dhi.io/wordpress
6.9.9-debian-php8.4-fpm-fips-dev, 6.9.9-debian13-php8.4-fpm-fips-dev, 6.9.9-php8.4-fpm-fips-dev
sha256:f0e4eedccc3fc7235d7989546c5478e5bd8bef42f7ac7b1135287aac0a99e4dd
Manifest digest:sha256:d444897ec92f7ea0e6952dd1d29e4896f613276b02ff222b56dd8f0acdcfe29c
Size
120.62 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:8c67b8b2d85c875547492ca9df304fadb75993d839c3c2f32ba580236a710bd9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:657844b204526aedc5545596ddc86a3a355e0770a5f77a676a0b6dfc920004c4 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:aae092275cba5f743cf795f3831963a47abe2255ee7b6db13b2d47d4e6894ee4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:acb8a5ac93c515c528b6663ba1d1e7c6f9ca9c5e8f630059ecf867d9f5e41f7f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:cf79dce2f3eeadf30b50e6071b1cc88b230ed371b277ded8605bbd4b65503c40 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:a0b2edf57a7b9f48d0b87017c964477b14d39e1144fdf8c092d7aa4ec9f7c0db |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:607849fc1d32b72a3b11b36234949fbcf51a7e268bfbe8dbf7b0761ed085885c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:94a99e78b011dbee0efe17b7213636d484f66bbd6324fce2ce1d70e1ff92038f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:34b3053c33003b05e907a7c17dee8df18abaf32f8daa97614161c73e0b03b48a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:8867461949b894e85dd2e78f40bcab20a639d90ca00601a3d82eb5b861e75181 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:83b111604f3156629db13bb697135aa90b5b4c9bf13937b2cbad2b971f5111b1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:9f4c102efdf452cd001dde220cfbecbfb751fa642dd6fe957cd48c71b5af81e5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:54dcf902c084c5f07981f610dbde6ef771980a3d5136a9200deb2203170f9303 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:cc8dbd46db294abceeac3cadf7713a6a39c63558836d65299167e2277ee54b23 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:ff5f1c8d1d6421583a71edb2a850bd65386dcec0ad4659e355926828a672f824 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:3f6213c9148e29d440f349fe236d0f8ee660aabb937fcc7fe1fcc0b793b89976 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:b6b040cc4eae585771ac439ab8b2f323b912c2fed0fec53ad220788818bb8667 |