Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.4, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-php8.4-fips-dev, 2-debian13-php8.4-fips-dev, 2-php8.4-fips-dev, 2.10-debian-php8.4-fips-dev, 2.10-debian13-php8.4-fips-dev, 2.10-php8.4-fips-dev, 2.10.3-debian-php8.4-fips-dev, 2.10.3-debian13-php8.4-fips-dev, 2.10.3-php8.4-fips-dev

Index digest:

sha256:53e5851df63f5a834cc7444e9b031641086d2c7fdf40febe08300bc570eb1a0a

Manifest digest:

sha256:20d607bf52ac056e4d59adf092a2af1239edad8ea06b40f7330809c45eb16b69

Size

79.49 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-debian-php8.4-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-debian-php8.4-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify
Failed to load attestations