Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.7 (php8.3-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

6.9.7-alpine-php8.3-fpm-dev, 6.9.7-alpine3.22-php8.3-fpm-dev

Index digest:

sha256:7680000b18633f032649cce3aaf6c22de96a0ad66398ae25592f7aa9ffb5d241

Manifest digest:

sha256:cabda447158c627cbb85d1c6b37604e409fea2e202372d66dbb859846b241502

Size

72.66 MB

Last pushed

4 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.7-alpine-php8.3-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.7-alpine-php8.3-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:4ec5b63c1201344da2cf9a829c89589685fe8d347289f84fad041bf7f37ed887
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:3e4d2e913b4dfbe427c01fab52f7d20013984693045a3966675f4dcf07251d9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:9c5775fec8945de97ddfecff0ed81d881ff841e73bf3b375a3df3c0480da4eeb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:38d97deec74b3a5b518ad0990dbb6b9d59562806417ff4beb6cad20b97d7d335
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:68d8c07292ad58f3343637c9f0062bd580ddfe0afdc572043b79e68ab58a762b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:38c07f18aabf3fa3ebd1ca4257ab126af6b596dafb9536ddcaa2b38efe1d2a8d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:584185a989c609bb9f092151e6d92995f8abe969e10b8b2ecff9078d4bbbeda4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:70ebe5ae9fdf7ba5accb3b7298f5f9e196cd21eb34201a9f6d602bdac1dd9932
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:64b31257d3101057520caac86aecb8bb049ebc6e48195bd85484b7af8ae88489
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:534f1fe6152d1101939dfe3884317e1790ac9be2429b6cfc56da9798f1a5c223
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:a1aae2680ad469f3e2fb8e641fc0742f62c00d04a1cf421c2a137d5283f13279
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:1aac09b740b7533563fd932b75305e3cc4109f8bf3e2840fef4be814ca5a0817
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:f33d8669e62a032e40a5d70e5a5e0769ed06afb225eacec4005ce442e859ed5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:60ba6adb8872238fde97d44b24a18225c12d9d2c2d3de27894d38b985b3a759c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:0f7d6593c81a569411cca0ccaed0970f5b8875c9ef66f1ce35da3628e185235c