dhi.io/wordpress
7.1-alpine-php8.5-fpm-fips-dev, 7.1-alpine3.22-php8.5-fpm-fips-dev
sha256:d550605ea65a15ff59cb7fffce0e567fe85b0634c7ada93468ddaff65473a1bb
Manifest digest:sha256:086d303ad599c34ec01dbe27820cf0b46b8b6f52ffe5d82cd5974cb1a88b5e0b
Size
80.83 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:7.1-alpine-php8.5-fpm-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:7.1-alpine-php8.5-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:5a2073269d85736212124c25e958d7a974e39d9ef29033dae08334b4074aa89e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:a4a4c8251a3251d8ab8633d101f96abba5103a8c7261c2fe41c3dc08538ac1cf |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:05a31caadbc7ab40575f87126b0e5d117fa31f957583cf49154e24c4e53df42f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:4b27d89d973dc458873de60d61239f482d8b856987af683d0badb5fd27bd0b6d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:a5d5f0218a3c9e85fa608fc71a1667fbd8f5b283bc72b0682fae35256acec8aa |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:7775d2934d1968d3929fff9c40e258c4cdc3c2444e481ade58de284dd3947115 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:f624b47badbad8179b6964da11145778561d90cfae54ad1be0ab6bab76a0f302 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:017a2555a64cbe737a2f73538084a819a63df18d320f3920c92f90505e35c893 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:9e6fb1d655f3415728b63b67eb41e8ae1daff3de539fef3e93ab395572570718 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:d73139d668716ed53d7217133dc19c6f090cefcac781e5d3d7aad35f14872e77 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:a3964ba825ae6a850dad2e22bd23b87fdff87da851232171c04ef933b8c24959 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:76a4e07bac378ae464fbc7085ebfeb1bd6b3a208da25051f5da3bb5b77ce4bfb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:8db57600facc4e9d9800a321b745040ab66eb631f82d92bad228e9d81543adac |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:0e82642112e6f18495c726b529d1d32484f832711b289943c888913ca5c29b2d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:23b20707897157d439a0606cfcf53e8ce300926c0ee7f5a29dd2e27f9dc01670 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:b3f174da7a298b2e0138ac535580beee48f818184d3c82c81d48c10230a8f741 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:c42c8fa14c217104d856ad1366f6e658f3f6c7ac1343163aafed5cc2a19d3661 |