Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips

Index digest:

sha256:30df4e70d64ddc0a931cf53aef0f1c638eb336be21ad69c7df44302295a99321

Manifest digest:

sha256:863a0da24ae9b0bf9f935ab4336e2b19c21416bd3e4912cc474ce313378ae4c2

Size

115.04 MB

Last pushed

14 hours ago

Vulnerabilities

0
4
3
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:8d89a659e8da3398f7f679a0927b496af7c57afc2e72f20e7f8060d0470ddcfd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:5ddd52c0e6ca66d3ccd3e371b66e50342bbf83d32c6f84e7f90a3f23fa82b92d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:44cc53ef57e79b16f57358563bf8e7d676ce63832f090d5eb780979eb52cf40d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:b31f5c5ec2c52024ff69c12a9672838edea0f98b094ecb1d373261e5da8c56cb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:12aba0a4519389656bfa811a62797155745a09100ccc09ad7387293dab3d1529
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:3cf35ef503c437761dab9ba42ea93908d346bad63e81d6a4b3dc7b395cc6cee5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:6395ccbfced25efaf3e25f7755af315cd5578d2c00312ddf36976633b548cfae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a3d49ceb65fa0755b0552b2e8da0a8352625c2e2f20e33750893e9a9e2338dcd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:08376f394629015e05f62c340fb4136368fd87f156996dc205f1e73065384a22
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:6fadb5c23aea1b126653215c145104a4d86ac3d585e05d783f2c8d31e8f7a60e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:d51875fdb0739ef7bf21350f7219f8be917cd01c4fafdf066071961bdf83f6c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:538826014f0b2c3cb28d7f75a30465777cbaa18fedfc9663e6c5f98401a9ce2d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:f7cf367c128752d16ad0190e5c5bd2092bf03aa75cb7ffec1621d805fee23563
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:1258e3f270f7929d7f64185d7009e689af7284dc6f6ef7b7610293b31b8987cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e74cc6c8cbc0cd3d5e60f8631ca2a57c2e9d0f05874a92fcf656739266b95fc5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:4a233426ff6bbd33f6a91bece83d41695dc971a8c8315c805d80a617a41e97f0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:b3f9b80e5eb1da4e284ade55bbcc7eec7963aa9ec3dc2879d51013a164e22be8