Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips

Index digest:

sha256:40e74a4e48a5e04fceb1a1bd1b6768425c66105c4be7302b6012090b8c143ee6

Manifest digest:

sha256:c71223668d5b3750cd85ffdd3f5f298bbb8d50f1e09a6f3928601a6bb4fbfd95

Size

115.42 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:fe24c455335c21f92c4abea7be7369a8e1885d8e34ec989774243016205b5b5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:5645266db635ff8e75ea099402314357630d5737f3d82b4c9bed12d538dc1dfe
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:75475d361ef4fceb7e9cdde2ee1bb365966aeb51d10867c019f48d5aa04ab5b0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:46bf6edcd74b1d2231557382a031c195235930564f563a1aacc8a6c24ea2e32f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:d14d57829546317011e0dbf532e027762f5f57126a594ef6e5e2a9c9be620dac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:01d316a4848240c868404673101cd6b718e00fdbc03e1d02412593c653af97b3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:afc4934362e437441f8a99aea0a748a48b09a4560ff1ee938819cc88ed7a3fec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:8c7ca0214f4604ca33e1cc71c3569cb503c0b9e79b52f88eb5902cd7f3171ee4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:e797e6f5593f81d700887c3dff4080b74ad2776fc5ebc46dd6ff1d4330f8306b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:9b49dc42837ea4bb3fe0d867af40cec71efdeb6a58b367317c8ff07fc1c45cc6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:6deee307a51b45eefe6a59c65bdac1c5a99631a134d99dd975b5883c33ce0506
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:64989587a414b08ceb955f23ba71784a8b0d6839209e63b3a3714f44c21f8c87
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:a257c36f9d787c0c8f93815f29f7d88108abacffd8860debec9de9b9d8fbe5f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:9cfb559a10dc03f20e7209abbe5b6a14ad4dc8669f2102e9faa65ff6e40d7722
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:fb4c98f1446d870e2ff30daedf9e2505e941c4879f2a2ec27847bb8c9ef22252
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:6af3bffa561c6fb21c7c76c366e22a3c30652aa771e06f9e5f7102681ace4af1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:880c58258dbbf13626714f0d494697170c6d13655b53f08b9a70e1d16bc1069d