Sign inSign up
Composer

dhi.io/composer

Composer LTS (php8.3, dev)

CIS
linux/amd64
debian 13
Tags:

2.2-debian-php8.3-dev, 2.2-debian13-php8.3-dev, 2.2-php8.3-dev, 2.2.30-debian-php8.3-dev, 2.2.30-debian13-php8.3-dev, 2.2.30-php8.3-dev

Index digest:

sha256:c0d279c9ea33a2f0c3fedf065d1fac63c66ba67b6ba9517af4a634032b08a692

Manifest digest:

sha256:c41e61c3fecc9122d4686af0949194aef7a0262ebf18c4f866d554deb9c79d59

Size

77.64 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2.2-debian-php8.3-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2.2-debian-php8.3-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:72abe087c5e31d80bca12719f78c314d64b97057f45eb6606d1ce5399843ced6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:a51811cd401e2f4aeb27994e9afff5266f197101285dfe2a042f97ef2c953bbb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:51813642acb07aa992b130c13595f21edd9e5a43c0bc1543a11683843535ff61
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:0b901445a5c5b4460f975959968da7c6dc12b5d936057c3ea62a22406b900c38
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:5decaaadc880ea22a7432bb081c24160ff5dd39af735f6e4df90e19313cd2782
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:d63f8bba2f2c525fb1bced00f0f8d086f782d6a1d976158ba3e6c016d0a1032b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:9f4835d149732a15c2b1d39e03172116298f80a6ff8f44c7e480735fb2d00413
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:ada012822fb7e72402370f02ac60299480c94371c6579130be11de05c07396f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:90ed0698c1105c678e4d98440448011f52250d0dbc18cb8ff9840a15291137ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:6e861989050129d3946ca090c842e5fc9a5dba23d82c2f0f01876460f6d0f46c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:86ef49eee8fe13e1c00a5b83ed7743b543eed749f06dd340571eecda82e3c46c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:5edae24ffd92e9a7188ee3882b0d490544c7eb51f9858d6319548890e9aab477
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:6754e80ef489103bb741a13001eb760a839f7ddb7915ed6ebeb3d615f826ae48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:308ec0f5757454565dc2d8611039503b87959bb9242fbf79af386575d2da92f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:3cc05b6735d0de87a329b88a9c21e788a9fcd0c80d6367ce60a51ca140f2bea9