Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.22
Tags:

7.1-alpine-php8.3-fpm-fips-dev, 7.1-alpine3.22-php8.3-fpm-fips-dev

Index digest:

sha256:b0812b2125ac5aa7cfe55f27189f06b761bfd1ecb508c11d24f68a70cf5324aa

Manifest digest:

sha256:96a95cc748df917d21aec69865ff5266faa58471e8c1fcf502ac334e15a2c01b

Size

79.63 MB

Last pushed

2 days ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-alpine-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-alpine-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:0bb9c5fb687af5075830f11eb0fd0032fe2665b81782ced9f8dfef9252550c13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:2ef2351b5f4941ad6ce7027ea29d2de63bf22de16cbfb2808d8a996c14d0fe41
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:3fe011a0ae6472d5fccbe71d5d07c3031fa7f9f7aea465b11066c72b203ff49f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:7f0d3c39ee78663022d76e31c81d9d441c2262a362e5d9f501af15006a421874
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:4cfd28385d575b6f0e0620ac359e5d04196910a171ec12140756cdb876158c9f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:57dd3f4e8bde9427d67d59ccd6731926b44ae626a3bdf9c52243b2b47a4330f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:a858da71b58ca8028f7eb7e40f59b99843ae9aa8d54e165c3a2ca3c6d1c90d86
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:cc83b5181a024eda9ce90407dc8a4ee68f7fb9250dcfe772cd2c1a437b11ee02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:7ff57d3fa574b40bc3b16fa78c1294fd3d468d237497468bc97c884ae26661fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:5555fc0d99673b9f1e9a779d52045f523bf2364056b5b2b010917e5dd86f15d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:9da24665a19f971fe4fb326a3c5cba930176b43bde2c0cc7fe44aadaa05bc3ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:96d1429a11b88b94ff3f75e1664a74da65df8cc5e95c05fae9f5b9c30913a40d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:4cafb5f4a4dd3a3e574738206f25e21f8c6fe683d80d9d77ceaf7b5c3966adfa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:47ca2999415d0f3919054f39496315fa5fe4c5d3d2b1ff705188c32899ffc426
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:3b475cf98a09feb41aa3f95f094ede607a06fc89efff2e5cbc7ba47aa71c8936
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:0ce320586a12ae91d30e8201d29a91bbdeb845719a274afb9c9fa73569274f4b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:e6440947ddc0ab01ded4fec8ba30b24549baef0a1bd9c2bad213705920ca9922