Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.3 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.1.3-debian-php8.5-fpm-fips, 7.1.3-debian13-php8.5-fpm-fips, 7.1.3-php8.5-fpm-fips

Index digest:

sha256:ff908f3eee1d56c7023ac6d31151757f641cd7e721ac2641d9ca3aca672a2ad4

Manifest digest:

sha256:2fecc57c6ea21a349a0b44ffb2d4e83a9eed02f475629178f080df4f5e166e3a

Size

121.57 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.3-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.3-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:4774023f472545b74918c8a829afde41fd70c9d180bb839da8822d5d5330852c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:79ac5cdf43d55d0d78e6760a013cbd111c0d34cf5feb77db815f1ca6d028c79f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:6dc9f72e1e84c176a877d71a609516b6909343ecec00981773a71bb0810a3999
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:a72d000a7878543f2a684f2fa5cdb94c3d7ab91efdd13a99ee6cadade7058c9c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:6b7444f59bcfeb8d394ab37acf40bfa32e16a3e8659b95f44425466c355e96e1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:84f4e8b67f30dd230ddbbb01fbc7f26f3c229fe4085753fa3d17e9d9689d4023
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:fd385eafea5f7fd600fe9df624db2380ed96f483dfbc0e447cec0ad201109b03
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:509a70a396a31dab979fc69eaa78f283bbf00a18e70b28284319b768f1af2ce4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:8d68182869dc8aeb9fab105f0dddd2ec9b85c30bf4ffcf4a8e6ec4c3282e46e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:9e37f9d3e7869f1766d2d6f94c3a3880bb398c75944741c2deab3bb42468af81
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:0f4a4ba7a71d62f16426e93a8f16d828b650532eba858a59fdc3b785eb52406c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:2c5cc446763400a44c50278f45e94bf65bf8bf43368c75cff1f34a8bf0bdb761
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:723f935185ff3fea276af8672ce2e85daf8814169baf8ad046ad00ad37707594
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:a7d8d5500b4a0a1de37b593c882c47e2d912d8a6ec5fca21b3d0d97ad7990019
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:d5ca921389442be02cad9a9342e693cf25b191037950d20b646d4c8641ce98fb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:7bd1903703e3a1e865b744ee307b0af8e2bc88e2dda0fa1421302d303c5d0919