Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

6.9.9-alpine-php8.3-fpm-dev, 6.9.9-alpine3.22-php8.3-fpm-dev

Index digest:

sha256:faea9af1a656b93a4262fd4abe731fa413ef90e4a44d3e8708a21289cd9057c1

Manifest digest:

sha256:02e6bd06e3253f0f5969665d50f6cfb9e4b7376c2c42bc4ec20e7f4c40ef35d4

Size

72.66 MB

Last pushed

13 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-alpine-php8.3-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-alpine-php8.3-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:ab2b2c015d1f87f592f936931caf42f75e8ed1dd28c5fb548f10fe157cd2e8b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:386687767c0429cbbe67913f270069a2fd0ac741fba9393a73bd2154c42ccf7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:52cc0e83429bc8377e81824f5b05adb3ffeb51124c20a0bedb9c7271e5cad628
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:1699e910d68deae8587ee7beb805ae45f43968f7b401e7acd004c8d8e2da1dde
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:8091ac78ff3ed8b7f34adc5c4f5a556d926d373f4d1a57b13cf42e53275831b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:5afb24d6f7ae90720007c838242919aa1fe5bafd07fd4f656b73b2d4f797da24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:a20a753f1f84df1cd112e813e5c40ceb8eac3897c43164af5c61d198657bcd9f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:af1bcb3ccfb6928a3341ccd688a4514d79cfc450fcf001dfefe49ebbf28e9882
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:e5a5ed3ff1811400e58adbb4edc44f12c58fde2668e41f0ee2a06de15c15351c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:87c965183dbdce7cb454c5fab031b33a613e3df048784dcdc25773ac2175d3d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:8ec0de98c0e45a5a96b4251f8b6aefafa700995a90522df75c21bb5131a10002
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:cfa8f1be9d9f0cd6dd4d5c1628cd749b5c48b8e355da1d3161a1ab16977e059f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:7133e4b5c0f2f2dede24ef058bd7379e76485f5b85cf300c0a3e9efc0704ef7c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:eed0e73470d6b110d19ccecc0f2738f6cea2c8eec9c32415a41e40f96e854be7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:ed158555c3186b8550b779d74d9bd898867ee2e37a0f5bc5ce0802438be074a9