Sign inSign up
Composer

dhi.io/composer

Composer LTS (php8.2, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-php8.2-fips-dev, 2.2-debian13-php8.2-fips-dev, 2.2-php8.2-fips-dev, 2.2.30-debian-php8.2-fips-dev, 2.2.30-debian13-php8.2-fips-dev, 2.2.30-php8.2-fips-dev

Index digest:

sha256:8851580a7da17f3e9958288ea8ab870f7f7d9b176dfd0d133adf116451f3fe1b

Manifest digest:

sha256:0c6efcd9b30bbd08bce6cf46c6107439025b70526cf01aecf6903921ce55ff94

Size

78.29 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2.2-debian-php8.2-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2.2-debian-php8.2-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:a8e7891c30d4818b153ad13737fda74ca4253856be4a598d4b5eba98b588a46e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:3e18a84b316f4ab5ee7afcd02c1b70c0908bd191c5f0e0da61ca2daa17251472
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:405a06e4836ebc2a779cf7206553b6c6aebd1a5cafe207615228322907419bbd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:4e75ce43a3d6c158d5da1be01b41bc67a23608b3fc7bca9b8a0f880b752319b8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:9a40067ca2019ecd383c1442d1b13677a840f32003219b3b6282bea234d7dc73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:7ea85b02ebd14c9bc4ea70df745901b99daab2874fc27e2b7df8596882fbcd72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:c37718454d67ff54448fa9a7226cc6d0312a0413c7a0e59736e483120138014f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:4d84b49bf7385e844ab7dd769a7a3127598efe9c4234d53b6c0028ba1943e5a7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:ad4ae745e27e7ac8fba2a8124aaae47cd956fe21b5a1f86735e2812b0b9a8b24
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:19b4e798c5ad419d148a7dce7ead8fa98a2e29879fda9fce3971d038ab1cb460
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:91b64af872142207686edea03ba041c41a09a2d2ea8541687dfac37692401b59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:510c5683ca7e8ec256b2d8119d1e3c2c2015d559a21f5b90a4a75a5626507764
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:5218fc932173d5c248a727d917cb37fd95b999fe657c18bdcd15aa38f0c05a3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:976b0fc67af1bee0a1210368f65091cb4f06dac5143c168f9e889be6e7e4aa1b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:15bfa16867f4fbc2aeb7876eb8a849d13521983d36a2187dc148982780373d19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:7b1424b2bf027da6f5e77abbc03cf8fc2102c12f80b8688d7b0d3c506ad00a0b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:3c183fbb75c7a29e08103e83ea7001621ab56add3304fee66e8cca3e1c175bb3