Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips-dev, 2.10-alpine3.23-fips-dev, 2.10.3-alpine3.23-fips-dev

Index digest:

sha256:ab78b1ffb5085d20846603226cfc87d706f6530c7987c8de8d47e4d8da1e446e

Manifest digest:

sha256:f1eb759c4faf18e2f06f7e1e29464f4fcdee1c5e31fc1d40daff3086e9765a2f

Size

51.38 MB

Last pushed

3 days ago

Vulnerabilities

0
1
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:9c3c9bc2b2ac472488b4825cd2aa0b1b8e99afa39c9822201e2c4a962664efc5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:5109c283c18624cbdb7588525d3c20aa921422b2e2bd30ca9cf20a7358318693
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:6fb29280037bae536bf5924a891b31763a73fc3d89e6d8c90f0ab9cb6b8c99da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:3fc34393ea3493f9e5ab2d525ff5f70aff12e3ef43a7df9986bfd0b4ff127193
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:db5914e8ff8468df5ffd3f82b9d27516684b4795d962a1ab03ca9e159f317ded
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:dd474bf91397e74a6996c2cfaff69e1f546a67b9523f49df2588b0b49cf1aec2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:8c70990bcd82e098fa557878bb1ec86a383b59c28c7314f2442fb3633f93ca1c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:e5898b9a93362fccf518788c950b73ba4ecce8f06b670a4d6e01e115614a292e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:157a8d1b8d266f1244e3388c02058c707e788f17246fd67c9bf2cbca7808bc4a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:12d23f2b8903b4255711b1e6bde062c728c96e070a9921c5724e30cfc1005f39
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:9f00d47a493acfd1c3c36c290352f3b13b7346ef860cdc63e8c586d37715d27f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:b3425a8f5edf18794d46e5a49b2390326540e745edce161dcd6a463ef308dd8d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:0e3ffdc2d7b18f7dfa227570f28017ad2c82b90cecf3dda0f9d63fef4e0c23fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:9b4b7104d70f982c89a6eb6090945b6b676b427d8630a14abf775068fc0bb29e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:1b2d9820167ca4f719ca03345291e7ef17bde7b9b9edcff3bce26cd8aa7897d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:9e8fcb583378d41953d6519bbc60b44685bc5246121ac9a51068812b6bdcd765
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:963ee681d7a12b9dde88f0fc373cb9f802a00bf3a1d163ec3e39d5421f4f9f00