Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

6.9.9-alpine3.22-php8.4-fpm-dev

Index digest:

sha256:b93514801ca34e1510e8bdcb996d53d24fa6b5528bd6495b7a4285e21e0416b2

Manifest digest:

sha256:620cde2bd0c5aa9884121205865ef6f410ad25d98308fef86ede8db3e9407a7e

Size

73.60 MB

Last pushed

6 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-alpine3.22-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-alpine3.22-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:203fae955c840df8f964b44f93c548d00457891b17f3bed216c50747694556a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:7f5289b9c4e99ab1e6d90ee33979990e1d5223f6af994ba5cadf2c9d5a4a3283
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:5d85afacbce89caebab83d86ece59b4e9cd48b2a8d5efb296f55aff7fd683820
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:ff1bfe1e4e95364a571c5450a6e7727c9978f5c5578f7d0c6d18563393a7fec2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:326fe40a5585f524c1147bd1fc150348935926fdf5dde2e31e35566fbca9e4c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a0d9696f560522b3a3be0b378ebc6618d3cc5a47186c1489a3b0ddd2dd9b526b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:0213600b1a1a560bb7e9dfa1f6971610cdf879dec14c95af9ed9560957ffb68d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:bb6a806c356621e7f7ad52fd6fa7cdbcf3237ae0ffe5e33979e1605a5720fdb7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:dabc906dd5bb126e420a1642d72c129d0300a4bebbb8062f3db2269835b3c1b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:e4e67314326849b154b59883d89e5ae599b436c75a238197793b8b8643bfd304
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:06b99810186c167688e0cf788e0193d8ef71f609bac7c0ff3a4c91bf807028fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:1e363c61d6a8d5a3b2ad3fa006e5eeaab81d432d92a7cb0c2452de41e9012ecb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:3c15c42ff2ea89c68c900e3c8fb6ae3b7c4bde3ee2d9c9f5621df391f4acfba4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:fdf47cdaf1d456dd5dabcd8855f8a41156eb3e27c312570db1e27e4c3eb5ae89
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:bfe2c767deae92d42f8d2f2dcfa99dee8bed8068c30f82e0813c81c08bc272a0