dhi.io/php
8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.5-debian-fips-dev, 8.5-debian13-fips-dev, 8.5-fips-dev, 8.5.11-debian-fips-dev, 8.5.11-debian13-fips-dev, 8.5.11-fips-dev
sha256:c7039eff8b6b14ee70bb38dd2a53330e01c2e2d871e47070ea190ce2b6040e3f
Manifest digest:sha256:5f5ba740977e777e4da962062dda7aa367799c30ad4ad0deb50115084c8380bc
Size
175.30 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/php:8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/php:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/php@sha256:0cdbdcb635969691322d6410a9be1ce75b4d92891a7067853265d15960516f50 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/php@sha256:550682c4ebdf6430ebd2f72956941834394597eac0f4f9285d52afbad1dc3cbe |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/php@sha256:466f9ebebcc7bfb7bff5edb0f54e8b2da73a3cb32ef300e3c1f0902525007903 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/php@sha256:82bba82101d20759b5cb0d67ac3cd59b698dbe09b24ee44b25a4df6736d8f48d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/php@sha256:55f8594cfeb16e841cbde1f785891a702bcc43c9c6fe20c0a483362e58d98782 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/php@sha256:377fb56b831d8c2fba79fba226369bd854a534cea0692b937ea0096b7523779e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/php@sha256:22612cb6374ab57fce91d452408c218e021e51fce527680d53f549bb3ce001e8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/php@sha256:84180956861abbfe55086721067cfeccc0baef4dc9804f57a7b040c378826fda |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/php@sha256:73828ea9f4cf40968c8481dd33496bc2612ede5b17d42b5d3c9757303936bc03 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/php@sha256:ca615addc4ddad75592673c69c4aa143ae22e3a7d77128eacc4a5b746581016b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/php@sha256:f579d4475ff82a91550abba3e095acbcf5a454e04ef015c5ac9c452d37972a6f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/php@sha256:8fb742d2669e33675739bb1e3562753ef9eb9383bd5c740f019951bd14d9d300 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/php@sha256:f4c56fd84e4d9841a7bbee8377c1fcbc908e87edc7ca8498d08d6a891e4f281b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/php@sha256:b00bb663d174aa8702515ad5eeaa986bd4562b36dd19ffccb9b7aa4665276c51 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/php@sha256:20b5ec5defd84602eba3109ab0f1b44d8557b7365343442a83dd7eb9770d9c3d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/php@sha256:4bc6f40af80cdc120ef90945c72ff88f614da8f93db658160528001b4cdbd7f4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/php@sha256:08baa9671d2fce80b386ffd60e41d38cef46f7fd7bd2f6abef65e6cfa4fe304b |