Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.2, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-php8.2-fips-dev, 2.10-alpine3.23-php8.2-fips-dev, 2.10.3-alpine3.23-php8.2-fips-dev

Index digest:

sha256:121db68bf11a1af4230b235295a559cb01d2e24323a82e3955441a5aff281fe5

Manifest digest:

sha256:a2900b6ad3e407dd55a1b5e0095e5e555c892ceba4b8b14fc2237545d4237489

Size

50.08 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-alpine3.23-php8.2-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-alpine3.23-php8.2-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:5712f4186cede97bb410ac395b59ed2455aaa35ef6ef8f57a249db87c2210765
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:701c242db0d23dcb417845928ad5c1b757797c473ad686572a71fecc425b70a0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:6578e564899f990b9ea755c0c11a591a39a5cf4ed821cc38499be1ddc1c30095
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:c42b8a5eab37e1306ecd7ffaaa42ff463f80a44cfb78a2ebe84ba1e64421e63a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:3501402c23aaa6f6eddb7c0ad2c54cf0bd4306edcbe76906cabe4c21ef0b8e6d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:40a3c0cb1667d207da6e81061950cdecdf9793327c9a9607f14c4ae7adca6412
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:2c56b2419e03a40ecf24445beb351c18a7fb7b0b53def81a1e323045a8d04828
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:0ffc579db8c300492f02a86a8ba6d1c6c7a97ac02733374662b0d3daa965fe5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:7880d1e094148fd9442dde294eda3424787b8c9f9c5ba6eb6de0f8d31972a312
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:a95a25872c1ad1244ac28e27f2c5b32af6fb7b6d85bf9cb94c27c0341bad82d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:d79afc40e13dde1d44853454247925452ac886395e90f9770550356a813373c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:48522377c0127bd900e1fedb6ae2e626c5bc8e2a5e7111a047aed15029f91db1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:11734f03996d8aa196d0e82e6c8ade60e9cf1fce8107577a3847511c4b3b6ca7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:e387c93cf2948617e10aea474f6498ca2a896e354993b5d1b0a724ac8d051395
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:ecc4766efa2d506573a202d9e4324664f286ec21bba52c25d33b306d3739f0ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:2494caf4be61b0a4fe77971349274a95f3da9417f2a67ab84f1d86cba065241e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:10179937ad5ac023c93cc6d786f4dca422a6c9e24d5117ab668bd6a42668b56c