Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.4-fpm, 7.0.6-debian13-php8.4-fpm, 7.0.6-php8.4-fpm

Index digest:

sha256:8c1bf93241f3543efb7a441e5f677281b0c09bbf1598f5834e4a6feb88d9e6c5

Manifest digest:

sha256:b1005148a9cdd61a6c7f9e812d36ee2ed82946ebadc7a5773ea5384d7ada555d

Size

106.32 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
1
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:4236b5e4e131deada4e1a40de73b3aa2d5e19dbc38785363ce6c27780156c541
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:4015850fb30988a2d4094d24206d6bc5a11fd5073979585efeac56e43556fcdd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:0c6647aa9373393c34fe1584e0fc34a5d4abe15e61db23328f03f39a6e49d90a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:a700152d7b7d44804fdc349c3cc76d73df600c4a829a6c8e369cb9bf45956055
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:79d4233674e0a22d03d01521ca1e114b9ded20d04007741c5f636c7af728ed58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:b6b6a2b42b462e9e416291008c9de5278c078255ac4803762a96c5ddc1bbd769
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:d97996ae377796a9e2d1e29b7ea8f72fa2128768c05208ac0a7d2387bb88f854
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:9f42036bfe1c9b061f696669ebe4dac1a94b604cf6892d5c8836b033b11932c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:576e2c3c6d47ad3cd5d0bf6a1b5a5ca699990b3e8a2f626f16e0567bb244b83d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:d6e8d51d1b19f2a22ba8111ac4be56a25e03550604f79ae86928e3e8c9e45a94
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:fcb76bb9053fb85c97b4ec26baa4fd445ee0e4123f83cade5bc3064e5e29f179
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:e9ae4c7a9d8ced616daf2db5918fdcb5955bb03d69f7cf266fc25b8214f29ce6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e9073ce51a12ded715cf30f41ec0cd28964ce81efa0ff491a76c317a49b5466a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:7ac86ca8b9644cf109ac2388fc03b213f07ae561bca16f4a49770feb92a7ba6d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:d191efffd1cd4f2926bd27ec5ecb6df34e5dae331d7be3747bcc195cdbaf3285