Security-patched legacy PHP-FPM (5.6-7.4): Debian bookworm + deb.sury.org, Jul 2026 builds.
814
Security-patched Docker images for legacy PHP FPM (5.6 – 7.4), built on Debian bookworm + deb.sury.org — unlike the official php:X.Y-fpm images, which are frozen at each version's end-of-life and no longer receive security fixes.
The official php:5.6-fpm image had its last build in January 2019; its base OS (Debian Stretch) is itself EOL. These images instead ship the PHP binaries from Sury's actively security-maintained packages (latest patch stamp: 3 July 2026) on a supported Debian bookworm base.
Official php:X.Y-fpm | panelica/php:X.Y-fpm | |
|---|---|---|
| Last PHP build | frozen at version EOL (e.g. 5.6 → Jan 2019) | 3 July 2026 (Sury security patch) |
| Base OS | Debian Stretch (EOL) | Debian bookworm (supported) |
| PHP-package HIGH/CRITICAL CVEs | unpatched | 0 / 0 (Trivy, verified 2026-07-14) |
The Trivy
0 / 0figure is for the PHP packages themselves. The remaining base-OS advisories Trivy reports are Debian bookworm's standardfix_deferred/will_not_fixset (perl, zlib, util-linux, …) — identical to anydebian:bookworm-slimbase and outside our control.
| PHP | Patched build | Pull tag (mutable) | Immutable pin |
|---|---|---|---|
| 5.6 | 5.6.40-103+0~20260703.133+debian12 | panelica/php:5.6-fpm | panelica/php:5.6-fpm-sury-2026.07 |
| 7.0 | 7.0.33-91+0~20260703.117+debian12 | panelica/php:7.0-fpm | panelica/php:7.0-fpm-sury-2026.07 |
| 7.1 | 7.1.33-79+0~20260703.126+debian12 | panelica/php:7.1-fpm | panelica/php:7.1-fpm-sury-2026.07 |
| 7.2 | 7.2.34-65+0~20260703.121+debian12 | panelica/php:7.2-fpm | panelica/php:7.2-fpm-sury-2026.07 |
| 7.3 | 7.3.33-34+0~20260703.143+debian12 | panelica/php:7.3-fpm | panelica/php:7.3-fpm-sury-2026.07 |
| 7.4 | 7.4.33-30+0~20260703.120+debian12 | panelica/php:7.4-fpm | panelica/php:7.4-fpm-sury-2026.07 |
X.Y-fpm — rolling security pointer. Always points at the newest monthly Sury security build for that branch. Use this for normal deployments; a monthly refresh moves it forward.X.Y-fpm-sury-YYYY.MM — immutable, date-pinned. Once published it is never overwritten; new content always gets a new date tag. Use this to pin a build for rollback or audit reproducibility.No component should rely on latest.
debian:bookworm-slimphp-fpm and php on PATH; PHP_INI_SCAN_DIR=/usr/local/etc/php/conf.d (present and empty for drop-in .ini mounts)mysqli, pdo_mysql, pgsql, gd, curl, zip, intl, mbstring, xml, opcache, bcmath, soap, sqlite3sodiumexif, sockets, ftp, gettext, iconv, calendar, posix, …) ship inside phpX.Y-common.docker pull panelica/php:7.4-fpm
docker run --rm panelica/php:7.4-fpm php -v
docker run --rm panelica/php:7.4-fpm php -m
Pin an exact build for reproducibility:
docker pull panelica/php:7.4-fpm-sury-2026.07
These images are produced for the Panelica hosting panel's legacy-PHP runtime, but they are self-contained and can be used independently.
Sury provides best-effort security patches for these EOL PHP branches — there is no SLA or guarantee of a fix for any given CVE. Legacy PHP (5.6 – 7.4) is end-of-life upstream. These images exist to reduce risk for workloads that cannot yet migrate; wherever possible, move to a currently supported PHP release.
Maintained by Panelica — https://panelica.com
Content type
Image
Digest
sha256:4f42fa1c0…
Size
75.6 MB
Last updated
3 months ago
docker pull panelica/php:5.6-fpm-sury-2026.07