Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

6.9.9-alpine3.22-php8.4-fpm-dev

Index digest:

sha256:e64a9c085f73de792143cf25f3aeef4634f9fda72aca24af59d3b828478a8165

Manifest digest:

sha256:4154dad669ce5db539ee39e2933a7fa4b0fc40fd10c8edb4653dcfd8acec8448

Size

73.61 MB

Last pushed

4 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-alpine3.22-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-alpine3.22-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:765a252a18a93e5528332b618f26ab306689a82bbb6fd29b7afebdb017334510
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:6ab00dd82f41373bed98bfd0e7eed5da12d0d1264eb14a0c459281f0ee6bcba1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:f9668debf3ec6dcb61bb6218a8343b1abea92ada6fdf3ac50cb0884e0def8a4e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:01b128621c529f2ae0fd73d99826cff64d02d407dc65ceac4690a7c82f7460a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:fc2556b85d478e94a2c920f0de644c3164b20668191a425837e07ddb70379518
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:ecc1a6aeb56b3b9addaa047a6ec92ee485d04ad08cc121a3b4dfd3ffdb225900
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:39255ee12aeaf3534c60d33bc81e320d7fb119ef4cb47f7c8ef3f9ee9a64c22b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:ca68fc1f6e44d5619720b0916177ce3d27a2d3c77ad77a1af0b2a613ee6c34b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:4b4f4c058ce81940d8f380d924de9abe95b23e7862edda29719100fbae4f2252
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:af1e8dc7bce933240cee6608666f1dce05ef0648eb4e071e4f9f822daffb2fb9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:b2a50d71957c342b3276dfee554ad59c0f58a9ec05b2304b41ec1f0f95ba59c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:15b8c63a1f133780a5953b0168fe2b75a0d7ea77f01e5b5c0bb00dafd757164a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:7cad8398f536b43d1cdba701da23cc65d79143c8fb8f6d98d957a9e320591f05
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:43fd9759145bec73bb535abed5759f7155389a67f809fefb8afc565d28839d19
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:a7c4a3f289feafa9c9d082c54d42c876bf9c543a5475b9860c7feee5248cde4f