dhi.io/php
8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.5-debian-fips-dev, 8.5-debian13-fips-dev, 8.5-fips-dev, 8.5.11-debian-fips-dev, 8.5.11-debian13-fips-dev, 8.5.11-fips-dev
sha256:7aef7bc423e84b3e9d047eff3ee4ab82237d9798d120c61ff16999800137ccb0
Manifest digest:sha256:c73ded04200a331a742b6accbe997a45f8692c1b6555db67ad1ee3de57602bff
Size
175.31 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/php:8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/php:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/php@sha256:c975b647396c2784dd2f6bfc8b9132bfbd0504e3fdaa378ad56db6c631361269 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/php@sha256:9a65330bdb373eb81e0980bc0e5db6dec11b5269c1e358ec0bd1707daf6487d4 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/php@sha256:dcd5a2c66ec03ade0e0542b98b129d00b65884e1905f9163836739780723c024 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/php@sha256:8fd0215b7b6545e2fdc7550bd2a1f65dc6886cd6f210bcd35eaeb810b401bb58 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/php@sha256:c007ed6b00f363f411782a9d4d50f3fdc0361f467a5d137fda47b657bb424a4f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/php@sha256:e1c7805413edef63d6081316980e4497d3a586a0fddf68b4baa50259d8e4cfe8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/php@sha256:f0298fe5cac0a61944454051c0e659a064423e919a8e7dd92d8d14bc650b14cb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/php@sha256:5c54018048c70274b28ac7955afa94a4ab72398b824e0ef6e4e75baaa826a881 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/php@sha256:da313e3d86717fb4dfe0ab7f6e5de438e9c1f1950dfc805a9020ab498808611f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/php@sha256:74028f1c09a4c780e8b304e4deb21b8522f61a08b4b293347204d8260eb92ab0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/php@sha256:b12a371fbfe3c38d366bd92a312e25892a2295f2b2d34001aa6c0580e855517c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/php@sha256:77b6023838c7b531db5a59cfbbc35e1547b8d748a1fa06dd3cfd8f65a044f19f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/php@sha256:c0383e2b60f8fb0dc8f38400a240dd3f05ef5c2c90c2c1519970307fe9003175 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/php@sha256:ac317cddc07aca8349f01dd0a023b4f5e9c04bc1c713468988dde726d6284cfe |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/php@sha256:7a8bfce78f46f169d6ba3b8d7717951b55d725ff2f3e43d71c3240d1a46c358d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/php@sha256:c9f8a3fa86826a3258a8438355119f63bf8ed39100640e494cf651d60e629ba5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/php@sha256:c39614b7079c25222cdca85c6aaf2676ae43a04da025f2d9ee352c0a21c4bea8 |