Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.10 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

6.9.10-debian-php8.4-fpm, 6.9.10-debian13-php8.4-fpm, 6.9.10-php8.4-fpm

Index digest:

sha256:a9a5fc1f5aa750eb2f05eea384b23fe3656a2ab932e9bc29956d9feae904b6b9

Manifest digest:

sha256:e8cc7b92391666e70cdf2e737def4e38cf606a9f85ab6480d4a8e1aa05e45599

Size

104.48 MB

Last pushed

53 minutes ago

Vulnerabilities

0
1
0
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.10-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.10-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:c23c9a8d1d26e68ae0946c9503e0ac536d1ef8afb19d4d96d439ac4d0fb0d16d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:68640a23eafa2d3db40b3b4645cb1d20558f8b7bd48027b6485ee6131d6a416e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:c373e38a65501c0d2d7ec52856d44579bd0cbf6f0af63997934b228507090dfc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:f65b11c0b65a4f5f081e97e92f6046442062032665ef94145011965124388f51
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:176e4da4a928205cade39289095cf0d9668b6c0c88d2c9eb0e11dd5919fc393b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:682deba1fcee2b0495e62c7098ec769b748ab649cb81a7e88757e7e804d8bd6f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:6ebd8f78067faf030dc808df8ef45eaf90adffbcfb225b2103e9ef8d62320a29
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:ad3c873d5fcb655ad4742e3aa497898c5b7eb246b3670cabee1f1cd39cd006dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:f0d76719ee88831566d0527f856383d7309d1b8446df3a40d364222358b54d93
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:e643fa93a169c3e1eacda0102cd1114c3f361388e0199edad1081e5436c30015
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:c4598f8b0366201485e9eb23764d4721cb986975fe5a370171be05a069dccc47
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:8acd2b68b9f538bd8ef693bbd82d7a2757861c95e947fbe47a88d2b6ce7574f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e414160f6069b7b9e8ce5af0939be2e212a1f78988c6cba3757dfc6d4d868309
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:05426da74dc851a0c27ad246d4edaabc924d410ee03b70f7337bb93b3be6055b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:a606b0a3e8ec5eb6137729723344985639dcc66096e2d7ecf05461fbff58bbb2