Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.4-fpm)

CIS
linux/amd64
debian 13
Tags:

7.1-debian-php8.4-fpm, 7.1-debian13-php8.4-fpm, 7.1-php8.4-fpm

Index digest:

sha256:56801ea377faf9c53667e31e1a5b931f76a186e1f4aea8ccd5e1f6334bf79510

Manifest digest:

sha256:b6169ae8fa53fc4f422c3a32d41c350fa7f5eca3e26b61479e2f4dffe3d77d88

Size

110.28 MB

Last pushed

3 days ago

Vulnerabilities

0
0
1
16
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-debian-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-debian-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:c0c4017b6e37b4114151eb946c19b16f8a29b18eae789aebfdf9a5e71c6f33b0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:4bbe9a33c2805201b9a7cb68742f155b8c043d6f79f6999f9043155b901a8854
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:3a68bc04f69fc0efac94ccc8596efb043a0a1b6623464a7a5d983b866e80764d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:f85f3814a8fe3e5696f71b5b7a4dae64b915798bc41d11a6e41b4785c4eb8bbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:35d884240c5fb39c76427812f75cb877f6d0a44e63154a01dabd89a53384487d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:c841235a9155d5a2c7e43a144bae0c7d10a9eab603d39f699bb6a124b1d79761
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:0a6b8f9f6a3d6c21ebfb0da55e2b6ceca1f5763699b24f0101822052e23e65b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:f94de07a7ac54fd8067bb98ccf7ee22ad79f26c2efe42b4a8324ab6dcc812fff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:aab2b8810c6a539d3ba5e748b035465b43b8c78fb8b96a941d8cfad6680dfeeb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:30c655e98fd86f8d2f3bc3d8f704f0a1427c03763b72fa6988729077242cbf0b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:644773419130a223476c72ef81d6faa29836a1d8d68fbc4bb50abbfe0a058e9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:37597480e49fbbc4ceb99b8cbedca8db158b1a74004d6ae3f81de9584d83f7f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:43ea3e830c789ee0de1e24898d1d210c06829636888f0f0d936588c8ca6914ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:fe805f6ebbdbb03cb5cfa20452da908cfdb2c5abe0c8b3afec17720a2aa72435
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:c7fe5d95c88ef528e522917d04bad1e36e70d74c3643c6c8315eb1eb8cf979d6