Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.4-fpm, 6.9.9-debian13-php8.4-fpm, 6.9.9-php8.4-fpm

Index digest:

sha256:c3ff965cd8f4d524c731dc2f0ec64184455a47e24b2c75fbe4b13b26dc5c8f86

Manifest digest:

sha256:f1ce8c6972a229b22bf0d67aca4c981ec39e74c564cc85d0b5e0f5ce8bcef275

Size

104.49 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:d60bed6a1ff1185bf377fef0e1ec1e72fb5fe822172a2e4caa524fac3e5cd4b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:07b79e27f7446c541e5980da3f8fe40601c329f4d1dedb3e07b5c5792509cb82
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:9e84e46ccb287e41756e5fbacec2b51ce2992b62c883b1eaf5aec4efe7afbada
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:059a5715badd2cb8e6c14b9490f91d3e014003933466f871cc7677a8bd18ce3b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:4399faad05c063b60554a77b09db2d180b7f386d67810e3c8163bce927e45113
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:360dd298c20407d6947a044a59081a16e35bed3af3db6ebf4360c368a851f75e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:0af88783ff9879fd788751a5fab4994e784980f06fb3f4745cc98c4196750f14
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:66d6da70abde68290c72a7e857b28542c19028902adfac624b46a91197722489
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:f70f886d233a7d8671de8819cfdaae3809dd49f33b3bc14644e6ba321107febb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:6f31c416e23c4f3af07d58e50765ef20c0db4b3d58cdd65db58db32ab5813c65
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:e6acaf0e906d7d42af17a0feb4838fc0007e72bffa90c708eea8c5c294d0b7d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:d5e474bc34c260eeaa8dff58524501760ecc6a4623c0b27fa404eb0f33848949
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:75fee2eb682f482b9a2c7dfd3377acddf199a843f57f67481f9d95e4501a104f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:e6ac4b20ec1cb7cfcb1a53cebf5381a42b208b1ad0c67952e6369fa2d482171e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:f684edb52c36b508adc6f8c3f8c25725d18e48cef0474bb103e9bf9b9ce7f4b1