Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.1.2-debian-php8.4-fpm, 7.1.2-debian13-php8.4-fpm, 7.1.2-php8.4-fpm

Index digest:

sha256:6df7fbf43a3926592743dab5af3b28fac94bdede91d0cebb80cd612240e68352

Manifest digest:

sha256:8a148b558954c747d5e58a628f4e0eb126dc1c0fc00514e1cba4958f260ef0a4

Size

110.29 MB

Last pushed

2 days ago

Vulnerabilities

0
4
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:3efbd3f88e17e4cf3c88f089845f53d7dabd7904e313dec36b3c011d0329a32e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:50a05d9f9241d9e65fe53db2b69c75ddf43d132002519fec31fd17a3baa94d83
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:37f7601f60668444c416e180c93de90786dec0eb85c5c3097b1e3a537bbe4657
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:aa3d35bbcfa5eb49a124c655f7bb6c182d0127eaa65f18c3fb21830921a651b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:cfbfaafddb9914186e03b2d9b37d0505c2295a5de35888b544628e2498cae50c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:3b5d91206448ecacd381134e6d4d7ac79eeecf7841e0129cef4db8101c50d1f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:ff0d625fbaf5ca761d20008df618c5f70b305e472b9bfdc23969a0798cfd4768
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:5542c19f59118ffc0040a3aa431c9f71876ef98e6c75946e9c8f4715bd8dea51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:457abc2d8e59f02756162b725d5a23a20807ba441f812b2ee60086a1cd5fe03f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:2ed18c8d5d4515b2267e42f9dfd197413c7a8d3b6910cb3dfeb31a1be89d2d8c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:db5c6c040aac50c629dd4b2819d177cdbe6f03b0d069d531db32b16e69d2432d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:d7090790db2b9937be2c4dff2db0c7e2ddcde1cf0877d877133929e2e9b06e4a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:b184201aa701cc8a694e26c5446bf30fddc3d354300d61ab0b5d3fc412f0d330
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:a9156e2fa200b5cac56fb2b4933b216629b8feea4c8ed011128cad4750d4fd27