Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.5-fpm)

CIS
linux/amd64
alpine 3.22
Tags:

7.1.2-alpine-php8.5-fpm, 7.1.2-alpine3.22-php8.5-fpm

Index digest:

sha256:27724cc0dd27c4b66f6469b10b5bc108beb2bcc37c222d28279071dc6e04bfd1

Manifest digest:

sha256:13e382e4ac691bba417b7e360d2eb8fdfa4b6b1afe4ce69a20ddbc97b0fadf75

Size

79.88 MB

Last pushed

2 days ago

Vulnerabilities

8
20
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-alpine-php8.5-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-alpine-php8.5-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:6b99ebdbc84c661be3b4555e52ffd0ae84e0b507ec8496f82015264c062c46c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:ae7046f6913f4490cd2b1c84b24f491d8bbccb3ba72c7a80fb5eb91c79d63729
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:7ee4ef195383a9e8f810aedf285fcfcda2e21a6b1cefa4596ceaa9a791f435a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:4d1807d41fdf017456ff8bda0e07ff7b0658be827325f218d61a10e9d6905bb9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:24781afa19a5576295295b4e0a073e2f6b08625709734c86d4f421174addce51
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:eade70d66f031be180f6b49d0c7109aef6d6579932c9f8cd8f5950daf919cb37
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:6f7aa2a9f4da67198b1d1f32402d9ec3b92f9c09919c852945f0645244e30298
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:2209322c534d077d5eb6a19463196ad169639016d4b5f40d3d9acd51af9dc32d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:e4d6e51502506b375f9ede8c5aa6751e9864f3c182119dc67d65e8abbd4045d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:50d3f8aed54256a21a9339a1b828bb5872ab182f41bfa053367dd89a841b132c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:333ac84eb27eda2ff3d7b8ec8bf648a74c9ea301cfd0a1f313adc0e7784bdf0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:5d7247ed7e985f9f1e06ff92a9ed8acfb2bdfbbe8525626e5dff5a55a59b3cc0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:1222ef4ed54709ec14dbc7041eb34ed4f33c5d8aa40cfdd2230c7a4c856cd72b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:4ccaf9c6ececf078f9eaddb3223aecf0ccc523977b42726a84fd298c3ecc3b4d