Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.7 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.7-debian-php8.5-fpm-fips, 7.0.7-debian13-php8.5-fpm-fips, 7.0.7-php8.5-fpm-fips

Index digest:

sha256:b271e5e51501b8f7af147edd875edfc3daedd3f77b71987020171d5caf5085ad

Manifest digest:

sha256:2dd1748fba5efba46b6894557a8f8e7df36b423c1ce68e977295e8922ac4ecdf

Size

117.27 MB

Last pushed

4 hours ago

Vulnerabilities

2
4
0
6
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.7-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.7-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:54a868479b4b364598706180de5fcab3a5c54132ab4b85d0ce09fed57a89853d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:87495d3c42c1b39dfbf06277aa04061f82c09a6d3c40962f9559bb8bda480063
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:1b7b8a2a9bf4f25c39c6718fa53cc118858b755a4d04c3ed28cf4d10a4f39379
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:6b3427763f4e5930378392cbc966396fe868e789ea2a111a60ec9fdeac6e2325
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:ad11de040f84a22e5bc8e9c70b36ac32ed0b2d7e0df16ea2186013bf7ebde68d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:3196a157ccc5db4a297d05433dae1ed17c0580643e9cc1e76e6904e77ba5c5fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:d2ddf54719ed9ea7cefb15aee715479dd99162cfcde66591d1ba45216625bab9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:f33a5c6e352b6cabf7d82136dff6363b32affd53b04b5becdfcee7b0d1625cfe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:baf09c65d4c317ec8efe369ca3d0f42c665a80a595c11c9c800aecca9cfc1d5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:e9330d519a24e4d1361e50fecd7f5b37338220b3254d08ec8c37998b030f4448
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:a888d2abc11a2b6aae7ee66b44a0757662b174418ed4fef60cc31f56245809e0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:db57d43f17e7efdb3d945cac863146688f273e444f42f78dd3ae43ad31f5bf12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:5376d84f9a47de02923c79ef8248af7f2915727783ef94efbb4e62e381e668cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:301cfc0037e65d42a179cfbde2c7d5e561ed495b7a1a4159bd1e1d0f25e562e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:35d8632aaf56e24465cd13e7e3a1503e7812e642b751b4f8e0582db627f9ddeb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:587c89add3d1b76255debd41ae1b8e1147c5a157839d7627f0faf560d501ad71
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:427a9524ee179879ed97672de32cd4c5a1c47ed0bc18b4c46d992848e5ad224b