Sign inSign up
PHP

dhi.io/php

PHP 8.5.x (fpm)

CIS
linux/amd64
debian 13
Tags:

8-debian-fpm, 8-debian13-fpm, 8-fpm, 8.5-debian-fpm, 8.5-debian13-fpm, 8.5-fpm, 8.5.10-debian-fpm, 8.5.10-debian13-fpm, 8.5.10-fpm

Index digest:

sha256:1adfee64bf4c561f4979e3604d345521b8acd4ef606b0f81f95e863c486d3029

Manifest digest:

sha256:1447ed2da7661f9aa2da0ec2e0427ac6fa47bf645372e770ab9b71ddd04b679f

Size

34.38 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/php:8-debian-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/php:8-debian-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/php@sha256:22daf758210cc6925590f1231e5004fbd3903808593c8fef0b976b04fd40c229
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/php@sha256:7b7b7e4f7bd939131e5ac04f3aef388af65309512f85c809f0c18845efc4871f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/php@sha256:c6848f574cbee6da3223dee9cede40646fafa1f09c30bf9357c6b1cdc5031bfd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/php@sha256:edb87291a068a415ad42c384fa82825bd91e056ae2ada10124f8979eb3270457
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/php@sha256:13d1734cf34e9ecd4352fd90a2d8bffe118d64745a2e09e450def8ef9dc87321
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/php@sha256:8b1018bfc96634269477d897dfb0b667f9931da0637216a962389b09b9243620
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/php@sha256:12844f9accb0ded6b668aff13dc82a1b88416a642014876c3f73d81337c7271b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/php@sha256:1ecbd2e51cb25d0c9b554aaabc7eec81b6f7fcdbb37196f4f08ad0cfc2a4a635
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/php@sha256:2071c3663dbc8489581a75799592117008d511641ba63e9221deff3bcf315900
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/php@sha256:f5e02d9ae9299de772b1d250800d977015eeb163af99aec719230c6e8c262f34
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/php@sha256:fdbb6d3a66dbadcbb45cf35489eb88bc02ea91604a5f9be242a4845c4aecac33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/php@sha256:0051b8f5c460b542ee63bcfdbca901065af290fc49619fae444ecefdcfafecea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/php@sha256:79f89a90ca87ed20dcd4b243dda2a36b5f4f34a51957711bd5f7cd97e4c9c215
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/php@sha256:b33e38f7441d55bdc0fa784b21e1ff1577d83f13f59bb3984558e0b25c76d522
SPDX SBOMhttps://spdx.dev/Documentdhi.io/php@sha256:863d9842367402887b03a59160e6839be65d39a29cc0cc2874a4cf3de0d4f679