Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.3 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.1.3-debian-php8.5-fpm-fips, 7.1.3-debian13-php8.5-fpm-fips, 7.1.3-php8.5-fpm-fips

Index digest:

sha256:d55cc2372c7ad60d4d1e49874ad4a495af2378cbba48648bdb77d756656242cf

Manifest digest:

sha256:357450505a3412732a9bdcf3290833c1c5f8499186878a4dda8c1f55506d89e5

Size

121.58 MB

Last pushed

21 hours ago

Vulnerabilities

0
1
0
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.3-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.3-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:c571712293df52651a9fa5bd6d9723533abe8180dbc6ad4828b524070498c26c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:bf21219ec2d1f06dedea202763efc9506fbe5b407fe3cb55e0d65199bbc50f1b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:5e9807a250cfd22568e6e6ea74632c0b6dda16d058d6c64f021e1d4a1984ffe8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:1ae27c09333b491f7a9f2fdb030235a2ed0b096397c7af961cd73cac0e58b97f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:5fc0a5518b92bf353f375b62e10d449cacfe43aafbec7a6f829740a8354b5e36
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:bfcda3adf2589ec84919bb8805cea6895db9b837900afaaab49a3afc4cbcba26
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:256d877c87dc0c11ef2345037749df477999d577902094ae89ebb0d757de0d76
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:e017438b2ca928c7224aacefbbebef6356e08bd0f4b478a48f3b7f3b8b0583f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:66592c2095b31529776fde791e534803329b8b50a9e36fe624e0bf73dfd74f89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:925a4c0ae0d38104cbbd45cd25ff4127abb58e8f3fe5f3ea3679cee0b47d773a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:cf120b41dacbe78f8b23171a3bca977e0ad1618178188b34c917686db42962b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:278256bb76c57517534d95f9f18d57ed077498f3ba8a8549de0fb3645036c1d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:f17a0daabbce6fcfe9e5f849f3e9db0a4f47bd2432c68c788b2914cce1cc6e87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:a7fd8fd82c6b28738e588fe792c5147db02461acd32e7ed7568adee66d2bd974
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:d9b705a7e6b927bab62926fab7ce7ea72d175a5d86b008e849910f842fc6ce91
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:43ec3c27991fd733217c51175650923da6c89eaa99083d66053df727b1ae1473
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:62f400252188480257e5908cad1b9c64a025af3d0d645e284a8c1b4f975f480d