Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-dev, 6.9.9-debian13-php8.5-fpm-dev, 6.9.9-php8.5-fpm-dev

Index digest:

sha256:b0966a02dfc898de3bf68a0afa1f963d2b5509d2f6c60f784953a575733c538c

Manifest digest:

sha256:5512e725d5eac0c39bd41d83885ae0b3b99499fbdb1ad65c945f4e2d4309617b

Size

111.44 MB

Last pushed

6 hours ago

Vulnerabilities

0
4
3
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:22979c27a49d3d640fab7d29cb18e13868ea18dfe12e83b84ad9cdc9488136a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:1c0d31c66b946756147ce6a66b12b6b85f03acc79ea8f4ec14cafa06d67602fd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:caa33a3d56c61fb0de19511ab32c4d91c4147942223f54665ee4814bba426e89
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:41dad0c55444793fffd48b03a7578f9afd024d810259a4d809d8aa6506b8b23e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:702eee00317c07cb3d65cce01d9a2c0746afb54a1a89022fc699c57101e18b6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:c60d0702efb3bbfb6b33f706a7b87e9416d5e47442ebeaaa097dea31efd25ee4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:4f8bec1e42d20e011ee45ec9629cb6f73ed0e639979c8974f01fa42a0d99fdda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:1a7da693e451668723a1b13ebf168b2ffefdc299fa1e15d834398c157ce37eb2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:5036484b047de4eba20c848333a56d2f008f3c17fb4fb08d435e6453f3023cfd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:1d90bd8b0b9523141d8325b6c70f6a26cc26f0542925bf465bf45eab42a8ede7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:17b4702ba8a63a4896efa2559d6a38dea659d9ada54850c8db61b051923e515d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:9e97f46fa0e1d2e7537d190cc1a6c5f96e1389a5ec39266e2f107d85c13597be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:639cf404f41dbb539e7c3b7d9f0473925579ac01d9222619342f4a83939a0805
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:32315c0b27eca4c1e5a04748a58a80deb533c70a0231ea87b89e6dd32f12574c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:d2e6b21160581efbc86a5eecc94a0bb55e06c3fcdcbe6ca9709f676c4ec80ba5