Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.3 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.1.3-debian-php8.4-fpm, 7.1.3-debian13-php8.4-fpm, 7.1.3-php8.4-fpm

Index digest:

sha256:3f29004768c92426bf81cb9e3f3ff840bade2cf5cafbf7f86fc47d147e7ea061

Manifest digest:

sha256:51cc8488479a3ca60f420c9abc4354ca717e963f279fb8a90c33e4022b6398c4

Size

110.63 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.3-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.3-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:2073756f8b28019d4f0ca50f1ffe12796d6185f5e63a04f2b9ddc75b22128cfc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:3702ecf7054f590bef39a0087bd9bfcd3973267e892435481956a3fc419e62c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:64e8b088831ced96934cb6ec57353a1523f46e7041f53c69658dc8a5d57bc600
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:08f877ee3c438bb06fce0416a3746695c34928de9946e0ab137c2cb257c66d2a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:8bdc208b830df735754d5bb1f86f72951d676cfba0c34a91e725ca0ac8d4f1ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:17fbd86026de801ee27faf0fdbfdd6d2b4c31e3b2c6c85124b1e0721477831fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:ac0506f20de0f72a06ae377b66fbfe1466e29acd28f45d15ba8215d765dd0c93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:504c1ee09a91c4f950c9d0384b1f4471f2ce4c110fd229919ebf99eff1e7ab05
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:93712746673ba7a41e2265d73dc097ebaa0f41366e3b6bc706730097c66bb306
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:069475470ef62afc9ea9934d496c60431b612508cdb0f5e9192d5d8d4c2800fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:af340eb7427bad46d30d51dc5743236abb1de8e72416f170844b0aa6f0cf4b51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:8773645cd6a7fff3806fe155b0decea666bd62fc31d53ca343e681d79db8e09a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:5ef631903b0d1a0443289a997da6f094ab3688bea5ee6496daaf8668a69236d3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:f08f4acd6befd2f8b1582972df9988a200637e09ea480af97b0a0b6aced4fbe7