Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.4-fpm, 7.0.6-debian13-php8.4-fpm, 7.0.6-php8.4-fpm

Index digest:

sha256:273dea0f15cc2ffe6e137c5999c7cb8a1eb2e507571abd621536b5a098481e03

Manifest digest:

sha256:a376624c68aba85f5ee99bfd6017d5a4bc082917a94e24e59e41e01473567e5f

Size

106.32 MB

Last pushed

2 days ago

Vulnerabilities

0
1
2
12
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:e175b2bbc32dab6693ec6c08b7663b8f7d1a9d928cde0310a8871c1399ed8d9b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:cb3cb7a4542f1faa86afa4a4ccf93eb4c69e3c4c814e7e72156b4fcee19217c1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:ce44c3e5577ec6c90a82dce42d1e6176fdbfa17b0a9b96c3678a795261efadcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:eaa31b957791f9c6b525494baba895a92b47b17193ba98913206ce7e77f5a291
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:83e469aad5b17da62b2c2e235d2d203c762cfb29c91b6f22d8283ad4e54d1468
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:3723e9c7aa4e95722b9331e4672c2de4beaef4776854df5229f56fc26ffb23ea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:8d8246190f9b499edcb98855782b42160adafcfbe077f4a9cbd509c82f3fea1b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:5ba6e793397e9efb5f3c6fadca9d86468287046aa256967c2d86fabd18ed5d88
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:ed8135ded8c4951aa8c514d8123270509411ed1ca6423ab3e4ffba809f72b28e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:0a87ceea98bb3e0bbd155be6ae5afeadb6c02bf97bb7dd601ae9a13df2ea0eac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:acf9b671362c9f7d0ca1c8611a7998502aa9c02e41044aad7600e7e8a3163ac6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:3589a57b0446eb4de6620c0f36920b5ceafd6cc020b97a681da7ec6c5884dc9f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:bee6425fd5af7235fc73ea33dc83dda62b0f741e1a1add89f987389b5345bf58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:79d76f11d507e1c693aeb105e106cdf342da29e157b7a5c3749c0aaa474139c4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:45195c1766a26178407d548d949f5fe576792478ec01fa983c8e4ff290988460