Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.3-fpm-dev, 6.9.9-debian13-php8.3-fpm-dev, 6.9.9-php8.3-fpm-dev

Index digest:

sha256:15c60802723ab8d7453a25a2534564f7688bf7fb98ad7e03e713206a0dca3539

Manifest digest:

sha256:8f48b8e0f7280fc289f12f9105b40189e08956fca71da938f16edae9aea04640

Size

108.54 MB

Last pushed

11 hours ago

Vulnerabilities

0
4
3
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.3-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.3-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:bf05b702340cf882e621c469a05889785f2e58fd9207d9494f9300a1f6887d1e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:656504d339a7409fd2ca43d4d0a8afef7d017772792a26a2d13abb5661f7869f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:6231210e88d9df2e6d7e7b6bb4b05de05575b2e97cf6bbe32545b9bc746aa90a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:27dd87e1f4300694c2419c46d8fad77c34b3fe7d42c81195b122c8cbcca40aaf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:6777f2c8ce0ea7bafc24a4c1a1b6709d7a7c5f2d76b772dbca2e4dd4ae712b0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:104e935c7a32b2e91a3172a2a88840109ee556a513227af985c616d96fdcec70
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:ee87733d47d696633bd7e8f213d1c456119500057be4ef6007ffddca01f64a38
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:79a3626bbd43d7ac70f91625fca74781149a4977dd89685e8586643721c5dc4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:5ee50f7cbd431ac4a25abf1e4f55c8ffa78bdd85e1753d508e6d23b1f54a8373
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:d556c55dbd49f40d55c6078f2696affdbb562fa850a570db54d53276876e41bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:d08ad802a725c2b4a2249f78a4b2d11e90378d81291ec557b3b68935775404be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:a82d6399c6f3bc94c4af8b6b6ca6a4a29c04775d3486e9be20138d64c017d3c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:34497e2e32f01d69e6256cfdd6fc57133c7bb7bbdb7efd0c409972a486aa6f5a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:e514949999239edd11f25e58b140e33592e08ec84b72b7ed603f39f42f402a5c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:bca9d67af308c0d1af7432c262a06646779758b45aa30541f7283a6c1142c382