Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.22
Tags:

6.9.9-alpine-php8.3-fpm-fips-dev, 6.9.9-alpine3.22-php8.3-fpm-fips-dev

Index digest:

sha256:fbc7dfabe5cc9071ca66d69230d8457dbd3d2b2580b6a0a4c01c55f9bdab0270

Manifest digest:

sha256:ade1492712dba7e52cc0c72f478af9cdc51cb74a5f6b38c6550b64bb8be1c6c6

Size

73.49 MB

Last pushed

11 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-alpine-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-alpine-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:abdae59b38dcb9a559886cff43d561335dce8768416705d7354a8dace7a844fd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:c876e4f668abec6a245f5dfd225c3e9c592c5df67d21c9cf1383648c119b8e5a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:7a872b325615b8cc2774de1c45cd6857b1b45802060fb89f27b4c1855bc883b0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:065edeb246da54c4c2cca952667943c859aaffc12cc790a0f5d90632f22d65df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:427e6f4311c60a5684588ed394240e3164f2f351a35f5a8f7ab14ca7968b1d4f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:e9423034355a9220ea8ef8ee73f54b491af1cb6427227746d13c2c5495860444
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:5a2bb39690de11631fb9291d6cc6830d8f16e7984547cac74a77b24acc09776c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:9bda2b8046632b40bf18a535b54f449645139714c1b916981275a0aac8294b4b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:164223bdb111b44f84e09546c6abb22a4faffdf6b7f1fd237396793cf28554c0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:f67aaf43b0d0381a0f5ebdf535c8ea782ff9859d763959d83b6389198c5d0a56
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:d80cb59791a6f1caff9f6a688486421cd4a092e8204ce67c6bbefe7f34e9f3cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:7a74cfce918f6f03134a5b0d7a2e4fc84321e84ef20156425b3b5fad3de004c7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:0f7efc46abfe2e74ed856ee92189dfabcaccb0d85b01835bbada42e5f9567af1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:82a724eb81615ad6633c9ade9ae58c12b3894729d6bf8e26fd2aecee57eb2fad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:b5a0bfa403bc9755aed214dccce64e352f95101d157713d99db0bfe4a3dafecf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:39c66e17bcd6bf4f7fadd35ef8e5473f1eddca0bf5623a8e598e000d65b2cb69