dhi.io/wordpress
7.0.7-debian-php8.5-fpm-fips, 7.0.7-debian13-php8.5-fpm-fips, 7.0.7-php8.5-fpm-fips
sha256:3fdcba64538b76eefa55e98d217f1faf097eb0824631625323a5743e86e60d4e
Manifest digest:sha256:aee9478a8c97a3736d1b8bbf5555cf9d1483fbd06fb2ae39716a5d8a700fdbee
Size
117.27 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:7.0.7-debian-php8.5-fpm-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:7.0.7-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:f29596a959ef72e22fdfbf7edbfd7559bc25a634d790cd7e80720cece8c7e70f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:f1c1ccb4b29f793901b1b895f7077144ec8a6b315b027805010dcf0e9fdb3578 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:77d112bc5013e31b8b7245216b9c641d07c73833f9a61ee6e5d7aa8b0882c0d0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:c37490aee88011a65f62c6b5a8c72d8e8f1f9988673775785febb77d96aa1347 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:c6ff83a03dc147aad62493d1edb54e20f7924f37af7cb6bba919c903cdd443b3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:70617da287cd6739b5a27dfc5a9caa8c15c1e4ef9b25155ddd20419c0a601ee9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:f5b169928f51c2e6cb96737c8a30c7b63e820365aa86a249df6197e24ec6cf04 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:23593c520c9adb66b1549edc3b9ff04d2fd6b679a10ea05b9ebca9d75a0d1f3f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:06fdde364cdd060ce79f26a03e924dad0ecee54db24ba3fa6cf639ce7bd67ad6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:8314e6e71be1110d149ea5591533816bc800d53436e1a2aa2b4313a806cd6786 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:1892349eece836584d93003be0ccbf01cd543140f0fc9d48cb2c8200dd857a90 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:d7fe63797f812f09785d8dc12931827ecd22f42192fcf961b7814020be63dafb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:fb8cb13f895593d41b5c1abf8f24d34c2854ec6d9934ff0b62e45974df669d12 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:7732c459e8181032c7cf4f844becd8bf83adbaaeea356a4a95327ccec8994af3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:eb8d69c0be03314b11135200c65529e1bd59e7a50e53bf5f15b9936503e57d87 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:9ec39afdf03812f3f61fe20d63199ef24e7f06304d72612aa172f809934b05d6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:c7bc06626abf5ca676eebb2277773ae65c2cb47f982da79397e063de72dd6ae0 |