Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.3-fpm-fips-dev, 7.0.6-debian13-php8.3-fpm-fips-dev, 7.0.6-php8.3-fpm-fips-dev

Index digest:

sha256:4351e0c79f417e8ec3db5a1018e74e1fefc80446a0a92a917553c708e8a68a75

Manifest digest:

sha256:d4d94b04e9777ea838e7cb87194660fab3d72d25503fa70e277aa39f46dff688

Size

120.66 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:267e4360962bb04e51a49a8ac39fbe8799f64b8cefe4c8e96cee834b114c489f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:eeaaea3149173cf2d2716663f2572af25f9270b6ac1d483bcb94e4e04816cac0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:aa213314f520aa208a70f617a667d5ae9031a41aae544a714bab83250918acad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:94ac6cbfd3728581d97bc0a65d6d250262ee9ed5d4b2338a19733c06ac48b1dd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:7427262ad0df6dc6860c8c0771d10852832fa03a1b6584ea371b268bdae93dd2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:b8ec5360e66cab2755745d484d31e7158f5c9b10fda433f7a42b72a16738b1e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:e013cd969595aafd9e4a1558d22e30789040eec6bbcd72e78e8c2a577c96786c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:85403912fadd76a4633936420d2eda4d06396730e1c76f7876acd47880e88c4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:013039fedfb9dca1d92ca2825bbf7878c4d2a5f9946bf8f6c0ad6af30dc7648f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:3bfb9bfc0fe154d89ec0db5475dd6b32e491d12dada0c8acb1d5ae85ec16cdeb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:69196efc2b54f666da55629e28ba51e7d23850929f6bba821461ff50a07e9017
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:c9bf3294a2f6f5f915aa99abdc5a950d2c94b09f3a505a9da973bab21dcac749
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:46b1994372c09562fded297fcfa1058e7b5f09feed714b8ea97a22ea3068834f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:591ee4325ca9103d658166223eb018452f7c73165ca351161db0c74e25a9b871
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:9fca8cb7d97a6518dfd9aac999ad5e85f7750e0e7ce500f4707cc3f39ed9ca08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:b4651be7592250e3a1d454b238956ed199a1ef44363de1db686bed114a7c7737
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:ff6d13eb8b2c9a785382f7b4b3a75ba144a5c3d700ac9663c052ccdf7266321b