Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.5-fpm-fips, 7.0.6-debian13-php8.5-fpm-fips, 7.0.6-php8.5-fpm-fips

Index digest:

sha256:f1fc9fc5d1e2140df974e373afc7ed05b9ea95dc6b91e701f81e28ed3e20efc0

Manifest digest:

sha256:76e950b32c67f62a2511f243c3cc9dfa9cde4a87c38ad2913bbd2dca802e4c6b

Size

117.25 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:06beebb6b3ad10544eb349270622b382697c9454cf17990d009ddd44bfeb4517
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:b310be1ece55e87a4a29e1ba3c4a03fe6dc757176f22a1e3671e4be3d4da60f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:57895a36557b41b782f1be33ff0f3142140bbe82f29e497b2663b3a79b673ec7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:110efcd2232e960ffe41ad1ce51aaeddfa335c1106fdfc067f905cc98494a762
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:cf68964685d554b5f74676b7f3b9dcfe5df4f65c251ca65e540356c6459fb318
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:8efc79fdc16673e06622bfc1e273e28ec1e3a875d3fe61efad05f8c0e9e12ae4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:2b3b80c80870812508bd4e2327d684293757fe40ea4e16bb067c99fbfa128aee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a82485a4aa4dae8fbccfe19da634052d85d91db33bdaaae63f0a3205ced7ed65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:d249b5b7d46ec0ea5da5224745dfa190724525c46ad1ef8deb68202745c25e26
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:9ae887a3732ff207fd70adb814558c8ad49e3f2689ad5ec06e93ac5d826036f9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:b33b8f9ecaeabe55f320a22805f64cb3731421b3a575f94005ba250f456992e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:1b1c857ef21d485ece38350fbc4d57ff5a356a3d52d98cdf31aeb88258aed628
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:1efb7b736d75f94907dcb37a3c5378e65b22567afc14fc0d04d55d57e4d9cb75
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:3c0cdbbe9aac8ff4b3ad650d2c412fcb1ea0b16859e6a53b53849f344e873cc5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:05c62d9900657bae915c69844786c3c9f9d78b783dd3b994323b013679bac46f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:029973ece2cf2cd97c774c5e206777846ad1cbfd356b432c27f7fffe6a66afee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:aa2e877c7b9e49645b13ce0a45a755b19ec13eb59168207f324921a07e954e08