Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.2, dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-php8.2-dev, 2-debian13-php8.2-dev, 2-php8.2-dev, 2.10-debian-php8.2-dev, 2.10-debian13-php8.2-dev, 2.10-php8.2-dev, 2.10.3-debian-php8.2-dev, 2.10.3-debian13-php8.2-dev, 2.10.3-php8.2-dev

Index digest:

sha256:d206f5ab1e0f51c1e6c4b5bbea6b03d3b9cd6dae2d49c9caa3de043bbf5f4025

Manifest digest:

sha256:c732d7caea751b8dc738df27f4ab05c8d9951cb5f162fb46dff71042fd8f1db8

Size

77.73 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-debian-php8.2-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-debian-php8.2-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:0a2422c5bf45c58e7a8d12c27a65be8a055d5e90fbb956f33881b046ea254614
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:bd546455040ba7bcb73ad0659979262391d8f1f516f0bad4a9bc3714b24c83a3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:0c406d8257e8e044013b4ca8a9d2fff781aedc2919b87bc1866f7b5e9ca4fff9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:d26d712280d5cf0a89f7cf6a5c6d0367ff1d318fe7a1d0df4155dd249a193446
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:4822fa1a6b403189fed514967d7166630e39962ee162fde653a1d68a6f3c3a97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:63b4f0a93a83ac72bbe156cbcf4769ded3cbf567f113a54324fa1fdfff0f90a9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:8b32df112cdf82c915073c5ea89ff2caf85f33221873457c2d768ae32c6ed3c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:b7edcee89f7bc9907b6d25e54fb33d9bc46c1e4232bc08b5137e5f58a5a27ed8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:806694990331b180f910ca5de65ac8116cf6b5aba19978efc45030620b2a675f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:a5b92983f88249550e14c7e5a82cf040301634d60a6594f328c9bc9d16e1ef0b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:3431d9cc2cee6e9325d1869a34eb218762342e18809946ace8c69d807929cf2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:aa9c658c6cad7db4937eb46eec1dd5f956b2e5124be875c582f93a9bf53f2d76
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:2b41f4a23e1caf8384a781baf0fb41a29daedd64c18c488e6e9a3cd02d703991
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:1695bb637cd9f627074623dde0ce5cac5ae2b5f8b9b21643969cd5722e1cc05d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:c03ca88c3b7a7df623ec8f47df9806741e289559a3f7127d0864697fa7ca67b9