Sign inSign up
Composer

dhi.io/composer

Composer LTS (php8.2, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-php8.2-fips-dev, 2.2-debian13-php8.2-fips-dev, 2.2-php8.2-fips-dev, 2.2.30-debian-php8.2-fips-dev, 2.2.30-debian13-php8.2-fips-dev, 2.2.30-php8.2-fips-dev

Index digest:

sha256:d2b71be287919b90a326e8d7fd58c86c9c5d72f2da8360a2c5d7128a09312e09

Manifest digest:

sha256:8a8b9e9c5d24e2eb56e88ceeb770e096fc4c53e5dbaa710e9503f48f62917a8a

Size

78.31 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2.2-debian-php8.2-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2.2-debian-php8.2-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:1363c95084387f75034a112a6483562f61a007e901e1ceee5547af86abdb4e65
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:218c71af6d32d39ecbcf94fd3c144f3d3657aa7a0295c39962a5f9d80fd3374d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:ce95f1952e5a289670a2c4cf7f72a1495a3f071db4ac1032b33a1f636db074d7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:5c60e8174160f0938bf0f2f86dd96fe379bd02b64419af943327c7c4017f2b45
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:54fc9f1add9e85cb3ab89626467f503a41cd250fc3844fbc8612c055ac19ab19
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:f730b57276b61459f76954545084d1bf5565b852d88ea82a5ea0c5193b6de0b4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:ebc4c567314201a078576328e9128d43750fc2f1d2a5e8b04f06ee5a909813d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:b07b55eb8bfae3515591dca99e05928d003043c9c4406edc358137d4277d215d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:603ab79580e80a4c4139cb22c16d3be0373db6316d95b89e6386d7f5e4da7f9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:d206f980982cbf463863c43e0ec669aeb79d0de1095caf1ead752e96022e13c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:848f463879fd309986cc0dde4346c84b7c502d098d61d1434ac98cb1d5a5a347
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:a613542a2e625141d6e05974205049913042dadbfeca9e2dac2f625f4fe2642b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:66a7bbf2254198f96cdbb2ba77ab624a724977085fb41752b6ce79a4c41b5140
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:cb6916809db02f4a0d11e3946e69da65005da462ddd819135f0220dbb497c418
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:927f868b7c12a75a5fa00756cdb0d969ac56b5fb11a5c44eb89a8083d1ab5ce2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:a50c18a3b4dec117366b806d6c4558e27b22b675d3ca30cf8216d05b77b3d2fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:9a22d877860216ddfc5f90c6a7f4abbdfbe45273c99ae6777086a2c1d32750d4