Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.10 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

6.9.10-debian-php8.4-fpm, 6.9.10-debian13-php8.4-fpm, 6.9.10-php8.4-fpm

Index digest:

sha256:9143b23bed5d259a380cd9a26f2b24bbec9157c0db51fb0240de45e6e8d94f0c

Manifest digest:

sha256:c73dba8c2c41aa17b152426a93074cfc867aa495fc9dd87500643e8833484fba

Size

104.46 MB

Last pushed

12 hours ago

Vulnerabilities

2
4
0
5
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.10-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.10-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:c042562c31bf3f3771cda70397cf71ac875314abe8f517b7b4e92509a1cbbed3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:82c5e77ba2b7aa115183d062e096fd5be339f2512c19241981b6233f7f5de942
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:51fb3ece71871b24f59430165c208463318b390db5125c6e9dcbb4bf8b0fafb6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:797f54f6053d474809f7aa9e23cc7543d15c5be18fcb7b71dc22e0f3c2dc698a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:bab886a1b840185153124ca8b7fc40b8e8ce11a3ca78791e04315fe1e3d6fcfa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:476b30dc9fe23164d7d7e810215911bec22d4ba2b9a5cc96607d8a228339e735
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:98cbd8590eb1f187507aa50e5a7ee13a364b4b1bfbe11305257fcedddf7bc592
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:6467119790e5c427a49ae3a1835e550cb723a850ed8ebfc31c5b8c085aa15969
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:f6a287a2daec2d38e2ed51021f17643b35a7941dea785e93ca650628ec4fc2f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:67d4fbb842da55f74b8f912b6ff4f36aec377a8c5fd4195da44e72e9198abe67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:7c4e98fd3f90dac6c460d82194ba2a138a955f009a85f05cf833542d1444eb44
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:b948762b25f80a39bcb016412b6b6c318cfeaad56020dca73a44b3ae7523ca21
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:23e4ff6ff8c2d16d1d8b2a6844b7f3743aeaf45076945d6ebdfda03882350afc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:0f489034e408576e1488b65a17cb6ee32c0ef2ce39d64d3a04c74e7dfdca95af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:e30fca45f57d57a3ce9faf37b357de79ca84fbd172f5af70f0c243800ce32eb5