Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.3-fpm-dev, 6.9.9-debian13-php8.3-fpm-dev, 6.9.9-php8.3-fpm-dev

Index digest:

sha256:a1224ca39c25a5f0b2da8420751738a3419addf5b51445f3c2f84ad1f286adae

Manifest digest:

sha256:070fe5f3fcde34e68bc616d7aa53cdce6c5727a1e54eeb9f75116224789cdff8

Size

108.90 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
5
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.3-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.3-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:11d9fbae56f61bd55e97b082a8ea7a0ee0d73d4613a65059075125235cbd0f52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:c772b4908f890e073b03cc00fba6cf95a618293bab1efdb6b9ff1a407ee90758
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:20bc7b1a2027e1902ac269834836c0e49eb59b784f72c0526644bcaa73641bd0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:aa2eb011f619158324b795d58cf055846574bbe39bf048919f7fba6d58386e8f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:12eb47f7073ea1697819ba7c380c08b1ba7ac1015feef8359ed3ca81fc1f4ef9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:b7384d97b3f2e137e6bfa1a3da21d067d4f5151e3862eed99eb05143f5a4e205
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:26fcb911aa3b497a74e05f394d55073d87a306c04f35a878d06c0d394789ecd4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:1d6d4c7ae82006509abe4038afc7e1760769ab738747bd894ef830e18167550b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:5df54fe86a5afba00259a1e9f6feeece2f0c13f7449c8d97af13c8c01367901e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:f1790c81d3e1d0d69bb153d2495c8b125b6881ba01a78d20cf284ea40c0c60e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:924fcb7e32830df6d43cb7d0d74982a1fe2455d708cb59dc7601abfe26fd6dd5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:19cf8c9016272a153f7730be6089d3450f4552c7ee9c921e8cec8d62b068b9f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:f8c6de52452cdba62e330b330983bb01b6008acf4f7ae7e2713dfbcde95894f1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:8c83cc6189c6ec0c36c04d8ba86aa6c12fa54b8c35832e737089529295843096
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:1f7ee7dabb97813dddfe6e79212f28fcc4d2997435a417f40f6e44da91bb5419