Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.4, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-php8.4-fips-dev, 2-debian13-php8.4-fips-dev, 2-php8.4-fips-dev, 2.10-debian-php8.4-fips-dev, 2.10-debian13-php8.4-fips-dev, 2.10-php8.4-fips-dev, 2.10.3-debian-php8.4-fips-dev, 2.10.3-debian13-php8.4-fips-dev, 2.10.3-php8.4-fips-dev

Index digest:

sha256:197df0e0fa945456e81fa10a2f4523e96114c469594da0c4e9693671999ba326

Manifest digest:

sha256:8c7909ae67244c4ec2ec745f8c8134067d27e98fc79cc59ab8116960de113378

Size

79.50 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-debian-php8.4-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-debian-php8.4-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:0a859b60d0701624169d2421c4441d1144bd5ae873632954df09900974aeb378
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:96ee3e68818d08eff2cb3fdf70785a74df5e780a905e5ee418f7627eeef299d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:1712673bc54876dfa450387fed4ab14471dc640fb600f2ce7cee3e2839c7eb04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:7256e5eac5a7b0cd2928134005ac884a603289fe2c5013b6c9e8b113c0555138
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:ec69eb3bb4685856f88725e6a2b3efd879626daaedf85cbd78f296f2b074d210
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:e8adb749f1d41aef83ccef6ce837cfaf4c30b7763dea7bd6d7487fe39b7262d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:c1370399eca2a7f026c11f1db07ed0006898df9c67aac50ef95ac7d15b210c65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:08019dbd807594da0813dea2c632c25add9f31f44c93933ef836458b17d9c579
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:5e6806bb98807f6c29f0c207560dda1d93ae6f53615f04151fce820ce609b71d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:da1f31f5f08ec7029987a70ef37d9e659de9a4da0cb7c55341b97a4e34b81bd8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:79a4ad37208d7a1c4b91cb43c75b49947c046c1706d8fb060f6613baa74cd3ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:6a3bfae2c2ad39387eacb5c4d9d337e1134000696f5ac6b93e1db5366e056654
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:8e15bacc3fb4e5de8b06eccc4e87240f5fd57eec6755bfaada6abbe16b2413f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:1a06a37465cccccfd8e2c22d2ca5d9ed86576684dcb99123539eb2e6108ec45e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:bdfe994bc65f25eac0cec6c09f3c688c5c0ec6fcd21c5b9536d9bbe3f4addb52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:c45ab4e2bf09bdfd7a19d0559375c5f8386a5c533fdc89ce11076cac1d6b1e16
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:382802ad64cb9c3e3c82ee32194d4210e31ed6d03753b98f7fbe57f8cf3a3038