Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.5-fpm)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.5-fpm, 7.0.6-debian13-php8.5-fpm, 7.0.6-php8.5-fpm

Index digest:

sha256:f85c32bb79685a6ab7045da4117f1fd7447cbbb95070d539c382e992d53eae36

Manifest digest:

sha256:0a0746cdb1bbbc95775c29578b9635bdbd8355650e19730d5c7ef0797f426fb1

Size

107.41 MB

Last pushed

2 days ago

Vulnerabilities

0
1
2
12
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.5-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.5-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:6b0a12dd4dbdb7209437dbff4d508f3e31af1e1f4991d78970390c3c7e4e2059
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:63afdaf28a5e5e7ec1df204809b90fabdc140cdb0d1c92f53f0839ca630ca2a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:62a7486e893910f2e7d1a56ee1c682dbaa4402ae431b1aa7b8630b05dac39557
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:efa9f5b5e5cd7191972bab0db905be34d2e36b429952e39810c245a1056b2987
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:5997b950efc318dba441e38f9ab5f7f2410671fd9dab0f5b20c78e0edce558e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:da04a9488d30c76f460b9bb81e5d755f6b473479da214d93328b48e4bbdaebc9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:10b4b4fb6238aa562e7b88a96034aa107f55ca7c9ad907d10546d01bf4a31ec8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:d563710e1668f4f6aeee4369a1ef5cc8bd413cfdc8482aa0b74eed84d52ceff9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:4b637572d7d06f22bb62b337e93fcf3b0c5cc898ad4008ba1a409cbeb5674722
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:d77826a41297388805c7ab68cf44723cf362a8550e32689dbde2a8172e6323d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:2c9bebaf5828ade170af2c1118eba9e0b116fb42ace3b09352935b4fbb79d2f4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:0eacf0d0f9a39b5044453b74fe1b16b67ca159f7baddfa771adacfa5311acd55
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:f1b35881f98fd1771c0bbdf5656c240220cff79d3946189ac1bc44007de6881d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:003db06784e6dc57367844d8592f447d03711b8ad011906888a08701ccae83bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:8f391cee5a816ab51363a0cd9fdf924cb24f5b1a97f4c2b531903bec547cb6a6