Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fips, 8.4-debian13-fips, 8.4-fips, 8.4.26-debian-fips, 8.4.26-debian13-fips, 8.4.26-fips

Index digest:

sha256:6b142a933c1b4a47ac362a722a8e0ac547499760e38940959757c7d0d7b7ff98

Manifest digest:

sha256:34a7e69c01060c0c91df88b3bb803152cb992eb77ab633cc2e903118c3eb7deb

Size

34.90 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:f222393fa56e63a0bc1b507b21233f555c74d9431706e6ebea0f210dcd685049
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:415bd8ecfcbaa4c948387888e1f383cc39431a2a907e7729b7e53256eb160076
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:afd78eb0151d2dc8b42114ec9c672241efb2be4230b8b07d68463fcdc4746e32
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:ee81b062125b435a63e58468ad130d39171bde967254f1a47d869b796eb31e67
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:ef49c9458e7e6bd13feb844edfb23adc482dbc86d275b94b0d8ea74af6b6d89b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:f2782387e369e24cf50eb5d9ac4186694ae1887e0c6173bcc784940bdffd1ce9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:93e9ba105b5826c9328be27c67f05b94971bb2c2cd5164b773b3c86ac8d9fe4b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:25d93f85eda4320d5b954b08f55010ccbab20c78b749353a95d05349f886bf2f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:858c55d73f2846093ffa09f9998b61b3e3f65d8db490078242f0896a407dabbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:21967312d4c3ad4ce5689fea4c40ea899a080d1494b6d4610d8632a626d3a781
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:8cab30a7fea545ec7b9998dc8428f7400416b50887682b83f6c1205397c56403
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:187ae943304677d37d1052a116ac4080fb6d940b6c55353a16c25e67110acc19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:762090a561a17fe15c64e7b7f077cdd676dd6c1a8938eb2a0a5d79e8dccc8129
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:5878ea8a07851c9f7b5226aa10c2eb01275288d8a27343cd5133078ada0a3f8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:de1ec72fbf48bce4e30c56facc83bd261d735ddd0ad5536b35bf4885f3933f56
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:4d82017930ccf922a6b81eb78ebbb9c2c33c45f8b39b072c0718927623866efb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:32cce65c0f25a141d41800b58be698c5d7169f8eacd1a61b09e162e1baa2ae07