Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.4-fpm-dev, 6.9.9-debian13-php8.4-fpm-dev, 6.9.9-php8.4-fpm-dev

Index digest:

sha256:cc256485e749dd40ac0a12d4c8479515e8edc58db6e9aee916bd6a6406a5cca3

Manifest digest:

sha256:f1686b6f96f1116d0c09ee66c809289480fa990e603751c071c8fd92a8d7e248

Size

110.71 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:1b8efbd9de4ca42a1d88e11ce161bcfb034b3be81853e9a9ed7ec7ba272fa6a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:e920b849ba2e696aa9a4ae72a2a45909677d9cb550f8ccd6e060ae68cbe58476
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:d3dcb060dde26f2c218d2b2d0d40f9a3cd4466d981d1d59a61c6ea76994e6a89
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:79e5c4d43d28fa1eb23cac3d122bb28f985b9df6004ce8a3323646b1d17f75fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:12d781c4c73fa3f1c9a178504599ac8a66f3a903a1685e8c52251c616070a76e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:d0f0006495ec3737d679add6b005b71fa6c2a70780928b58f57a552aa577c336
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:51ef222a741a82afbda1a6e40346fef86c49a0b187afbef1f2d84ef656bb2279
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:a7da40d2bd468de9efce9abb48735d478902a2c16fcb1a005339393d87f89667
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:0e068a0f3beedb6a6bc9454b6064b2752d5779a5b3a91c145780dd2fc547ede0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:b0e0fd28a8583fd7608bafa64fb9a4a0b9d9bb800f49b19d5ef92deaecf5228e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:15e32c98b3ce23493226147fc23aa3a16ecf801938affdd997ab90c0f932b23b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:3d3f05515bcf52452af606483a714a345af132502835cc5a44ee5c611f6611ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e3ba41b8ef3161ea4968d9c70f6368c287222c36b237912b04f5088f7f3ff43d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:c22f6e90f08b381c0e86740ef63cbd2a16e7ce37bea11762408eb4fed2d8da75
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:e7ea0a8377ea8be03ea286e01863877f781188db2481d4f83a1ef5ffa11c68c8