Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips

Index digest:

sha256:bed20e42da7f7d9276e128e5591a1a8b3a66e144b48534bfbee2ecbfbdf1ab86

Manifest digest:

sha256:0e5318ae6d4000f41e30655c6e7dd9ac0325b02e5e1b9c5fa43924515128c3f1

Size

115.42 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:e300a425114a61981902c62848d6672e89387ece269a277b76d51e8c3c01c7e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:22cf908f30b6270254c0dab5085d4bf3079e30f134131ac55b1f95ad680a668a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:765c8d1b43175e1922ec6db10945cfd0c10fdba52ba72e89999e9cf8c43548e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:8dba5b1745d836daf31be5c26e03484695c9f3c42719e6944cf3ad72721d8692
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:eab9b4c7ba3cd7977e5989d7c16f1d012e9adb5f5ff57ff2c3f6433289bfb089
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:5633780b5187ed00d99573b7c90d700b24979ca53b6fca0af4996ee7d9e8e22c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:e5b8fb1c5590716196db35f36cbf4c1f8e8c53d761e0a40f46dc1724e568535b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:fcc514d2753b0f120b173d1a9cf3e60b195490a3f6d1fdb32ddbbfdc20447f74
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:4ecf572010b0ddc62004c97b00a3ebd7c62c67ed09246726d7e1826e41d28284
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:4211eb8cb500f88f61717eddf2caaa0d6fca3160f905836dd47d5e489120a1be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:78906f5f9d5809a52ca25af8a72620b5d5dece20a7da73ab2ae4903f4a5d962d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:96110c17717f7534571915d7425bd7f773e20abc7fa994b2a1a8259cb4053711
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:155eca7ff14b746d9fdf56a485375f3e2f41cdb9e8c1a39f974e1926039c3302
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:ceb983b15951b12408ef2a2fa0e39a5f6ea9af7dc8164dc7ad5bb036edad40a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e22aef640fa4b3056af0b883aaf12e44304b416a69452e9e34ca16d6a22b41df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:dac9b291d390add1d2eaff0f81a01e8b1b9ecdbee7ba156a760e11a3ae66d326
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:0d089149c85a7c18f9fbf2bd917adc7bf2ae412c04b36b2d6e4e0bc9b38e5fb2