Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.1.2-debian-php8.5-fpm-fips, 7.1.2-debian13-php8.5-fpm-fips, 7.1.2-php8.5-fpm-fips

Index digest:

sha256:9a7694fb4f3b694488b5a716b0bbc3b1b1ae7c501a92765fef2ce334d152681b

Manifest digest:

sha256:dfaa4be3c7b66ab6677fe8726e09c6fa1d0f726a08e67300194d1c22e625d146

Size

121.57 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:813640e83462b6355e9bcb223591a33105d2c37ae31937ba47c0fa25fa0aaf7b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:8bfb82c525e6b0d0c0835c868a3949046439ae418d739b494318224d3ddd2832
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:9bf633d86ad40b2142dff078fce4e6ff0ae6b3c13a1f8c85979a309432cfaca2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:f203de3442f374368d81fd73cdc5e18fe56ea87497a583d4ca1d6cdd33fbcf8f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:418a4dd7a312771b16ab198da057816a2410aa9046a46ff117db7a583001b4e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:688bbb2701ed6b5de8fe195c24d9dc13c98d2e04af19eb24f8fb0ccb78ae6ce6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:0b80d30df1030c1ad988709d6da4413d9a2658da13e6277994196e8269067a7c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:e1c096ed955e2f2cfd8c90a7190d83d0ace6337a893fdb218e60ff0fdf29f215
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:cebe7eb2eeb7015e579f04bf8ceb910c067fbc1cf1a21fc0241c03f99faefcfa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:7fdd04e5a773b84c7ead612be29fc61e4c7b196330a1e032926d613cdda383d3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:788b5cf46c3c013914f93626a8319fa3b3f4ac799ef20bb2409705118bb5d588
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:0e7a71c47f1c80e137af8dea971ff6ed7f4a1f5b96a02571a2722e2812142c5c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:6d9fabff60372bbd0ca33aaf07e4ebbd5bf5a888cd8410fbf1345be62e613401
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:4056b24eb7371890d16a66d5633e8738f32e5199bb613341d0573d34a24723fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e4a6a897a8cbb23c44ca070c17d78f6bf063bb318286f9b62b593a25d33636ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:19b2ee121c3a99ce1b21635a9eaf6f9033010995b73672c1d5d0ec085d74681e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:d0142a03da53c245bc5d62930596fb57da387e2304c33223995d5e6c54e558f3