Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips

Index digest:

sha256:c7b09a8c6da48273ef8a1e5b732698b6e79c91effb915e08fbc25b77e153cb2c

Manifest digest:

sha256:ef8c4c830eff851d7e1458b00fd1b168105a0fb4e000d4240f01dd6780b48566

Size

115.42 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:3def630d521b13da9f0dcc1c1943eb52ac0e00cc245cc935d7eb7e046e899d3a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:3a8e6ccf1a9c0344f5bf5e29cef1a22714adef366249aa7e0cdbacb154eee1a8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:d95ac1c59b043c5ed458a6e359b57de8cb6bd6bb138304ccfa247d10007b5e7a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:c7700ced672c091b2dc01c164fbb3198f8c7868152dbdf662be997447a0e6951
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:e7277f1160fb9c0e9e6114725f4e7a55123ca067d853c738261384d432c392e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:50653c161a3e0b6031198940e0bcba53b6a6b6ec8f9bd55046883c09c3e97c94
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:b2abae03d403b683b00d68c6354e08727d88c37dbb1cabf4da9e0adf6f419632
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:1f104eabd9eb54326a59353b1a2a8a765cce2ac063746f81970660fbf7dee191
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:b458edd98f505c82978792a2fe7cf354441449b8f8d86b4b4ac1632ff30c0da4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:b530b207889cd8123739e204ea74607cff5b487ff82b52c1fce94604967893e7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:8eb2535e8ab9a43f12713e41371330a6c29fb731d5d85960c3319651d9dbed52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:f8fe561f906d11e3a03fba817f744c528c781a74ccc2168c74da07240053868f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:5b053000c0a18cb1fa22b275392f6fd3d3f7150ac22069fdafdb791dc205a456
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:42eec644f5ee6fd4d40e41a681b7a99d3cd1f2634c7ea1878ed0b72238c88ca7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:0bd8cc6a56354ae462c4cdc577a0c5769e14784bb5dddfd894256934a11f664d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:d4a59bec682ddd7653bc0249415d8dd8023eba76443daab49e4cc81164198006
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:aa3c4b0f42f1feede281a3afb5b0b254d102cc6ab216788f9437adbf279adbbc