Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.4-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.4-fpm-dev, 7.0.6-debian13-php8.4-fpm-dev, 7.0.6-php8.4-fpm-dev

Index digest:

sha256:31942ef4560f1202f52abb7a06e694db93e879ef2119828534b3e17fbbaeca7c

Manifest digest:

sha256:94794c402343e9b919ce285f8c6934a5d40914c60ab2fcac1d1584dc5ba5b5f9

Size

112.55 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:3e1ed8c5c99a89cd437a48f0a76071db30abddd34fa3de2ef774d3eefbd20bbd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:303795f233042ab0a50ccdd6092eea2844aed160c27799425013822ed6ff11c1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:df23386608395b0bc1cc84376f2d4b2fa472a26bdcc07b689888e44dd0ab8e71
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:983df61fdcf73e0fe07d3fd816526f734f7f9628c5dc8352f14b18d77a137e14
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:419cf0ba4a8676979539bae1b0256ffa8d4fcb216f1b241835520196801d7182
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:785415e353ab0c1a79894f747b53f6f4716552ead05e6da41e5562708a797762
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:9b3db7f8cd04790005d47d321c56f051ef4fef69e5a3693b4182e448ad99d523
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:ac83c3f32fadfd10fe118d848d4349eae171f71fcbb4a02c7aa42fe4635d38dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:6c75ce64c84420ec1567c4c745c40b0c0924fb816a54957a3defa785a3dee356
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:2147ec4d152ba9558c68abab3510acc5c1a0831eae497006f0f2f69fd04c2e2a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:2542df08cab678dde357aaca5a3013ce2eb34da6713b0286100ab7f579d591d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:05f557d66598020d034a2fdd7143e7cdabdda0550acd5e4c902dd8e5f833129f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:eaef199c44483a6495012ee103c808c6a3214af766b18219ba468ad5075fc505
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:9027847e62ce54df2847ba6e7113fc9461ef91d6dd094d94434e4bcff834d2b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:6247b3a720b010bb63afaf8daf3cc4bb5df40d51d9dd992f07643338bfa961de