Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm, fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

8-debian-fpm-fips, 8-debian13-fpm-fips, 8-fpm-fips, 8.5-debian-fpm-fips, 8.5-debian13-fpm-fips, 8.5-fpm-fips, 8.5.11-debian-fpm-fips, 8.5.11-debian13-fpm-fips, 8.5.11-fpm-fips

Index digest:

sha256:d9f06b0f1d36e2fb1ffbaebab5f71eb682e64b6751cca4c2fb48ec9a033ea84c

Manifest digest:

sha256:1605d0f573de36ba72df478f35691e8ae8f0cd122f681545ac64ae75767fe11f

Size

34.43 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:030f3f0c3be1f1ef888feabecc5de731462e35c07419cc3e00c314440d65487c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:7efff68d8c1455fa765910bcc8388a3a69dd7828b64afdd451423dbfd9a4561a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/php@sha256:6edc53e4ab199d8921b5fb042554ce562c87cf3c1e0169f37e4e789b710e8b91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:947dd9f3a06977b2a1e422ead2faecaff66a7f1d1cca3c7a4a40cd81b3f35351
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/php@sha256:160d7a24473b052cd519faa20fbb134abe858ea3b0adf88ca05f257a10bff3dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:101458f5d08104c37362c2a752d94f796b8f3f6902c4b2ca479f2736cfa9b887
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:291997aa7d67aec1fde8390a3c1687da35bad3f44db18e244ad445fda98e4a08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:cff38a6406d06b59bd81e5650f2465e86e6c35b652ae1657d7977db7ae60fba0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:34b40c0133cf7905be718e0d6716f162acd6a3674dd18308d9d1f28de043bd5c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:da0eb6d9a24c24a4b8643dba970b2cb2772dae49ed61cc7d372c57ea691b520f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:7384d2a2b1a34199471bf0718649d9b8b7eb52870fe45955acae7dd93bb84941
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:2c9635b1f9a254e6e2644c221fd1f4a0cda664c304b3ddf55eebfa8674189944
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:037d77a37189a972c1a4517edffbcd96eeed3b9c07afda8ddb90bb1e7e52e7ef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:581ff22f1f1afa35f3a8473de2933e91ced6330e7e35628e5d9b6f5eefedb358
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:b62bf9c9b93e79eae642a7448ff1382a2ff3b937cf7d13b07e2099149a287a87
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:e3a55db343f02586d1ce857ebf367a99d417a71f25f56e4fb80ebe954bb66a6a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:77b8847c3cd9c9b13508e65e5b68e827602c2d78def5336a8ac2f0a183395216