Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.7 (php8.5-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

6.9.7-alpine-php8.5-fpm-dev, 6.9.7-alpine3.22-php8.5-fpm-dev

Index digest:

sha256:dd838a50d0bbbae4a522b4923e0d778326e27b5a348cd31f43f832db1ff0ed7d

Manifest digest:

sha256:6902491ca54871176e39b9af3a5b30ae9dc967231ee4ea17f53fdd62762a52fe

Size

73.87 MB

Last pushed

1 day ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.7-alpine-php8.5-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.7-alpine-php8.5-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:00247d1a9468100dd6df57ece5bde352a2cc5049d954462c98dcb5e0f96bc2c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:1ccd9e40e2656ad623c10d039ea08edc30793eafb36ccd920164d4452fdbc714
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:70632c9a61c55801b9130f9d9f1ec8903c232c6a3389270edc4e4a3305697aec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:9d3e4a84ace64d4a49471eae39eeab165eda78eb65c609f7bea8e807c33dd57d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:9cd488aae7cf08e9f9b28e8a943cc993067f2ed91c02169e2f4b82e9d484fef0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:02920c4498ce80e5149e54fafd7885efb38031cc849e1580d54ac81145932e19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:af07561f2213d3e69a8127cd01fb0bbd7ec6d11b902e2aeb97e15ee1d2da4841
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:721e298761d4128ddd8b48ddb54bfb43df1984bef3aac5d4fce3b2514aafa995
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:57c9dc7f460fce700d079ee6bcfd8dc8bcce0ab56347555c96d98c80f4bc95e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:9ae2a8332dec3b27577369949ba8ffd71b8f25f8beeb3ed28c8940feaff8d309
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:f5c50eea33783a7f66b939e92dd737d5110b77b74db59c263d4ffde07089d5ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:5034164243830f1abaf3e32a564ca2131fc69d6d60cf4e5341d6ab9155508b90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:51f6f5ab6b1f923d339a4cbe0a3ffa23c3c84ed711d8e83299b3a8fdbf3ff13b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:4cf32d8efc3580bd8e556ece7259eefb8795c036e8fa647e3f55c7111c2c19d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:65fc0c1279608efabbda080c9da3dc6117adbf8e8df7611efc2dab1874729961