Sign inSign up
Composer

dhi.io/composer

Composer LTS (php8.4, dev)

CIS
linux/amd64
debian 13
Tags:

2.2-debian-php8.4-dev, 2.2-debian13-php8.4-dev, 2.2-php8.4-dev, 2.2.30-debian-php8.4-dev, 2.2.30-debian13-php8.4-dev, 2.2.30-php8.4-dev

Index digest:

sha256:550379c7c5c97d84944af45635a1998106b45cf4fdbfcb6def621e93fa0a9f78

Manifest digest:

sha256:a9200e11474697453a2bd7e4e6e55d1ceed1992f21b33747afad4c40ca1ac25e

Size

78.57 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2.2-debian-php8.4-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2.2-debian-php8.4-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:fcb09736502718d96cf9e6240b7165241d556c678113677694d4b39fb013be22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:557b090d0132fcb8ba24bbfa68b94b2c55357d671d9050c64b3ed96bff612d6e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:de949286565f2f1b928396a5f803a815a4f2209e5b6bb1a88300aac03aa86aaf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:5ce89c26b8585eb1b39e512b398b0251a692b4142852ed9a55aa33108791fb60
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:df85f308cc7f017081eee48670eb12709e64057df98ebc49a617d48e99149d22
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:40872ed2ace9449d81e34d3ba7cdc54cb38806e793dda607a865992091b4334e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:2ffbc481a2ab9fafd9914e2cdd9f23a84e6eb45f949b3a46037e9a0141a9be4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:2f65dd45fb4be3f166b40f154eb1d6d6590958e2b738900fd53fa818e61369e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:111923c287568fe418944a396764308c31867ad8baef2a5faa3f8129e12246bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:ecb9b0b297534cda820f4a99402ca77c6878fce2a51abdc0b9d9f66676df2824
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:f76a713d8022d693cbc1f6bfb70dcae7843171f64226eba195073d21bb4217a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:06189abd528fe4ec4a6d2750b78b323c600ad639eb8f197a45a98025d2ff1faf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:1cb91249deaae0595e5b7b98fded946c9ee7ebc851a5608925a8fcc061273458
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:913253c1d2e74060eebfd6fee0e5764c17c5a48a4399d675cf77c93cbc959b49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:f2b04efa67a95761442da52bd2b8706336ee4d1f0a0160147884f8a7c7486a90