Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.5-fpm)

CIS
linux/amd64
alpine 3.22
Tags:

7.0.6-alpine3.22-php8.5-fpm

Index digest:

sha256:55f1a8db753acddfdadc0fc55272b0dcc33823c18e089e86fa2e6eb42d5fe961

Manifest digest:

sha256:a5abe18e2c5de8a7b332225d53e8497dd7205f0bdf9cd12bbea8d3c511ee8945

Size

75.57 MB

Last pushed

10 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-alpine3.22-php8.5-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-alpine3.22-php8.5-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:ea833e2bfc0c3eca4d8ffdda8a180d7ed133b4dbf050f05cfab8440b6e09eb9b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:9cacde403a3576a1fc0940909b12e35eae621ef4f1635fedb6abc5ebe804d712
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:2d40e8a83434cd73873d64a4ab0fb547b7e6b861983eba2f20c67cdbfdb35fab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:6685f2ddbc3f9890f69360a16bb33e4adbdbf7d355fedd5b9a608fb88232df16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:599a410f4fbd3a79086299e42c7927077b8f45579a0f095a31595eb88dc5e347
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:22c89f1e04c0889f03380941f69cb4dccc4b1a594e6e116c62e5f17dee7e70ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:834772def0f11d61fd85fe6a4993345694d5e12de4cac3fbe0617ed7e7d292f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:b7885c0246e32536f40ee70693821ad342e46ca0c879a38faed20a0e121f1017
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:1983838f822d941117691bc4da14ef3f01da73efebd00761cc4e01fae1998e50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:bb4ec4710c0a0d27626f0346fbdb60717dbf859378267657a2a4b9513f93c4b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:ad00df3e5eb1f41ed7128d0269d80f25cc0cb30fc2afc034f157e0cf4e9f0581
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:e93558f3b528a5ead4f5b1599564fd6a604cba00d0499b40df4044217ad85e7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:5ca947ea5a0a4e3c650d3a64a6223d18c3f17f4c1df66e1178ceac2352d33b4d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:44a08bfb3b4c331ebcde2c5d78d687ab51056036fdf31e60ca82376d5d30c2d9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:871bc4482fdfe70b6552d0506db39f0831a2d765407798ef4136c7265a43eae1