Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.10 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

6.9.10-debian-php8.4-fpm, 6.9.10-debian13-php8.4-fpm, 6.9.10-php8.4-fpm

Index digest:

sha256:7775c78d61224f462b696944a52d6dce77b22a85c4e633db53d6e843425ea12c

Manifest digest:

sha256:545d47923fdb05497e835e4aa91be6e078b6e9ac539b951bd1d45dd256579f64

Size

104.49 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.10-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.10-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:d6717048ee761c3c9bf59e534b07fd5a2f4a47ec93a01ac94559e3e51466b5f9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:7cc3a78d868f0bba3eb5d90dc41bc7c7c0f43028029f2884e564b7457c0ab9da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:9cb29006ff1b65fe8435e0140b873eb4c2866059dc90e141562c0684b6781cf9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:e208d9384676936e97cf215e89dafa4621ab5de461ff8e2142226da3798ea172
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:3c5343e9339f1ce6812a3df34ec5c7d7f270a4fba1f6ce40be2cabefe4a87341
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:621e0566e73eb3005291ca6a17d84e925f9fbf14b6e08f930b668d0cd014f2d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:6f82f52d3f104a4a9559f80c41537a9e72f07cb78f5b35c55dbe2c65cad84a91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:7324b88de2bed5440ce25496232a196b7c5f6d4b60bac2dc348665843f371319
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:a34163212cfa3bb223a3cd0cb1792189881b90153125476b0f58d1e7f17760b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:05bfa8da3703e3ac51479409221cc27b6f519f8a8998a330b11e03149b770bae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:e7485a8c443892de5b1bf7986436672d7b464c9f214ef1371c80abe2e5a44624
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:7057aa748fad1d747c6b0acd6ae6aa68753ac5a368bd938c32ee08ef766ce53c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:97619d646430f346c72b61cf28da1f9a3a67365cdb2c3fdcc9f89c68495bb4ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:b1a010ad2997d1340992513cefa826ddc758451c95b64bdd6165bb98782d5e49