Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.3-fpm)

CIS
linux/amd64
alpine 3.22
Tags:

7.1-alpine-php8.3-fpm, 7.1-alpine3.22-php8.3-fpm

Index digest:

sha256:6184afe93663b765d6555b27edfebabd1b97a56ec9cb92c696bef2f99c508320

Manifest digest:

sha256:9b723ab3f40122e701244c60e2495a33e13a679c9fb9cfc0d4cf789b5bc40893

Size

78.66 MB

Last pushed

23 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-alpine-php8.3-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-alpine-php8.3-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:9e44f2de1b8d4f5ba05f69556b153f10c916a20c9d321fe8a4b817e1f62762de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:0e167bf20e5cc851494178dca31fcd738f1a2c8521769f1706b7664d1dc41805
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:e36a8a778c0cbc49891477c016dfe8570bfd36178422fe824f41534799337fd3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:a68cde64b14131947bc8fc230f292a8c3a551c875fd5fc25d85eba6d4f505d48
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:3f657de1109d197801ccf2ae4b2c9f54b52bdff233941fd60a385629c0049f5a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:3cf25363b827fe124aad979315e608b32bc8f542d8c6df1ea365efbed3a51367
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:1fe88ab783e85dd4e6258e5f4232e1563bf7c84502bc5fbf766964c403252795
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:da782d9cf748d79349c5011f382d3ab87a1830ad69e38433aee478918d993f4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:6bbd1e7b4aa7a605b267465f4a5fbcdbf1b89a26efa65240646cde4657aee6d4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:63ff9316752725501a84583cf2a8a81acfe836ce4c0a66ce1f4f06017443b3d0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:6541558d5019c0c9ea0d49d95fa6871be2605958baf35932d9c5046894f853ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:4d83fa20eb14c69fc610ccbc00c9afe6921c0a982107b2eabb7ffc6cd665eca4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:e90902143065afd1c396f41d8620e7dfcd0e953b95bf5243496b2fb479579a71
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:ca809943ecef4a8e3a4c2f832903a674b3778eae9548e0f6f48c163820fbf119
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:feeba4ac5072187c922b54b885f3d421851c533b69f1ccba0d229a30b30d4546