Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.4-fpm, dev)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.4-fpm-dev, 7.0.6-debian13-php8.4-fpm-dev, 7.0.6-php8.4-fpm-dev

Index digest:

sha256:bd228f406050bbf7ea6a8a049ed72806e98ba7ec3e8926da03e061cbcafc3e1d

Manifest digest:

sha256:dab00912e2ad972e553b3f8feb5166b92066814531b5cd674f4ea23d9b05d714

Size

112.55 MB

Last pushed

2 days ago

Vulnerabilities

0
1
1
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.4-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.4-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:fc3bb8c83b7316bcc5155125af3cf9c66f41cd85c409e92dbccd0be6772456a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:35ef1e61b4a7aa93ea46a8752869c27ac48a4bf6f64be93f1c5d0e00b2805197
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:7d4d9df3da9e8838b531b04f80f80c4f9634e5a1f64851684115a709a7977db8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:9d0dc51f8657db3b611b110bd154db4909d938121c3a32104829ae7fc8e30f6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:d8cf57691559d6d21678796be8cad2eafd1d8bf3c51b0d4712221cd8f4090e8d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:91e65333a18129a8798571c1cdcff6dcd51130d0e2c4e5cf679d24ba5f31ddbc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:7692ededef4c365dc4e7f46a931a638d27035e6b8cd6f50c4065b23ed03c2d83
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:ea2cdb1aead3edfd02d48d48962f637da2ce9f29720db39d2a725b2cb1406aac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:ffaeba2f7135b7e65ebc299e89954bc871b1701af4bdf2fda285a26fdb1e63dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:a9246cec46364a7c55a1a1e1568faed8c23cc47a704abe4c7cbc323107d87e5c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:56d16635df251c7c65c7a69d434a52a068934ede0829ad08048aa3ebb53c4a94
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:ece556922ba174102a224979611d0db5e4fc8a860318a8e8088387e85783ebb7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:075751f55e4d60498e09a755613b36e78f3cb03336adb09150a3363461ab1862
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:408668b02f07de6f5fd01e26946a0ea6ae22dc4b644876de6f2c3f0c33676048
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:352e2734fca78cb6dcab408fadfcf6ddfd1919c61c8d2560ed398fe1991bfe37