Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips

Index digest:

sha256:c301f5b2c0baf5c09fb1577a53352d35d8e1bb78d88d0723e7d9131696559ece

Manifest digest:

sha256:cf2094716865cc9e190a8abd14c6a7b61217dae3b39f71a3baec4427f0598bf8

Size

115.42 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:085a7089a644c5abf600c0e26951fea3394d1dd60b3442a57bd51ea3fd947b12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:4219c93d4320dc20945d368fe972ac2968a6665a52aed7d2e15a686789dbb3fe
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:d283eb0faf346006dba0646ca3f45bc1508f8bbe9e30b8b4965cbb3c8f6e69e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:db061e521e0f52a62e39b997d0c8432531714482c0641e3c5f2d960b56c85ec1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:6cdb565456e24c9ff98e2bc16bec74e53aaa9fa7a9dead4bcf9f8dc3cb24185b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:1b3827f1d86be202fc56abd3a72bbc65927763f6e8ff964e2d9dd91a61249704
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:4152eee7f349b5ede189297a1629e6d4f36d58eb7ea3897cdea06fe1f169b966
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:8c02b235f845c35edbb1e435034add014273298d0547eb0f85862ce3ec55e27d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:62e950b2d5bfc77ab876dfa8630c47539e217aab60c5e44333736f5932d55286
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:7c0f1d3205223e48c4cd57839c98016cd180e295b26ab549a52d561469f9431c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:044f66cf7b50c02de5ed83276af6233ff715cca223664e9f2fa0cca8a7df597d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:cb066d69c9db910424faa6c83eac2f23752bb05dd69ceef374b32170199e1339
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:a7ce21e1a99e73720a45ef853697eed425a6b11cb949fe8faf5c4badaa026e28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:c7ee9644b6846e608d6ae7419384bc99e379d434070c167e6b063775a9ab168e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e932a314217e79a1f00654fc2ea667f156a32ce7f27b0fce81054ba7241504fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:287514cbba4b80e6bd9ea8e7a27a9a640f1d28b37bb81d98db2fd8a8dc30c8a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:246aef03bb3dac04b52d159bea5841374261feee58a72c52fc70c8dcd6725ed4