Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.3-fpm-fips-dev, 6.9.9-debian13-php8.3-fpm-fips-dev, 6.9.9-php8.3-fpm-fips-dev

Index digest:

sha256:a9f0fe65c3c2195ad98a49f5833226b848656734daf37618a3873d23c30508f2

Manifest digest:

sha256:5e20ada84fdfe15c572385f5bd10a1e6566aa8b3256b159edc6185e81b8b9f8e

Size

118.84 MB

Last pushed

23 hours ago

Vulnerabilities

0
1
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:47fe464f6ea0fca3ded8ae67b454893aa024fc0e4427690e15c59722c1ef48bf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:bfeba1d7e3f8cd5d6ede8dd88d7b395e6a76ce7002713982280895f3ccb0bc01
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:d70790e54c6095573a7dc8d1c642cb190e363beff67fc8ccc048b64312aa5a8e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:8f7fcc131f43eb96da1a5e2c4546c9362e83df107079cc7f0c5c073c3de8e8a6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:d9714071a30a84d7c18b6369af3a6cc4ab4076a428c1d5d187e7602c256b30b2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:076c2f765d9411163294718adb013fc14fde28afa01fbb905f958d4c73fd6bed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:b1388e33936cc964897f038ea209e305b668db3b1dc669adcaab115bdc4e11e6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:be0e6a19b6174b4e9185c165ef0ddfe729a9f70bc2d156184e60640768faa88a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:301e022bf657279a20c53ea69c0d97c045796409366a1bd14a6aa1571de4d6b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:5582ece51182a9683589992120bc6aeac7217d76bb8a28162302dbe8f399c79d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:726684556f7c6f6ee9eeecc4a53067c88838fe8475d4819f442d1c085f05c4d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:5bb0c2fd93890ac0b715436e23695adde0cf095601fa3addee169f270cf5f1b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:bbe4a38c560ddd477531f16ee0f01fba1d8a958e27c1c822ae4658481ee81b54
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:087acfb386ffa51ad98da6c7de436839f180da36acbd7a5f9cd6953dced0ec1b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:b7835a5a54e6cc5f62fd1919707072eaa2ffa687715be4597c50d8616d382fbf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:3ff81b1f2d067d250c36b32a28fde91c939a76e9910204f44e768ab2a12a3146
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:dedb0b9066e5ba9bad90d076bcfc47b31056d94b027deb07f98a9dad59edff35