Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.10 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.10-debian-php8.5-fpm-fips, 6.9.10-debian13-php8.5-fpm-fips, 6.9.10-php8.5-fpm-fips

Index digest:

sha256:d781578defb7e7e98c832fce702bf80956a9206a4c780e3e64a6f1b4330a5f76

Manifest digest:

sha256:0a129bba9d6a984cf2d80492df220dfd363c9d45d1c7e0b6d22c8c9de65d3ded

Size

115.43 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.10-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.10-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:5e20723522dc763e21c6521929cfbd0a9872f6fcb758a7c11c8fb98b295cebc9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:c466eea3722cbef85961779d3481ba4d9f1dfda9d4becf19a89ed712478c17f0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:9bf4bcb8747802d010aec3dd91db7ab682b1313ff93ee667e314dfdb0b62d40b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:de10d0721e3580962121f816c37829f3574510fac3c27d8df4f6b3fd121120a9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:09e2f4723ef125d66a14c60caf9b86b5bef66614a7a651c6db7b6697f4996131
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:63e0b91be300081cba811cbbc929a393dd615035da2052f39b420763ef7ca14b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:096f07308a6871b18d61f6e4fd162043aee205f330b723eefed5844393ad61dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:f87cbbeecc6060a7b4b34e49afd50b520d69b4b70239b287d018fba36ace00ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:da2b57ce70c88d8f534e167a34cbca2cc6c580db3b24ce8b25cbb157f20faa44
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:74f1dcd9a0250eacf2e34ae13e9e44ec8657cb384268b90f7ee30d7f92053794
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:d9a26b1d4b2d1d24c212be6beacf171780f1a51f83b13dda48d70d8c23eed89d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:20ff4638ec8b2a8922b99514f0580c8b3c5a0d0b9fc52b7726449037ce0f3137
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:a52cee2850c23376d0bada7933b010c9d1430f4ee09be8918f9c3cd36f34c40d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:31529b2c14a9afd8f4f36c21f727aab9ea36259649f33af599ab6d314e82a438
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:3bfa6e829aa115a7309082bbecbfc1aeae6bee3bfbd41e591b43e9960add58b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:efef3c287261065c1100ff2ab02e473146eaecd626c3a85f07df489adde7291d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:536950cfa103b67098ec0233cb8e2fdb39edc0f9fbf07f37cd2770be57bb99cc