Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.6 (php8.5-fpm)

CIS
linux/amd64
debian 13
Tags:

7.0.6-debian-php8.5-fpm, 7.0.6-debian13-php8.5-fpm, 7.0.6-php8.5-fpm

Index digest:

sha256:933e938fa0069416542a649c5dbfc07eaf4caebdf9170a61b0c73cee652da17d

Manifest digest:

sha256:78febd4b5e2af4a2c869c9131a0ec39699086a2d62e941aad60f705b5bfbb549

Size

107.04 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.6-debian-php8.5-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.6-debian-php8.5-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:992a7ae1f8efd530818c66c9fcc87de4cdf0038ccec370e90f281d52d648d672
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:a7124d3a6dc51c99b118d3a1bfa75ed059b9398657ea4f41142da40b4f80edbf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:16fd68e951839f3761acc53adcfaee27e7bc88711f76b61c5220f24b489d8d0f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:de6f719d62b33e35c10ad0d81862151be3dbb73117766d6f389fe2d2a4e6e6c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:73f1ca3a41b3a8fd9b873672ce49a1b87e8858cfe7e3d6098f84623d6728bd73
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a22919abbf361796e3707aa334b31201e04e80f46f0c00fb96111418f4efaebe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:29d428349db9281ac36a9aa413fd207f9949d1208a5f0898469d00845758a833
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:48735f545ccb79924b6bd07ea7f0432793ad96f1a8be4e46bcda2b892bde3ad3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:e17981914022c390f4e5a00f51d8c79e24391ed6a1c416400dc6d6121e65d78c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:ce6569a6ff2364ed11dd57027ddac18381fdc52dd0e216ce0951cbbf671e1e9c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:d5f92fc7457bc6b7f3fe0c1a7477fb21daeddf335f81f5fff9486eeb00c3e28d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:8f366ea14c7322e89016a1f39b8ee1d79b38b3e2078f8acb852a15c776afe18f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:8eb27cf8442602c3924b40fc5edd031e18935a19350cc1fce60d56c38899c776
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:e0ee638609a6c4303ad12559d2dc0c78892b7f2701d165923809b3368fc55aa7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:482f88a02a71aa51b8807a11a0f50c4c9a4fdc723fd51a098e0711b08bf629ec