Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.3, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-php8.3-fips-dev, 2.10-alpine3.23-php8.3-fips-dev, 2.10.3-alpine3.23-php8.3-fips-dev

Index digest:

sha256:2834a66c1c535f9ecafa980b019417ea10ef6f05947d4360689a70ab6c78d794

Manifest digest:

sha256:3ad034b55055763f349bb00614a42d69f5e5a2167240e4e989edeb46214f515c

Size

50.28 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-alpine3.23-php8.3-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-alpine3.23-php8.3-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:e2f2b97e1bed22ae4092ed5559cca4ad3e47e0d026225fbda7a03c12807e1e4b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:4f7fe40e7e236ae8b907e788ff72378163d1edd8485014b7a82316e4a0981308
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/composer@sha256:3a36e7f3a5e7b9d35ff4105674b882d7742f41d99b8383654797ed802b6cb1ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:592c38f2cb03f0f346f756c7a7e8838cc52fb08ae532325584aff4bbd1f3a371
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/composer@sha256:2b33bac5c3992d0d1423dbba0e3ab03144107aa22d39885c6285d10114999844
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:3aed307815f209ab3f3d274ae7da681c338973e7ffddf5dee8e0855386cd54ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:180f4599c7067b49da132b3b07281c23df38d55997fc23ae7aa82b71af9df84d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:02b125612f0ce62bae4926873eeaf437d2c0f54dde925f5aa75b8fc00f89ca8f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:9fb770252996c2f0cfc5fc1c2ee38efa60907f14aaf7cae964dd3d633841f6de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:f22c6bd187cfec691d8c5de3bdf1ac1c5229f5cef8e52c4b3da082b8e364130d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:f4d2f415b94556d5530b83216f88bfdf238d5bb70a8e667a64bceaaa7a27c3c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:925a34549614192a39b031ebde528859111b8269ad3b46d786d90ca4a3f5fa6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:f0e69e302580a1331603fe8761853f9e1518e8e28d7b07443d2dcef371e577d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:eaac8795e2989c32df1a359868e58fb6ca2396c0f2a510b76af7e64f01891ae5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:6920774ff59e61b54b224ca3f071dd2ad2962a74426e517c95dcca307224b245
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:89bd027dda32b5d1154c7824f56afd94d7b39c806b250db4733c16adc6fc203f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:a1f209b0aaf232c0cdb6c978e1b76552231de20260b4f2e55b2def1da6e0c2dd