dhi.io/wordpress
6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips
sha256:c301f5b2c0baf5c09fb1577a53352d35d8e1bb78d88d0723e7d9131696559ece
Manifest digest:sha256:cf2094716865cc9e190a8abd14c6a7b61217dae3b39f71a3baec4427f0598bf8
Size
115.42 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:085a7089a644c5abf600c0e26951fea3394d1dd60b3442a57bd51ea3fd947b12 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:4219c93d4320dc20945d368fe972ac2968a6665a52aed7d2e15a686789dbb3fe |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:d283eb0faf346006dba0646ca3f45bc1508f8bbe9e30b8b4965cbb3c8f6e69e3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:db061e521e0f52a62e39b997d0c8432531714482c0641e3c5f2d960b56c85ec1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:6cdb565456e24c9ff98e2bc16bec74e53aaa9fa7a9dead4bcf9f8dc3cb24185b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:1b3827f1d86be202fc56abd3a72bbc65927763f6e8ff964e2d9dd91a61249704 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:4152eee7f349b5ede189297a1629e6d4f36d58eb7ea3897cdea06fe1f169b966 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:8c02b235f845c35edbb1e435034add014273298d0547eb0f85862ce3ec55e27d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:62e950b2d5bfc77ab876dfa8630c47539e217aab60c5e44333736f5932d55286 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:7c0f1d3205223e48c4cd57839c98016cd180e295b26ab549a52d561469f9431c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:044f66cf7b50c02de5ed83276af6233ff715cca223664e9f2fa0cca8a7df597d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:cb066d69c9db910424faa6c83eac2f23752bb05dd69ceef374b32170199e1339 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:a7ce21e1a99e73720a45ef853697eed425a6b11cb949fe8faf5c4badaa026e28 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:c7ee9644b6846e608d6ae7419384bc99e379d434070c167e6b063775a9ab168e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:e932a314217e79a1f00654fc2ea667f156a32ce7f27b0fce81054ba7241504fa |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:287514cbba4b80e6bd9ea8e7a27a9a640f1d28b37bb81d98db2fd8a8dc30c8a0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:246aef03bb3dac04b52d159bea5841374261feee58a72c52fc70c8dcd6725ed4 |