dhi.io/wordpress
7.1-debian-php8.5-fpm-fips, 7.1-debian13-php8.5-fpm-fips, 7.1-php8.5-fpm-fips
sha256:17b299c9db3f0c59131fa23334a215970662aa3b6a2ceac5ef65e22cd97dc3ca
Manifest digest:sha256:5a925a4142e6ba0775732919fd21b6bbf93b43c96f36d3fca0580f7cda568b40
Size
121.17 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:7.1-debian-php8.5-fpm-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:7.1-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:8fceecc54cbc15d6335fc742dd015641a8879b3adacc05a1b4ff8aa2522c53bf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:a9cac2695679824a2f351c2d58dcab130bd5d4714772a26d7f3db3b127633eff |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:5c49b07bbf5aafda7956ebee50e6981325ac95e28e54705094a3720aada8a624 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:38685d6667be77fbe2c713593dc0aa0356b2bac12f62e7205619941e98ffb60d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:37ddbca2f66370fbbc505e6fc6cb9534d90e90379b0babbc9ceda16a4444a1b0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:eea5bf09c7dec8ba1b5ee1bcf307e446f1fb442c98e9216d552e995afab16a04 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:4fcf0cb5021c882af039da112aeb285e45de52ac2fd6f1a854f9e4c404b2c5a9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:18767acd4a6f299835534a068d51461e8a0f8df977b734e4a66afc9329a74706 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:c550cef69c18d0dea1f3aaf612aeb8f0f1488a0fc690268f291b061a7b06943c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:d52c11b378465fc9f54b12553312833ba6c8759e2a2b7f43408c7fa23d4d5431 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:ff622e88cab0a5a08e2400c229fd29262d807abda0b1177e1d9a40ff4813a4e1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:409f2013fd91a35d83d180edf83c36b08537c8b52ef6f559c4a9fad801f70ae0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:d94c1fa88438a822b372b4f5fc4276a887f512490493af2bec348606f020265d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:41bb7a427d6f3949dac2cade9e424961e9dbbe16ae3263ef4eb2a9737b1e4230 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:a075ed2330e05961f1906b1f918d9cecf4ca43117b418335996456c4994d5914 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:ceb09b7353630f49dd7a4a4f5f31875b462fa5671af66e691bc9e3121831d2b7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:7466bbd80d39e7503741f51dd8ae4d6f5bc04995fce3a82f704c8893a005ffe4 |