Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.4-fpm, 7.0.6-debian13-php8.4-fpm, 7.0.6-php8.4-fpm

Index digest:

sha256:dd0465283d3ddbe69da4e206bbf2ad642eed2448fa0a718f00e0812613e02836

Manifest digest:

sha256:97059618966eaea60319dedb9f881de38264d56c875236c8ab370da35ed29d76

Size

106.32 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:b41b4e151ed0889ef8fa7105e2f830dbdaa501fc6fc50f8e95133bc4e038a88b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:22df729a3d6ff73a0c0db38043530acc6c3a51436b9811181236fb118f290772
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:9fa468c12c159c6912b6ea44f09e8388d2b4d71abe87404d11e77a8b91b05313
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:4d0f967e12ac61913d18144bacae8855bfc4a48b9e64abb2a738f533028296ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:d8acf1dc5b818dba21b1c138ce3ef74bd02ebc88b8add2bae00d3fe5dfce798b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:12727abce7d8a635f9506127457498434be99cfa742be7e2ad7ff5abc1a9c93d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:eaec9e5072b94209a9b6b1c80d011d39873c3daf2e07bc5acac3bba6773329ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:f30d1726f36a07752a7cebd9a6758e09f8ced5875726fea402cf9095a79605b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:5fef685c6278a01cf4f2623869a556ed76f772a4039b65fdd1c42f991d60c1e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:eba169d2e81151a7985e88d287285509592559ecd944eb2c7f1e4860ab234230
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:0d923939a30eba8cc1e61353fa763b451648ca897844b8c470887b2b6241bad2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:ef536165d262d68d9795d0b7ffe8a52247e3b75726210a391d506eb6d49022df
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:87f15bf81897283ba3db123a57e5755af1030858c5027c148dbf95a2fdc07f82
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:c12d84bea1b56621c14f4e3dd526841eb67bc28608bf7b384822fe7529357c7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:bd277538f82fe0d9150f3035cd84b11541df114ac18eb50bf2ad8bb225a39c66