Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.4-fpm-dev, 6.9.9-debian13-php8.4-fpm-dev, 6.9.9-php8.4-fpm-dev

Index digest:

sha256:0e1e5c164382b1dbc9a04e6966b244bfbf7c2d6cf2bfad7e26d7711605348b52

Manifest digest:

sha256:a7290368809f11a266f4f283cde903428385f7e8581de66616b96f6b9716015f

Size

110.33 MB

Last pushed

23 hours ago

Vulnerabilities

0
4
3
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:fe215a7ffbea4555ae495e26d21f9821a67a73f479b18d24194715c696ebea6e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:e7753f4c5ede1100421d3afc1e310f2471f22b69281db018aab4f98ce9494c23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:47ed347757910a769b3e4bc895929b7285389d41d5c80ea546a1b25cf7821bf3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:2be7f81eeacbf794b59e252b765b78310f42a903a00c09ff1572b4d2f0d209ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:35edb72164061258ff10f7122ed0f775b09fbde34fd0b9f1b7906182e2e3bb98
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:ba0ef06d0886de1fa5107f2d03cdb59fd6f642fef17a4aab37f4e628de16b040
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:ec4973d4a29adab4df7f7ee478de7abf924214764933077be2909522a42d8268
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:49e944c5587643cd739f24e903126ab67c5dd57c3cce03584d7c877c03326b65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:47bec30898d22fe31f47d667bd2934af482626b1f6a8aa017d883eb08f03be9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:9fea6933228859e382cf4f0845e38a2e61e937d147822e2448d5f6016928f9e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:df2f0fce36d001b3d87eb652e404e16596cfed1ceb8ad4c103f8f016349a1264
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:cc1540e1e05bb2f49d6545370bf2accab794318f42f211a462958f0a6b670e89
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:a40bcd2f2951de21b1da0674a8dfbecf06057c66c104c6192070f9c958cc13fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:479322840770c9c1bf19cb4c6774315802c084bc606ea4eb47bf9e5bb8209cf4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:365b9afbe3219fda0f9f267c49df0cedcfe22c4eeea7ba5336c37662edcf495c