Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips-dev, 2.10-alpine3.23-fips-dev, 2.10.3-alpine3.23-fips-dev

Index digest:

sha256:f400580a9166d3218804b2318d6ffc815d755cf15f63e26a19ca3f4f0fdc90f3

Manifest digest:

sha256:a6cfe1f20fb20283a98052d39aaa80e1ef3c277accf7527d0ee4e0b45715d344

Size

51.49 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
6
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:c52f57056f0d1e4d40a708eea8a9d0d65acd2b417aa823338c85c5d7a7aa8ed9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:4f656468908bbd3188368b12e27d024cd7ffe05a1eb44c67b0359be793b1a55f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:aa460a4dce4028cc772c815a94b2c56d05e5ec79e1216a0eceae812c9375b607
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:4ea351cf965881e3f9410865428a929beafaef21c61ba1f20315a3f9a831d8b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:f1476f51b999961e2d15eb99d28d6075b74d93ad56cd24a0b861aa6cdc0339ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:7355c8754307ded80641932511d47cf8bcbc7271c685e3072a3cf1f8c7b2fd05
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:184a46f222d983a1663c595033fd933fc84c1fdf5dc44c5920b9ce95387685fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:7ed952c3b59cc9700b495989829773d08d6f296c9bfdf05fcc0716a3d2979fe5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:1fe7acca7ef39612321b6cb5daded0843892bc2533fc3cd3cbe11313e45fb622
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:39229d58e71d456034d553987d032c6f44fa0602eaf6e0a0d40535267fa027d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:11de2a7dd7a8920a0363adbe4b70ab2dea9d076a88dc5786bdcbbc5cdc3f9c7b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:42510060f6fce1a92023bd90f07d7a43eb399592fed180a9393ff1a4950bfcff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:fb3972148f39a66c4f8eb6b3cbaa82a299ac2c2f1f0a382b4c638e56f0dfb4af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:5a565ecb2b5edc0f064e97e2a8cb374f8c806bfff9d701c235112c87bbd4c2d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:0c30392cc6e971a49bc45fccb6bc74100f6f97f7d052932909cae3f99f144366
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:79cd6c73f8dda0179d6c193d01684a0cef12dc942366a48748796116525e7598
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:3d2a0ea96c71a27641a1642df7758dde9cd219de04cf787909eae3d3cd9207fe