Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.10 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

6.9.10-debian-php8.4-fpm, 6.9.10-debian13-php8.4-fpm, 6.9.10-php8.4-fpm

Index digest:

sha256:c1d0168eb969cd33508151acb9a161743b8443c39d40d1210261d12935a476ed

Manifest digest:

sha256:e203bb01d3ae62003fcfac8f02291e3f6e038b2713f2518fa5834b494f1d2b38

Size

104.48 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.10-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.10-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:25b11e7f554d5cb7e863f7e71ba44ea67bfb241fe8dfe22f28d3351fd91aeea9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:2e5603e9960cf13df1cdc52c76c47ed0ea4f5557a033cfcdc5fc303d21bd608b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:1b29bf9c63422a0027d68776b753baecc4342f76e33a42c38a147147e81043f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:2c8988816c7824d540dd98ac4dddaa43bbb9141d06ff8253d5a30ae87c094123
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:dd6d2853bb031d25abdac772028fe4a70f081fb6ba3d7b6b8bd2f0180417dc73
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:8fbf2f1f2132e9e4cd1a8ec0ac2b868b65bb96a4d36b79ec07e76077c798b545
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:94cc446165a95d4bea69e1c3bff3e1e9d69b6530acc1f70517458178e225821d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:32bd4f962c51a54fd03f14a6a2afebfa689c86c2745891594d45a467f7427234
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:1d3d7332677a4248b43b692a0f6a9582cb88f48949d675fe2dee8552e3d354d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:990f0b04506d8bfb7c127a27dffaa2f7396d553b6293370513f05d217682d132
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:1152c98ecc022f46d8304a5d8468c2e0fb5973b71a1b3a2b43af44875a2cb848
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:abcc93471d29acbbc4ff4ce3da604a93b3a5cf323ad2a1e89cb08c0905a49c11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:fc7981d03e16530e856400115b5b0dc432c2443a4d3017925fbf9c7697b0ddb2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:e3886214cb0f0d9a89750f4746a1d3a4b7db26a969fcc754121ed35eea975dcb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:7c5cbff42815ca22447a168e44dcc6a6b9c10b54602098b9a77b239cdb2ec4df