Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.5-fpm-fips, 7.0.6-debian13-php8.5-fpm-fips, 7.0.6-php8.5-fpm-fips

Index digest:

sha256:bd3d876c9e2b848536e9101da3533fc1fbcdda4faf831f83be733b9e35c0991c

Manifest digest:

sha256:1843adf75b53ca191014d2750cffa0b996f14243fd7de889fbb9dd8819b37f8d

Size

117.25 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:0fe61cd05c0309cab612d520f29aa57dae0ff98a11b6ea47baa6869f35f478e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:ce0281b59e8e3b441d707c9a5403db8a2f0b249bb9e9d01811be6886363c210e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:73d3e6561a69f6ca586070990eee5dd51aae677372e9281da50de5a5f9982bc7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:cacf947a31d90871f168550d4d50bd1f9e70dbf0b53571134bf1fccebbec30e8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:df9aabb6d62089ab988b7294962adac35b7466d861e79999165a6fa21e250b8c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:f2ffc249b12ddc0005e87d12e23b6fd0c14d2a765138ca6d9a6459d882449b61
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:feb0c5fa3d5e34d577c37ef25c1f67cdd70febad146ce4cc27310fcfa22c6f55
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:8ad1876a92d12c674b4dd76f0670c9c10fac30f06301e06d92adda615c97ce02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:771a79708d50f0a6f78014709609f133e723e6dddb6a2bffe91bbc53af34b772
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:738784fd4d90c25681ff62f21d5ea2dd52a41055f956e3afe87bdc524caffc67
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:7ff4f32475dd2348d51b4b811f114804d6614bf99001531579bd1fef02a7e2c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:b009f104b9a32a542818ee30dc4281353ed9cd7919e59c375793340cb74485a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:ab7f4eb413c7acce27e00743d5f5a760a2ee6664df1c7812cef64bdaddb4307f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:5e7119bc73fa74501725c0d0edaeff7b46ba53b539b82e240051d676ca6889db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:ad10fe619186e224a2903784c0d439319d5076cd1c161a6a04d317c9d764dcd7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:1340218d407729fd131f6d0a4e6a4c576a654d24e55aefe171d2af80f8725627
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:d8ac9253ae1b7d4b142c2a35e1b72bd3e3cad6bddf7e1328c3bd5b16f37ba4e6