Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.7 (php8.4-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.7-debian-php8.4-fpm-fips, 7.0.7-debian13-php8.4-fpm-fips, 7.0.7-php8.4-fpm-fips

Index digest:

sha256:2f409ee77e99b4a4930cc899325133664860ee607e1d13a56b4c2b3e3411230e

Manifest digest:

sha256:d18c0bfd52ad086e7833e56f3247f38842198cdcce7a7285b79052e41755f10b

Size

116.14 MB

Last pushed

17 hours ago

Vulnerabilities

2
4
0
6
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.7-debian-php8.4-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.7-debian-php8.4-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:b127f8d64967bfc1feb06bcee8fd13d9cdbb946463c02feaf733aef815c34ffa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:c43598a4cf98b51f53da4be3c5f141f32474d94ac66faa8e706d5a9b922778f5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:cd039d3e6c563a83b31232956b4370462c9745fa2ffb968c42f160985ad92746
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:921db1a72e5490917ea6b40254cd75044f1955a8544e890a594ff044f9f39ef7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:7a19309f464e0e402fbdfe358e4e1bc2fec424bed843098841c3b4ad751f100c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:aa86928f5190883987801ee436b981d828e8a26d26a0485fbc9391acd4b37cf4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:05065dbddf7a2dc388a88545c79380b6b0a7512e802a42e59e885645b77342b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:0b87e397e20f7a197198fe27d5c5133372786badf4c1b9b175e893d652742971
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:4f36bff33873af661424791b90c76feebcd0109f9062b1582324a35b197ea93b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:4cfebd74ef17bfe89c7f6c597bd4e99789208e31c4bf7e02ea98593eb9af0ff9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:ac7730612ca77f96fcde79d17da614886934c843a23683ee1db5b7f247bf208e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:cee3fe22b97976b63ec756d2ec6789c0110d27ac3a1f89af96cf426c2e7a354c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:e9a10a9c2cdd43180c304b1a42add215f8b05f179796ca768c48fa77de315728
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:5b80f35a214c7ac79ff84d6dc1ac81c105feedee32b0120034b93e04fcfe592e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:4766940eacaad292dcf4dcaafb5892358660f7f0bf1173b7eea51bcbf658ad50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:0d6994f5406278d3a9670bb356b702d4c3abdb74275ce6fa101865676077c112
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:5bc0f8c00bacc8836b64af3c1fdd5f0376039b19963b632e130b469b2497ab6e