dhi.io/wordpress
7.1.3-debian-php8.5-fpm-fips, 7.1.3-debian13-php8.5-fpm-fips, 7.1.3-php8.5-fpm-fips
sha256:ff908f3eee1d56c7023ac6d31151757f641cd7e721ac2641d9ca3aca672a2ad4
Manifest digest:sha256:2fecc57c6ea21a349a0b44ffb2d4e83a9eed02f475629178f080df4f5e166e3a
Size
121.57 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:7.1.3-debian-php8.5-fpm-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:7.1.3-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:4774023f472545b74918c8a829afde41fd70c9d180bb839da8822d5d5330852c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:79ac5cdf43d55d0d78e6760a013cbd111c0d34cf5feb77db815f1ca6d028c79f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:6dc9f72e1e84c176a877d71a609516b6909343ecec00981773a71bb0810a3999 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:a72d000a7878543f2a684f2fa5cdb94c3d7ab91efdd13a99ee6cadade7058c9c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:6b7444f59bcfeb8d394ab37acf40bfa32e16a3e8659b95f44425466c355e96e1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:84f4e8b67f30dd230ddbbb01fbc7f26f3c229fe4085753fa3d17e9d9689d4023 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:fd385eafea5f7fd600fe9df624db2380ed96f483dfbc0e447cec0ad201109b03 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:509a70a396a31dab979fc69eaa78f283bbf00a18e70b28284319b768f1af2ce4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:8d68182869dc8aeb9fab105f0dddd2ec9b85c30bf4ffcf4a8e6ec4c3282e46e4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:9e37f9d3e7869f1766d2d6f94c3a3880bb398c75944741c2deab3bb42468af81 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:0f4a4ba7a71d62f16426e93a8f16d828b650532eba858a59fdc3b785eb52406c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:2c5cc446763400a44c50278f45e94bf65bf8bf43368c75cff1f34a8bf0bdb761 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:723f935185ff3fea276af8672ce2e85daf8814169baf8ad046ad00ad37707594 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:a7d8d5500b4a0a1de37b593c882c47e2d912d8a6ec5fca21b3d0d97ad7990019 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:d5ca921389442be02cad9a9342e693cf25b191037950d20b646d4c8641ce98fb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:7bd1903703e3a1e865b744ee307b0af8e2bc88e2dda0fa1421302d303c5d0919 |