Sign inSign up
PHP

dhi.io/php

PHP 8.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.4-debian-fips, 8.4-debian13-fips, 8.4-fips, 8.4.25-debian-fips, 8.4.25-debian13-fips, 8.4.25-fips

Index digest:

sha256:7d32b7fc810636c89a77f66fb0476b1600ea9835e32329940e0eaee216d64a28

Manifest digest:

sha256:41e8b6c63bbf1d3a95d6626301886dbc9cd4a6d1dc6a20b601c3c2ac459896a2

Size

34.89 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:7ed7c6d3db7e22097120b6f02454b934a168e410cddb830db912034f31ab9ec8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:1f503be4620c29ca61aebb0b9f3b5d89cf4805b37251744db6b9e7f466d740a0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:a035ad524438dff07f33743b136eef45b4beccf8540b5b2c9fb03588f33f390d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:355564ab346feb7e01488c5d4999d0a82026da137c8caf3d9a737876468febd9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:de97c3696c4e87881e5272e98441708a81d3169a7f3217a00165c65bd6e87b34
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:a5137254b0ba2199830137ae31d5c226c79cb86f864a0e606769c141dd68c87f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:5e42f097ace05e1348c1319c067972f18ec5b35659cffc2bd6d651fba13ced9b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:62573b91371899dbfbb9b22c3a5b5a93e16cb39e15e5ed6c610e291955d6a241
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:d08d3e5e1c7433ce83e3aaa56c482dda0a8a56d87c9b103f7dbe2820b2b420b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:8670b87e58a259cbdf2fcfd2cbb27fdd21cc04d60ce600367e4fbe556c753a31
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:f3c041612bf0c219daf18e0e4b01752139dac7cef6c171ac891b706dcbf0c6b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:fc75f77b91ba781c282ad0aa8ddd9b1bc700d63d650cc6f170b960dd7c765997
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:4b4f3fd4c585c63791f842641c4958e1b3f97bcdcd339a5720557d5c93c9d907
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:c4b92a895c729fdfa579675303e6fee037e72d113dc1d1cd54e1a95243efde8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:8befb2a1706a4a5c04a126672cc9d802407af8622f21197e5701087ce78da828
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:a252dc7dacacdbd4a91d868f72f6de31d4523a544508964bb28e7292660451c7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:ba3c06d70ba34feb936f8882b18f01c6511d5afcb06d2c1988f2d633a0ae809f