Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.7 (php8.5-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

6.9.7-alpine-php8.5-fpm-dev, 6.9.7-alpine3.22-php8.5-fpm-dev

Index digest:

sha256:60c77b77152e9f1e13e5366f227ae28f1e8a6feb6754668d7b3eb14a049f8f5f

Manifest digest:

sha256:5ba67efee03290e76649d0ac96f446cae357324b24b9257d6aad5212ae6317a4

Size

73.87 MB

Last pushed

6 days ago

Vulnerabilities

8
18
25
6
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.7-alpine-php8.5-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.7-alpine-php8.5-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:41e3bec02aa16158ffda26231d3dbcc21cd5c3ea327177c2f0e47032bfca96ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:8830d69aa48779755549a3b7d169a941d93bf1543cf673000c0323503950b4ba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:d5631eb9cdbf5f5131b1a92dbf8a0ea86bc3afaf7453a8c0e12b5c8340fcfe85
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:9c03054fad86a7131d55056fd52253ca9cdc4a841e46443926f79bb7de4202c9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:6c6bf0883459ed422ca5d7565463d5c74848d9995dfce21c06b74da4677f8986
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:bab7b7f4874b93405736c0560d47a7f766c01d25b6b4f28eace6f6f3ce09cf88
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:2e649eb6b3e3c2bfb6974187966abcafbc9bb8ef480509943b253d4032ab68d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:e533e8aface52984ff0cbb4ccec0d6d2553f771dc24db5bbac9a2758bc698ff2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:ec29ecfa63d27d9feb996c95f987e1d52bb4af741cac3e7b7da1a98252b94975
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:26d882b8b02010afcc91003e2a64d25f20cf2fc5d29800810d1288451e018970
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:296ca0f66b3039dce4eba29ab862e7f5e3de7551e18f380b9f8a0945b4ae113f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:28567e0b4a4b6bb21fe4f214c711a8c0316cd26cf573cade2519971b8a17f5d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:86b6f2614d36f4cf84ff99b4eb85caefc51c514ee7abd2eca06f19799c2e82dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:7918e4f4e61380640c2a78fc0a4d582ea7a2459a5f887d5b327815621c56a2d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:03494fd65897ff3921aecf34e09896fa1303149c2587fbc58e0a93a76ab4cb5e