Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.4-fpm-fips-dev, 6.9.9-debian13-php8.4-fpm-fips-dev, 6.9.9-php8.4-fpm-fips-dev

Index digest:

sha256:1c493fc0cf6a1459d6184dc5d3cd1ed2b37a564ad9f5b51054dbfb5c3b68dcd3

Manifest digest:

sha256:1fbe6ac102320a8aacd3ed7ce0cde7b2976a412eebb899f15caa2c69cd9cb2d7

Size

120.25 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
3
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:43fab84cd9a0ea156f6363b272a8603ed0c97b33962129e380b85d9505f6b461
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:99f9da493eed52e37f8625f7d9e778c86654c534955859473b10f95d4385f92c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:ac7e8d47628f3d21dfaa84383e2bf1922da085b26d6d8ea8ef0b4a4a7c871cf0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:c3ade2a7dfff4eba641044b84113655e3eccb3949ad1d0bfc0a0c17a62b1e1bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:0d1498fadf2706708501a5a2d70250bf48b623fe14f8b54a53a6a12d431f14c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:cd28df8b8e80141f8685bfeaf29d30bf9a425bf4647527bde531e881ca42bd31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:3f6f14fa158ccb6ed2aef5929c2b47889c1820c84b9673f256daa7d8e8856040
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:37505ef6f1aa2f36aff9bd38fd0de96a3a5b5a461868868f56963b86cfd43c40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:66115c144eb2aa4692385e9d995e2b33801e4b890b357958203aa8bbbe8648b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:d38c6b906fca99a03b97a9a721f61c4422132614a22f2045c67817c10d097e3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:448307abef7259285300bbdb1defc0a46ebe509b1d3b8e5270f768cd282fffdd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:67df6d8f54959fc2aec296204cb09dff971e81b434f0086f02c52a0b10210035
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:37ca93a0bb7d3dba583582e5db1e926f2d3d7613cebbe6bb77667f325b75c52e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:407e4b0371c1366d76df6be51711644dfa08f0d03b31aa752feab503ad2f839f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:6116a84ddaea74c5200b0469f9fbd04d55af90791ec42f9fb687380892c53ed5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:f45c9dcee1ee4fd82c823d928b0a20f02fec96a77cf3872c346b32d9787815b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:efc015cb53958d0d305ed3f20fa335cc1c1950657320381b53aeeb0bbab70184