Sign inSign up
Composer

dhi.io/composer

Composer 2.10 (php8.5, dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-php8.5-dev, 2-debian13-php8.5-dev, 2-php8.5-dev, 2.10-debian-php8.5-dev, 2.10-debian13-php8.5-dev, 2.10-php8.5-dev, 2.10.3-debian-php8.5-dev, 2.10.3-debian13-php8.5-dev, 2.10.3-php8.5-dev

Index digest:

sha256:d93f3e2330077d6b34fe92f64a3e6dd97de0386ec73a531be8d2f79fcab0ad8d

Manifest digest:

sha256:9b3354bf2f9a28516acb674daabbd430f01e0d4b1a2354f3de3b7382094c0d11

Size

78.98 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/composer:2-debian-php8.5-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/composer:2-debian-php8.5-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/composer@sha256:7a1ca813a04f30c8ebda7cbdf708772732c0c0c819df8ee802532dcdbcba603c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/composer@sha256:8e553774c0a0dfa690fb24ea44782e273e8b4791727dd458a87f1aa3826ab0da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/composer@sha256:6d4731516f12d7ec2c4b1eeaf504dff2f60d753b24e218fa079c5c169a0d571d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/composer@sha256:aef1bf851f65fc6e713ed97d8e73571655d8a84ed89cc69e2c09b553266c35a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/composer@sha256:2e3e789ae5ed0cef37142c6bfc297ef33340d7a1e47467d51f9b7aff67c03b4b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/composer@sha256:f4c9954280b65c846aee957676d64dcc2b0d9c5f306d6416c7ab2e02cc2c9f63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/composer@sha256:0c4e9eb8fd8f12ee1911b59c5f8eac47b2c2218543ec076b8d64dde62dc76ca7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/composer@sha256:23164a9d67fd9c9aa407f05ffba6f660e6c2aedbd961ace5f5b54bfa455faff6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/composer@sha256:1db8721c7a507a19643dc95d1b024afb575e075fd3605ef01d065f29ea03a4fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/composer@sha256:e25fc9e45c84303951720851deb1e779ba9317026aabeb66cab9a47ccb6b946e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/composer@sha256:80e62ac5f66ab46eb2d0d65e90a08c808337a2d6f6ae989262f83aff1da9c180
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/composer@sha256:42fb1e4c946acae74dc26fcfd251817672ced4f168c6db99a66eceb8d73ab9b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/composer@sha256:e12732c72f750f9eaf59a93ff2ea4e3493032cf5e2fc0dca551885cd26874082
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/composer@sha256:3881e19c13aa3d4fd3b11d2e3cd00d30b7e6fb249f8c89afe9a50f9fd935b326
SPDX SBOMhttps://spdx.dev/Documentdhi.io/composer@sha256:353c9198e49f5a42096d0ac6d335aad5d04315645963f2b4d1b5f22e6712cf8c