Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.3-fpm-dev, 6.9.9-debian13-php8.3-fpm-dev, 6.9.9-php8.3-fpm-dev

Index digest:

sha256:336adf078c36a3674bc8767f4d4adf90a5c424035b7348a2c9969872a06181bb

Manifest digest:

sha256:c29b2ef3653968251a6dd122a6d55cc179202197013a9038fe8a7b70359cdfbd

Size

108.90 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
1
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.3-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.3-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:64142fdb604a3664a526ab98808004d71bb092d6eba279b6693e09cb3ebe8293
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:f1c6409361190174f9745c737c66ee55d7ac19a059b7ebd23ac8e2a173f658cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:d24ae8045bd854e012e872896a817b9f5aa3d3dcb4e1ef57b1d8724fa28d0cd5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:107a13d891f4d573556933f963506f19520aba15ac0a43f970e4f3c7501c27b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:6a8fdd6b293aedfb36d47647b201b3a641060be864f3a23127d7ce5e59d2f900
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:139c8e4108007c525c6d7a9052f941ecef143196c985162053bbcce46b830b4e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:2f19e989172f90f4c05872255359addb6988ae49c551ad0297a273fbd3665ef1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:a3c5335c8cac56a165e90dcefbb58adf2b4f9ed095c08604881df62d88250e8c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:e85ab20b640dda9c3cda15caee9d49d6b28d4cc4f23ee48a1a0d9d29ce5e88f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:0783ab97b143fddb8e65f26228c745ee2d325666e02a6a68b8290b125077972d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:159a653960586e435f3dae6ebf0de6fbd639b3505cc555cdf42a10dbb5b8b932
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:7cb099911ba8b280c390cf93ed87c306a7af6258baa14974b46499cc9b1d1870
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:7ee06877934bf061695dc6efd4ddbc2cb1459a4107c86af8a301cc28b3288db1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:f4e95d6ada34fcefe188c70d9e2a8f6b55ee8cfbb92dddd353364bae56437111
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:3240ab0426f5b349fedc85fcbc4e0978c98ac1f1f33de917a39576e5bbbf3a34