Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.1.2-debian-php8.4-fpm, 7.1.2-debian13-php8.4-fpm, 7.1.2-php8.4-fpm

Index digest:

sha256:87ac566173eae2b3e0660b658e12720bb328c7d0cb7c68a746859871afd4070a

Manifest digest:

sha256:a9c07c43e0ba5b1c9aec311f9616bfd28ab3d93bdeeea11f85d3d825bacbf426

Size

110.63 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:3de43fa9c7e0408fc325e5abe8f59afe0faf58cd854f9e78d38dd54f80424209
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:1346b703b88775946571bc06a6bc8d7d1e475838e67d75e0f01f23951d46000f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:b64d3242df7fe58d252dc316fb21604f2d2933a479d8e2fc17884e8e304ef1cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:047a865d2faa3b0ba4d04c7c1b03ecd8720ee2d5f59cb87278df626401557a1d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:fe16f9307667af0e1022c0f87ae1a5f75483bfecea3dfcda3c68511250922d66
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:63ce06589c138743da59b7fa80832141fe8e35dc9c1a7bbb09e30e5db2fa9879
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:303965c976791b8f31a9cc547fd9c90f10c39fb885c07f033c148afa72fccf42
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:f264da8aaefcf9140e0b8a8bf7389d24cfd2a8ac641d04831aef4ded952b309f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:8d3cda2f0577e0b8774266afc0181a4775a1b7422334227ac0b29a89269621fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:895c300cea3612a5abe2ab1c874aa1b896c910c8c9cbe8b41a6c822a92d8693d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:64a70737d7d53fd48032d4577d39eaa0fb2f9a012cff5087d83b663a73369cee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:b4ddf41c7be8c7cf1595894f10af3775e07536a850bb500a16aae53fb8d1751d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:b99dad1dfc2ed4aa66c44452770acb5818d8740a54357df3057c549c602bfc09
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:d44f4571fbffb597be7aea5f1cfbceb8c9d3fa5d9a8c00f83a9992f0b2ba6c38
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:ceb5ac23a9de9e0ad5c215adc5cd789ab4104280a08a5337883303de69c0abb0