Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.3-fpm-fips-dev, 7.0.6-debian13-php8.3-fpm-fips-dev, 7.0.6-php8.3-fpm-fips-dev

Index digest:

sha256:7189d275552899c36ad139214fa08757101c31e7fe62308b80aad00dd904ded5

Manifest digest:

sha256:ec48a81c6fa66998fc9f0765cfacbed26fb68a44692889fa679b47f07ac17221

Size

120.32 MB

Last pushed

15 hours ago

Vulnerabilities

0
4
3
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:de15b24f20f47fced092ff2875061b43a9868a2da8756c2ce2c52dabfbc9b020
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:8d1569a0ae7968a6aeabf19a3a9ee53f6300a801d474ba2b600f243a15b2d061
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:4c34eaf3d9d6f1972f25504446348cac13dfe3c68c6ea369dc905727ce9fd40a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:b70b299aa3dedc6b744883a41a02a51b07e3979f84fe598b539a02a6cf101ee7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:1c904f2a597100ca29b18d58fbc7a255eeb57825c090c9483e427ffcc01a9a82
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:3decb804176a28690bb6d2db135b0b79b4ecc13c6330e4cb58e9c0a438816067
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:3699c2e6779ee8040cc095b8a55438265e671698576807ab6c3bb0b2e0cd46aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:b3a1939de7636f3d2014b6b15c36cc9f6b2e1dbb2593d64f78ae84ce975c46d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:a4e6d89f74503bd82718e0eceffd93ea65b216f20e99fbe3439e061d42493f31
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:755daebcd4168c2247683ebae8ae2285183c779b64731e7ee9d2d8cda9a58b12
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:49254e244f55061d7eea5361b3818124d00ae4bd1fac15184bd065402721a98c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:b9a73919dd8fa5daf2c99216a71402a4d0d1f7113753d17c506e822dd24608b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:ab9a84d9378b9cb774407b4437b454136704b185cd35b49d4564d8c4d2d5f099
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:057f3abbd13c2ce2aca1f2393ab6b94ffb69c3d4ef99e5681c04ed21512c37db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:3671177ea56da752daec1ba054e437b714fa28d4715a790e23d2221c48325b1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:039fd59e5bf1e6a3f73391ed6df8f03602b41909bccfb971e5dfcfd88a9a9699
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:7417b2c1be9d4228569994d12c7860f333f00156e60962158ec96a2a03e4356b