Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.5-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

7.1.2-debian-php8.5-fpm-dev, 7.1.2-debian13-php8.5-fpm-dev, 7.1.2-php8.5-fpm-dev

Index digest:

sha256:2c040c025b50e0d3da03f4d88fa0236dff00cb15526861122b585b2409cdf9ed

Manifest digest:

sha256:e5a1fc656420b75e711b6533eca94fc1e79adb96c0964ffee26583126889e89f

Size

117.95 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-debian-php8.5-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-debian-php8.5-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:cd1db9722fa39235f2e26c24cf05f696ec611303c6d00fd4710e822cc24a6ce4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:2502b320beed173f6bd7c244cec073a2def17d37b23c6e2c6b8c9d5ca57d0a05
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:107f6b57f2f97116164d1974fcb23b9c6b6222b29a06cda18f29e82c7833cb0d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:4acc06938f807ed9c882f9edb065733e3b370f4d9ea318c4cdd72833e8b5fd9c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:11aa978fc9f5eb9bf34b926a6a9b0aa2f45d9a0c578b2326ee31c05b3d8121da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:ffce9e5a95d7f1a40600a478c770d9f038cbfd7231124c5b87ac9ddd2307f7fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:9eaa02a227cd38aa1bf064ad6096120f5da0b11d84d8162f64a7dfced16f76fe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:55adb8d17f2bcf145ac9d50b7d9b8fa2e2e84601b50cd16c5f71c7e45d562fd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:47d550568ec1a53cee9ef11352ff0bda9c55737dd285a392ac483480393c507e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:f58cbd3ebee239c46826d08b47a5bb36e7fc8ee24ce21e561e79ed742c1d3ed4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:13a4c5366d281f073d60f6bf4a521840af9f65c5c55d26cadb391e619c104458
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:a15d84c3a63a8d433a54362c918088b7f6b8c50c0a22977dafa49ae57d42b551
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:17589e290157bb145bc859a1dc2db4725d8dd7e3526e3f215f70c63306defe3d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:5ad7fe9284398faefacf61c50c6e43159cbe100845ed09ed5a751f70720389c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:eac9d1ddfc191bf95037384cf1c9b482ad69c6943b9fbad99f214b13c9c500e7