Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.5-fpm)

CIS
linux/amd64
alpine 3.22
Tags:

7.1.2-alpine3.22-php8.5-fpm

Index digest:

sha256:fb55894763edf71e2688a1a46caf5e1f8534e671bfae37436288e339a5b4f985

Manifest digest:

sha256:b8e2fe6a6be25b62cdaa6c17587c678fa1f43be9be35ff1db359bee0b5646d03

Size

79.88 MB

Last pushed

8 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-alpine3.22-php8.5-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-alpine3.22-php8.5-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:077914c21eaf714e349a7baea4e0aa73b7f34a0c6dbb955f3176e6b32dd81f93
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:76fe6b3a20c6c7b2dffaa4113da427494693e8953c28fea7ef8426fba332b84c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:fd53e18e79c01cce3ef7d813308c50878fdaf2113a32379f77c07b48d915b958
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:079b350cab02448305be0532790ee17a91b14cc6ffc6336a537902358364def5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:8d072d1c52fa2ed935d1e7d88a6e570a950e10b9c121d9d1d26b1656d62c2172
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:f398ddb18ddd64f16940a8124d2e282a489aa2cbebda4649454431b39fcaa907
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:6fc6350f7b0e8bb5a081c622f8fdd8bcb82a2b925b06d696d6533ae5bf60ac2e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:e6e4bed4ceeb1e1e7c3a91e5d83ed599e6f48d25ea86c490a433f8692c7edf23
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:bd1fcdfb275ad5645cf09e5286586371cbfa9456ba2c9002b5d0df6837fd212d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:24947c2a135e8126e51a0535a8e772aa64d12c7322d75ad019f1c76295022c8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:12e4d5904c847a09145e3877a1dbd9ee935cf7fc3eeb88e3f3f75986cc373051
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:62203a31911c80dcaf4cad768b1318a6eb8950357ee4d0103e549c95f413f796
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:69db3003a1d9ff017779de4797fc4e671d2c521303d7d9a11a711d05708c79dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:60b1e1844140e33630fb1dff04828ab20d64d14696f6f7301b999ac27a5689bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:81a201641a9e697dd560c277582686e737a33528c5b597054922a02881d23c14