Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.2, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-php8.2-fips-dev, 2.10-alpine3.23-php8.2-fips-dev, 2.10.3-alpine3.23-php8.2-fips-dev

Index digest:

sha256:756e670afbe15d202145541cf97f4d695f89377cf5645d332d24c329e86b69c6

Manifest digest:

sha256:1609ba0efa8e92a3cad5cee46c88fbfff9ea5af46e4e013757838c3f97826d5f

Size

50.08 MB

Last pushed

3 days ago

Vulnerabilities

0
1
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-alpine3.23-php8.2-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-alpine3.23-php8.2-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:f49fada86f6fc51c2faf12d0e7855efbad8524416b35b4e8ad48a3f9d04e62ee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:00f036f3c80d470f9bd5b75aad16fff7b6a8a9ef3df266dc3af332bea98af05d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:05e0e1d08daa6ca007394b522e12cc32ef6451d4c19392ff4669e44f4f19d6aa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:58b8e1cb93e0d1c1e2adeb1d8d3e1abb8c81295b49bbda747aacdfea18f1fe32
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:cba5b27f2117bc958ce3e82c7bcac5cbbf0e70149f278ed4f55f1badc5219899
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:a64d0a76b84bb47c69178b93a162d6aec78ab23c6e7ec0675888e2cf6765e576
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:0f27ce78289b0b607bd6fa640636524b17ab575becc7f949ed9b6310f5fcab02
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:37d7d9822b06d7ed636eebbc1a81c742768234895ec1e7390b72fe70e01e683f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:4ea784f0211af65036ef5c927c33cd937fa58e9ec56542588eb667411c2c7ebe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:864bf10f789ba3f86835a334253815e3ad7d624cb70c08318b294ce5945e39f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:457d0e6998049f5a9dd2169aeed82bcdbd20e584536bef4d463475b7ebc89e47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:bb81e896bbaca68838f6b8b20515abe6966c413d3a0c69004f689a8cac5aa263
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:34907bcb47c923da4d4523bc0347f9ef18d0499eb3eab2bc5ceafa12bb46504b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:0c0a99d0c3d6732ec8957fbc8f6899a68437625fd85bb2ee052f0df4e58e53a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:23aa5fe28c750487874f894924d00156a1211a2c074781e7ab144536d2ba56a3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:926b4b71695691ddf58d69fd221cb9582524bfdbd559f1c17d7414684f71f2de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:fb0765cbe1133adc2562b2d4afa0485493cfe271204a7f6b97be4541c5e13a9f