Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.4-fpm-fips-dev, 6.9.9-debian13-php8.4-fpm-fips-dev, 6.9.9-php8.4-fpm-fips-dev

Index digest:

sha256:f0e4eedccc3fc7235d7989546c5478e5bd8bef42f7ac7b1135287aac0a99e4dd

Manifest digest:

sha256:d444897ec92f7ea0e6952dd1d29e4896f613276b02ff222b56dd8f0acdcfe29c

Size

120.62 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:8c67b8b2d85c875547492ca9df304fadb75993d839c3c2f32ba580236a710bd9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:657844b204526aedc5545596ddc86a3a355e0770a5f77a676a0b6dfc920004c4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:aae092275cba5f743cf795f3831963a47abe2255ee7b6db13b2d47d4e6894ee4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:acb8a5ac93c515c528b6663ba1d1e7c6f9ca9c5e8f630059ecf867d9f5e41f7f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:cf79dce2f3eeadf30b50e6071b1cc88b230ed371b277ded8605bbd4b65503c40
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:a0b2edf57a7b9f48d0b87017c964477b14d39e1144fdf8c092d7aa4ec9f7c0db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:607849fc1d32b72a3b11b36234949fbcf51a7e268bfbe8dbf7b0761ed085885c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:94a99e78b011dbee0efe17b7213636d484f66bbd6324fce2ce1d70e1ff92038f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:34b3053c33003b05e907a7c17dee8df18abaf32f8daa97614161c73e0b03b48a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:8867461949b894e85dd2e78f40bcab20a639d90ca00601a3d82eb5b861e75181
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:83b111604f3156629db13bb697135aa90b5b4c9bf13937b2cbad2b971f5111b1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:9f4c102efdf452cd001dde220cfbecbfb751fa642dd6fe957cd48c71b5af81e5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:54dcf902c084c5f07981f610dbde6ef771980a3d5136a9200deb2203170f9303
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:cc8dbd46db294abceeac3cadf7713a6a39c63558836d65299167e2277ee54b23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:ff5f1c8d1d6421583a71edb2a850bd65386dcec0ad4659e355926828a672f824
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:3f6213c9148e29d440f349fe236d0f8ee660aabb937fcc7fe1fcc0b793b89976
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:b6b040cc4eae585771ac439ab8b2f323b912c2fed0fec53ad220788818bb8667