Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.4-fpm-dev, 6.9.9-debian13-php8.4-fpm-dev, 6.9.9-php8.4-fpm-dev

Index digest:

sha256:356bde4d6b09e1e6d9484d3c09fb63041117570a77fac07ca42309cde5ba8333

Manifest digest:

sha256:eb626de7afbd1b085706782fe1bc61cbf87a820fa9201c8cec32dbad5cb8d48b

Size

110.34 MB

Last pushed

9 hours ago

Vulnerabilities

0
4
3
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:cd197e65327f120118356ff9123adb84dabba1f89417307a8ce1e28ff8ba8d89
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:b1161383288cf3853a4ec6acf5948596e8bf5e1ad4e70bb1f8215451bc67ee99
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:b19ef717f25aa7ca3f24f8a4c45607636639cccd2269e1821c396c9816868878
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:d777784b517ab91f4908cadd55bd8d3ecaa9916bf874596f8ddef92dc1e4f914
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:ef5ca149338d44cd2da92954e6ecd4e2446e5826c1d08008f55305e42e76c241
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:304f9f1a21d18ea394c0ea2f5e34631dff3ccdeab8220fef24b6c0f36738c7e4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:1b6f1e04b9c94ca3f1dd4b3bc95b1be9540e9e7881adafd61081275a9c11a7fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:b29dd6c9939a5ce2b4a1721b71c67df0d4443593691fc43e77bcfa936c281c45
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:aa75149c5267fa02d51cf1ac03df6befdd85590ed48dda62c9ddb76310c4c8fb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:d8d2be1bd9db18f2fb2b636ddb3e242fed30df6ce8d56621f6e6e9e582fef511
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:f1d649e546a14b77b4c7e9cdcb8f2199f81f2750ca3a8e64bb0e1c47586dd15f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:4ee4365adec9ec410b45d07ee1235c4b7000387c34b78da9160ff06eada44d41
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:9ffbf7bce08520d80c19ce68a9ad4c71af2c56e25c5f3b9a8ce86689abf65d5a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:8aa6f4d543c72bfa4d79483b1c53b62d94c84f667b1d4a15a91341dfcf13e366
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:4958c31af2e7f49c567addc7ac9a6d1a6b62bc3fc6f012bf52e27205045d479e