Sign inSign up
Composer

dhi.io/composer

Composer LTS (php8.2, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-php8.2-fips-dev, 2.2-debian13-php8.2-fips-dev, 2.2-php8.2-fips-dev, 2.2.30-debian-php8.2-fips-dev, 2.2.30-debian13-php8.2-fips-dev, 2.2.30-php8.2-fips-dev

Index digest:

sha256:0ddb5e5959b80e2a947af215608fc95693b5f69b34eab06c681533b7cb96f1a2

Manifest digest:

sha256:c3023d776c0ee39fc07094586bcdba909584274cc6a473d5ccf8c37e6361d46c

Size

78.33 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2.2-debian-php8.2-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2.2-debian-php8.2-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:f659be53d1098b81a9ccaaccc2b5ef90810cccae600fa9dbc6e74e6cb5979a5e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:0dc8e433a9353cd7a618541f68b07950cf21b4215a79eec7dfb7f796744c1ffa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:4edca6a580bcdca086bccb7afff2dacdc756819d8d4ec414e78d0d1fea96dd17
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:bdf907cf362a440359d1c66014d628f61c6626ce1f11fb9f6f89e4e19954eeab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:5d468111d8bab43d22ffd1ae04b87032d37c312c0f0d3663ccf8578f4efbda9f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:a54523a69d13f965213968ed7c476cda1dcedec2083f530a66aec0731413b94a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:5f0f7cb84fe3ac8ab09523f9fc3eaeba1aaae8554337cc2d6e73cecb6fae788a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:20e1f9928d40dd43dad092afb1fe4253e4a9171dd655711ba9cc11b27d5b1dd8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:b1c103179b08d0ecfb7beba1363a7806922b79a56dea6636a325a3047a2bbc0a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:170e83d1dafcd4fbbc93a31385c2b8d6114a50dceaa5ed65fbfaa655d8084112
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:3c1cc467c092f89d1ad3d1460a389dc3b9c56e537463c2ab678107e64a00a24f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:0b4d15f6aed44a8be20a26533459c853bec6686ea17f49018b73b939b979dcfc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:05dd87b7f47c0d44c4d22b96d549e38605130f80784d30ea9a62af577b3e8db2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:d01829a0f057ffcd0e90ae967b1eb11f4ede8405884eb91fad521054e24d9291
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:39fa08b82870e5fd0a7d14b6abd2e818d3813da3daedb875b9c53deedeaaf91e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:a933cca2413dd263aee7d0eb887e6a32e68a268e3fcf4ecc048cd88182671c95
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:6758cef25db31c9b5c21bfa4cd375736be9a7d961ad01abe4303e7d5c8704968