Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm)

CIS
linux/arm64
debian 13
Tags:

6.9.9-debian-php8.4-fpm, 6.9.9-debian13-php8.4-fpm, 6.9.9-php8.4-fpm

Index digest:

sha256:c3ff965cd8f4d524c731dc2f0ec64184455a47e24b2c75fbe4b13b26dc5c8f86

Manifest digest:

sha256:a0105c7883845910cdfe33ab5dba7bf38394bfb159f945303986e17248f01d0f

Size

102.10 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:50c90d337a30137efbf67dadb1bfe862b3aea192a0ddbf5c9c84fbfba07e1c97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:340b1508e1cd86bbae0ab36a02bc48b088c1b931459b1960fc8de4a768043eeb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:9eeb288929a486030212998986a3cebaa6dfbb0bccb91fac858ee508f1b6dd62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:10e91f6bebbf34ce3f9d45fdbd39a6105cc2ea35e82a5866d0a7e399674d6c6b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:dd6391cee81822d81f93677a06d6227d6682ac0328177192d8ea4014e375f4e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:b2f721622d362a14233d26d98fc3bc9da231547d2c07ab1bfe9267ad315beef6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:7817cc331b855c1317c79f1877d55a4eae882c135fd54707978387243a2d0143
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:b76a1b3c5aabe040a8d40abc64a962ed16c4712e718d1f4dc3e1fedcc18bb951
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:3262368605e71f16592745c0fb28f2432f93621ee31a999e0aaadcc3e9f5fdf8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:60b3b94bbcc17946b095594f3ff58597ef0b65c9bbc2f8a5eaff7e8bd7b281cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:ae88cf5d24a50ffd0fd6abde1b15a83723ab2f4d0d41e7e8051f1ee4572cc5e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:efd089e4dee53188d93d5aaab872790b081908c6fcb16dbc793342bf44d3f932
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:18a07d9f60457ae1e758fca6f67932f058b9593ddb804aebf4dadd2f44a112ce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:6086bd7c8b03d7f950469efd4bc3702ddb0cfeeae74834facf0fb4bd57b9bd39
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:0a092c7aa113179cccd45dec51f117323f6eca64209b04f894f0fdd128a8f83a