Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.5-fpm-fips, 7.0.6-debian13-php8.5-fpm-fips, 7.0.6-php8.5-fpm-fips

Index digest:

sha256:8b9387ca42fd02c15251ad8f60911c7f13c0d7255e34a79cd36f5d124d4db91b

Manifest digest:

sha256:9b47cd73f7b8898c1b5fcdc87656134220220aba7fc4590955381c7927f383ac

Size

117.25 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:c43896dccb56f356934dad5900aed8e00f37eea60991e684e4994fa9e62ae058
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:79d9a0975ff835ef0ae9fe5b4cc8a9dcde0690f92fdff64b78c9b013fb5fceef
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:2f9b211654d479c41a2679567eb2cd523079328d260917d3db9f7ac50a0db44a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:3b5b7410c90e87c27bf0e2a1877773f089c1cc9ed10eb9e597541fbb07986e08
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:709af6255c06f632c9d3c6a92b9b65e730175939e0caa346c5201b159db58912
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:370d5075bc74a749a412d8320d8af5ec4d121b2bd0017a62d763d451a4cc7a4b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:fbdd0e7f592a008bedf0df7eadc3632c6844835556c8d9eaab6fb44fdc7a130e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:ed957a80491f9858cc670bdd86ea6812ff2d9adbd1942ec2b23b605996ca5883
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:df105a67bb4bfb42dc40376e9bb2267ce4b7ccce61ae0cfba80af1618ff4f643
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:48a35a02aedbfa8e8e85c022ee1aeed441aa54adb440dfc4cd205bf208c599b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:447da4e75e84c9f9dec0ed893c0c7946af31baa161cd3c903c041a64026c185c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:ae4340528c0d5bbe65006cc81c605187582e54ffb5f3389b4a851eacaebce6d6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:370c3b9e001755bf338e08f30cd109e8474c120f00a312ef895a70ee6215cdd4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:cb4f4759f5b79fc192a371ad7705bdeea8f3e7caed4583d23a04e7f0ec89f908
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:7de15e9d2a765629131b545cfde0a30f581d41f3509849ebc190b88beff1fe45
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:3e57a451df5fb00997683f6c4c1b4e27662a7aaa7e43ac79cd79c38800224034
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:f5d2f58944645bd83102e7eff86d8476985b94a13b296e3e74ea7b3db749f7db