Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.4-fpm)

CIS
linux/amd64
alpine 3.22
Tags:

7.1.2-alpine-php8.4-fpm, 7.1.2-alpine3.22-php8.4-fpm

Index digest:

sha256:3f5cdd4ef94420fd67bdcee1c77dceec4ea94c9339b6d42f6779da1e4dd6be97

Manifest digest:

sha256:e573af5e6482d5fa7b0f4fa1a68a21e67321b853e160fbf29a742fc0f99df990

Size

79.62 MB

Last pushed

2 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-alpine-php8.4-fpm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-alpine-php8.4-fpm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:7cabb8779922180ad7b87253001a754e0d9ad52eaa0201e81d264df982764565
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:5e15fea895a310a312060e66b1862e278887ed56d22f6e3149d229f312ab85c0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:ae1ccd3870d9a479199c466f2003d72665e47be5a1ac0bcb8e134f053acbe966
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:16af30dc1764248809b3f99dc4cfdfca30a84f0c78c86d884b83f653057aa999
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:adc4f1adfae9e27f4f521fa17e254ecd791bdfef4f864663fcd48a543b2623a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:4787118e0282958e1ee7abc9cd1b56db98f20b951b6326ef58528f1f87f6a572
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:f37f44d794827a377798605c4f9d4ffbe23b19458419388324e884e1f74caa5a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:e1db5f8e219e901fffe9a57c4fedff3fcb91fb7a324d70cf3a750128ae454b82
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:ded8465135e44adaf6a4ef33e4c82e425886bff98fca99c85acb9d31cde1d59c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:9e048d1852f5e78cf2b2be0f3026299294a7eafe6b2bf099a8bf8d37c7cdc2e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:2b88b5518f811e21b5780220a361494c3bcf1de6865785ceb061d5e0954629a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:47a24225021f8deeb76709d14eb51c5d3ddec8975f84954e6ca1c326df965078
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:203df91892c9e93319a4f09637f605b6253e3ca6b898cbece391392889fc97bb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:78f9adfe74959243570aad152c297075f4e834eb1edef9d1688c564d9abbca79