dhi.io/wordpress
7.0.6-debian-php8.5-fpm-fips, 7.0.6-debian13-php8.5-fpm-fips, 7.0.6-php8.5-fpm-fips
sha256:bd3d876c9e2b848536e9101da3533fc1fbcdda4faf831f83be733b9e35c0991c
Manifest digest:sha256:1843adf75b53ca191014d2750cffa0b996f14243fd7de889fbb9dd8819b37f8d
Size
117.25 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:0fe61cd05c0309cab612d520f29aa57dae0ff98a11b6ea47baa6869f35f478e0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:ce0281b59e8e3b441d707c9a5403db8a2f0b249bb9e9d01811be6886363c210e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:73d3e6561a69f6ca586070990eee5dd51aae677372e9281da50de5a5f9982bc7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:cacf947a31d90871f168550d4d50bd1f9e70dbf0b53571134bf1fccebbec30e8 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:df9aabb6d62089ab988b7294962adac35b7466d861e79999165a6fa21e250b8c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:f2ffc249b12ddc0005e87d12e23b6fd0c14d2a765138ca6d9a6459d882449b61 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:feb0c5fa3d5e34d577c37ef25c1f67cdd70febad146ce4cc27310fcfa22c6f55 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:8ad1876a92d12c674b4dd76f0670c9c10fac30f06301e06d92adda615c97ce02 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:771a79708d50f0a6f78014709609f133e723e6dddb6a2bffe91bbc53af34b772 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:738784fd4d90c25681ff62f21d5ea2dd52a41055f956e3afe87bdc524caffc67 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:7ff4f32475dd2348d51b4b811f114804d6614bf99001531579bd1fef02a7e2c8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:b009f104b9a32a542818ee30dc4281353ed9cd7919e59c375793340cb74485a7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:ab7f4eb413c7acce27e00743d5f5a760a2ee6664df1c7812cef64bdaddb4307f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:5e7119bc73fa74501725c0d0edaeff7b46ba53b539b82e240051d676ca6889db |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:ad10fe619186e224a2903784c0d439319d5076cd1c161a6a04d317c9d764dcd7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:1340218d407729fd131f6d0a4e6a4c576a654d24e55aefe171d2af80f8725627 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:d8ac9253ae1b7d4b142c2a35e1b72bd3e3cad6bddf7e1328c3bd5b16f37ba4e6 |