Sign inSign up
Composer

dhi.io/composer

Composer LTS (php8.4, dev)

CIS
linux/amd64
debian 13
Tags:

2.2-debian-php8.4-dev, 2.2-debian13-php8.4-dev, 2.2-php8.4-dev, 2.2.30-debian-php8.4-dev, 2.2.30-debian13-php8.4-dev, 2.2.30-php8.4-dev

Index digest:

sha256:f63d169213f8568deb3306673b465876a46c60f01601d0b5da3cf73f4abbc100

Manifest digest:

sha256:fa6bd74a930e3342d67961802f0f223ea82a058ec50fe6e66565aaf08d990d94

Size

78.56 MB

Last pushed

17 hours ago

Vulnerabilities

0
2
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2.2-debian-php8.4-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2.2-debian-php8.4-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:3dd4bdae0a92cfc535fe440b5340ca9c52d59773cd9ec251e4541da0ef6ca4af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:1e60a39fb7a3c3142b6a65be1285ebaa0555a7794e28f40bd33c7316434d995e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:2e47791583d4c5bdadcb43cf8141c3be2ee92cc66b0cbe1007ad63c3cb1befc0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:119674c36c83b81ad6d94bc98a7b5a28f5ea012b582431781a7dc924d2ba07fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:11d7e776bee722f3efe92e8d7b0861cf8e7739c9fc0da87050eeb444e35bf4b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:e3694a4d0eabd63d57c61906cf77b9460c40c5e86f236df517037f6380874c9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:e665f8ae4edceb5433fb3e891db1bb60e367a72cd24195dce2819ae8e3ffd02e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:a510660de5b6764b6cda5bbb0bc8a1ea9c1dd035192ec09b7ebbacaa31d91043
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:764355f5f02fd72f6cfaa2ad0548e596b944618e37d1d7882fd0b528ab999485
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:d63f2f43f35b12b65119afa06b5664e4d687db545e8b4ab764eae0967d2e4e22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:edba9ecf757f259d706733a511efe0537b858afba4a50dcc4da70e121ffcd5ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:d9f4fbd6bd18d3a9afc982f64f34b8ba3a9f72e9977d133e5d946d8e17794237
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:d16fe689405f85386352a6a738682f86ffcc1d744bfc94ad1e0dcc65110610ba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:c9d35a62e64b4bfc374929f04ec346fa766ee422000ac769d51fa044b0f810d5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:697c78c158804303b874d5cba8696a31495da0ad4c3caa1ecbd279f880722a05