Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.3-fpm-fips-dev, 7.0.6-debian13-php8.3-fpm-fips-dev, 7.0.6-php8.3-fpm-fips-dev

Index digest:

sha256:36935e23ef3db686472a06817ffe14cdb787262dcc494ef9c415ddfe0ec25973

Manifest digest:

sha256:91c9342e52773a884cb01309e9c4727c4a782fd0014cb3b7737b4621895515e7

Size

120.67 MB

Last pushed

16 hours ago

Vulnerabilities

0
2
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:a04750740868858e362a824658345afbab7ec4d1389b4c0f7a05fb8ad0ae1d82
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:5369083571816c415474426034ad55bf32373bd4a78912705c83ff10756be5e5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:c534c349879e5abeb64401a1aec97343fc72542f35b9093d4a27e8e07cc3ce36
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:578ff5df1127b3d84b31f4a04fb54337114483a23deb43545858c810d8b628b4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:d0ad3008259a27d44d5ed1108d097976d0dd4e92db491d390a3e57264924e012
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:bd50d6f6feb5e6a00c381b5d70531d62fb0ee9adc7aacb510ab7d6df47c31a31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:be9ca2f45ea22e714350ed5626039ae170bf120742d57674dd28fbaa1b5cb7bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:0b8aca55786f0f566c9e2eecfa112d74ccff77733534139bff0c599a017dc5cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:f640cef75a4c12074fc095dfab7d4d6d13db5081fdfe9725949c669b8045afb6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:87860935a08f61e8af3f0f6342e4864698007b588559f4b365a5c1e3223363ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:f729828bd7f195c200bcd7393ad33bb4cc4db7d01a5b4bea367ec3a9d79fdde3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:4ddbbf08dcc522c6e647457a3731c8db3937618e476e1fe35ea9dcee34c0aec9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:6c3883bc6bac9f3b93254bb86a64445794bb5dae4ab68c5247e47179d3b9eaa4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:07b95fe8a018619a5d4e1f3dc355aa7d2ea75fd68e055d65fec8d895eab4fa7d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:fd74c8dc60bfe27a1de372b1c98d5620c013aa69a74fc7f04ed4f6cd5daa09e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:417e69af7eb4fdec71f31a092900cd2effa03fb50655872be988ccf788607b9d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:cf202c72e50c372d5e4e2cae15677b6f7dab2e99794b52d4e55c38d635e1da10