Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.7 (php8.5-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.7-debian-php8.5-fpm-dev, 6.9.7-debian13-php8.5-fpm-dev, 6.9.7-php8.5-fpm-dev

Index digest:

sha256:ca0ffb5f7a34890ec47c1d13185a7724d4df21301409c9783cdb32e73c6d7eb3

Manifest digest:

sha256:70ba3b56d789fc6c26f9333f90b3b534b4832b5806cf599310a10ee5cd13c5b1

Size

111.42 MB

Last pushed

4 days ago

Vulnerabilities

0
4
5
17
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.7-debian-php8.5-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.7-debian-php8.5-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:4fb52fc7a116e09f78293ee50ca76d3b8a043494c06b773c49c18df0c44a828f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:a64df624abcfeffd13876a270195819dc1d2e608f667cd92f60df34653de0cb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:325cb421f087270cdb84909a77f946e381c9cbd1c0838ebabb2deffb7072d030
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:6c7a5fbddc7ffec9b6e2a22855f084f68188fdbf17d28242162eb31985cf47ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:238a8ba7018ceb511d2a8081fba657fab0be40ce031f4043a90098f49d0f0bbe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:04f201dc9f0a3f4784da7c5f9caa9dda18420186520c37de8b89bd441f1979fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:63933fc77a6e923035e16c44a0f1131241bdab0fd5fdd73fea3a1b07d0db4b30
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:826daf3db728906ad7ef9b7f8bc302dafd1e3a4bcb8b8bb6f1c35531f54583f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:f63d03de45ee03c4664425578f178e0a3a5873a6a1e5019f524eb72fb2fce262
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:b7ef7b9a01b687c7e8594cf7db236dd4f996029312bce6aa0163308fea4ff6a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:0dcb4e6132536c6d9744d9c6fcace88a477a8051c658c89b27207ca70061077c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:e383c156f86686c424b1fcdddab88a9adccbf2371ffcc762765dbcd5a55c927f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:346d1433694f7c0ead106e4b42f56d72ddf6aeb7d7f5571d4902397693531eb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:e1abfd794d2ed1e3fa94dafeee33fa39d3355c31592745c29231934bd5be4bd9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:865d3adae388d0f0833596e5310e4e6275a50684b4c235ce63c7c66134e9b61d