Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.10 (php8.4-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.10-debian-php8.4-fpm-fips-dev, 6.9.10-debian13-php8.4-fpm-fips-dev, 6.9.10-php8.4-fpm-fips-dev

Index digest:

sha256:17ffb85680c4a6fcfa4898628a4be10c9027ca6955bf15fa68fdf81e3bd1395a

Manifest digest:

sha256:a7edf229cb5ef6722dafb4b5a87c909b4f3d6d6af66c7176a2f71d3512e8e7ed

Size

120.63 MB

Last pushed

16 hours ago

Vulnerabilities

1
5
1
7
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.10-debian-php8.4-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.10-debian-php8.4-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:fe4ffe6553132b4b27ea08f50c0a781a4100e101d328b0a3226874149c32640b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:103996388b3f07c1f6a140d1b7375f7c7d8d3f14ef4adbe212e4160282cf9504
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:cf1fe22f13b9406c7f3da33e3cbe554853946df76457557cc0bf187c3be125a6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:544dc60c97c24408cd7b2bf85071b4dc8ca2c24fd4b71e52103a548b676ff755
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:df8ece1cb1aca9eda36c5a1e078f352426d29c5467080a164a304fbcbdedb52f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:3e0c8df0e0d0b9119e9f8cecdb434a5c692070c20779451ac47c99a5f197aecb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:d05e76ac9f5d37d3a639fe14361ee66301a05c6648d86490005c26699506591b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:8ba07e84045147031029464fc87306baa56aa27fbab7d3033e3298390eb4453a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:8d7c5b5838fc4a5f6e7420cd9d8968e07d09b2886aedc2bcef69dbaaa962d662
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:056701058d0c4ea223b599fc699aaaa0068e4cb8c98fb6c990d1b08fb0a966b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:b642f7eb227932deeff5cad0bed68e6514c8ffb74ad43c17468d4ae495eac03c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:3420a0a5ff0627b642ff9bd9a718afac0b7ef6abd817342641c854afccc7876b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:9e03789f26704f3ca554b135c42174fda0e8c278f58365e930ccd008a07fbd5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:c1fcc95059f3a4515d917b35eb5313cd1fd0bbb0c36e863c4d2f88489ac1d2f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:0001d3d7a4e0c88cac1db7c45e02de769b09acf6bf486c8ecf237e58c3ac3014
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:f334d2a08311f3a07607a16f374a9c131b48afce9a479de322d6ef38c8ac5bfc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:80533195a8b04302304d76a7969024d75e7c71c70c832a2a5bf2ad232bb22ed8