Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.5-fpm, dev)

CIS
linux/amd64
alpine 3.22
Tags:

7.1-alpine-php8.5-fpm-dev, 7.1-alpine3.22-php8.5-fpm-dev

Index digest:

sha256:d93cdf3dd16e27494340e603d52ea89511b0691ed51f76a4e6ff64f710443516

Manifest digest:

sha256:be2d2e1e3033aa07873f59e15c4eabb9c979569dd388496bbacd1e72f5f41e8b

Size

80.00 MB

Last pushed

11 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-alpine-php8.5-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-alpine-php8.5-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:ee319dad9f8f7a19daaa7b22542c36476935a5d73ddc8702f4be3b7c3e1b62e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:576799c2853488c98f9c52dd12e4a4c25b30d666572f5301f50b867480d66507
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:47b383d36e2fce05a3da429bfcdd85e5eef5d104d72aea04f4865c59ebaa2781
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:e8c2aeb1c7198881c34a88a119ee1a8d2b5d2659ee9a3c07fea88128ba019ee5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:9e66394ea8e438f05a99b8f7ea03df2854bbf763450d288c2fdf631408f0da4b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:cdbd486ce771a55013355a9162ef2593464c2dca1ecdd55c78d00c4d4729d49a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:6b356bae11ef49c7f148d235d8df9216a2f2c0c8a93e61c92cabbd06b35b6fe9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:dc07a638f8c43237ef0817a86e13dbec5c0ee9b14cca8bba525663a98c294b53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:75a382ad645ffa1e5e8ca81c02403881066fdb8c1d66dcc5422dd4dd5da5133f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:7bff5186a9297f23328a66ab014bb7d686d6d20105215afa702b8b847b548dfe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:e192ee78fa0f8437e94b72b60b9849112db8b9adcb2e82dc704686a649f69236
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:0cbd35a9446cff71847e0bec64c71f232de1af6308385ed48a41a0d92e61e28c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:f1870797403cd980d783bd2af72777f2716148b7cffbfa8cee1321058327de1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:6d4fe50dc900a9d9b3c827ac17167260a8e123a40ff27efefb8ac0a89fe8755a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:4604933ed4d29d3f06214d57c963bb9eb2266bf7e269db57ebe9c80d058061cd