Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.1.2-debian-php8.4-fpm, 7.1.2-debian13-php8.4-fpm, 7.1.2-php8.4-fpm

Index digest:

sha256:487854cfb31df95381a3f18c12f2b3bb6d6eb75e869150cb0f714e7aae7a67b7

Manifest digest:

sha256:5145c516e0b7b602ec920b3e5ad3c2cb56c1e2e7ac190f3b2ea563273e3b456d

Size

110.30 MB

Last pushed

4 hours ago

Vulnerabilities

0
4
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:48db39ca9d9b22e1a6b4d0c07edacc25c1ddadcd1c3681249594403d3e516fe5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:8550a4856c80c993632bbd5f9e8ba26b190025ede2d738aae04987aa13a45639
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:f785fea2c620e148630e855e4b0fd338d7b5c30de75ce56b626db5e60f7c9f97
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:89818d6fa63ef3543c758c459a0e32d07e0da2ce5e0b41250b48dd6821d7995d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:fa91e789196174399527a88eadc4d3a656f96bdd3ee34fa20a51d6d118bcd49b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:ed4e94b32d2d5036a3f04937a7b6719f8735e2d23e25a2a7da05d50e1378c8a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:dc60c672a602890d861ec45a13c11a75a9be41876fff85a6c9be03722bba2a49
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:8e95af19ccb43bbe5f90e926dcdd59ca400088c6908d5a4d5f1478bcc2afcce4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:0ce147b259636f2b47e1ca573dce69357add6866ff508d30d7efda1cebacfae1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:e7de9692cf5b2daa8b1f479fb330c89d291503c34ef78277e1a8b41473d6aa2d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:69dff926ac60d9cf5c8d0a91e6a28f52b6d6397a041dded07feac2d1bd331d49
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:d1039832e0011e77befa7cae0398ba742174a4ede968add5341cddb8a8154a69
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:4f3af56b043f7045ca57751f441f17f06eb2b40b9e1e50e4ad55733514ce2234
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:36689b1ef7a084a94c945dffb91ae522dd0de3f488cab3e20a1b95a05a51dba4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:bbff9271a08ee5ae4bd39d66470ab0b1fd3133660c60d1e3580f1263f0949fbf