Vulnerability Reportphp:8.5.9-cli-alpine3.24

php:cli-alpine3.24php:cli-alpinephp:alpine3.24php:alpinephp:8.5.9-cli-alpine3.24php:8.5.9-cli-alpinephp:8.5.9-alpine3.24php:8.5.9-alpinephp:8.5-cli-alpine3.24php:8.5-cli-alpinephp:8.5-alpine3.24php:8.5-alpinephp:8-cli-alpine3.24php:8-cli-alpinephp:8-alpine3.24php:8-alpine
digestsha256:0554eb53778b5316f6b9a3447c9dfa3cf2141c0c02ff816c42cdc9aa240a34aa

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. The provided vulnerability inputs list no exposed or post-exploit findings, and the image is published by Docker Official with a perfect trust score. There are no known inherited risks for downstream images, so it can be used directly as a base without additional hardening. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

0 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
No vulnerabilities found matching filters.

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.