69078de37f55af67a03a666fee7c698ad43f4fcf2495db2de369cc4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:68113b2f1ea58f6d3dc8825655f8b203513c8660c7dbca78371849dc89380a81
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:b4e3f8f01905a3fc61c6900d0d33a77c9f5f83d9f779ff32ffeb8d414e43fbfe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:a4f8b97b3660cb645a3355ab306844215f85419b1f054d29eeb0654c0087d4e7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:1383a0c4dd3805a52c9db09ebb2d51d83a163ea445c032c790850b53cefc3858
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f59f4b2fe9f496be0d9c69472ccf8a18c9a5554490b3599bd6988135d40b72aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:8c9ed7ea34bcb9eb59b0d71c0680b9f8f1000560c7bde740c083175520babfa8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:1c6db8f893ecb2ef9a3e1e93ed6c55239dff16ec2aa5f86dd9eee8344953998a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:bd944a278608256bc2aa776e8fa1e5fc004f9dfed5beec14618220bdd320bc0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:9fff97f86a05e167319b7a77e6be14cf56e20ccce669deb314405c621bd0b834
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:c23e87db9e22e7eb18901a368c7558e0ecdeff00df627efcdc936ecc3b2b534e