Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.5-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.22
Tags:

7.1-alpine-php8.5-fpm-fips-dev, 7.1-alpine3.22-php8.5-fpm-fips-dev

Index digest:

sha256:cf48b9517883b73f2b74a3adce7744c66ca9572eacdd104fd8f56164c162a112

Manifest digest:

sha256:200a3acc2603b2812ac16b8a8be09963e766eafa2c80ddbb15b690d3f0c67bd0

Size

80.83 MB

Last pushed

18 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-alpine-php8.5-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-alpine-php8.5-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:d17cfd966b6e2623376216a5ab2331f239ea02b42b4d3f8dfcb496e05bafc4b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:084c0cb567a6887692b506bd7ef167c036074796280407d7340daeccd246c0d3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:7c129b7a381aa0ea06908def6fa0f807acb3f4b81cf508aafe6a7b963aea2e19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:df64f0aa36f61d5ac0e4f143bdb2a5596c7b5865803b0b41754183ec99531038
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:7446c09eec4ac200c736137133e9eb7384056294990fac816d54c143d315535b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:3a69ea3b5cc2a22349774abd9443fd2aa62b9a3ce51d98f0aed048b9b78ef1d5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:fc9d25b146490a92bf73599d09cc65393e47a22308244a88857aff9baa8fda45
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a48626e353c41f47f783052729ea30d2dba11df1febe16e1b6d3c8b1e970f79d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:62b30a2153e3888549e17959b91eee74effd59931b9c981e70ef4011499052ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:a116ab5618b013c1ee758628322cc09f87204a0eea531b736aa328f307c5da1d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:0a764d74c06b999c2a22759a613c8006e8d62aa24331f5c226019682611d5b3f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:00a7864e04e8a8acade8c48cc45c71967a15b1378ee23808cd09ed632767ce1a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:721b78f356bf792600e0f935a050f567f90baee405c568a2ea8c985073fae602
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:c097136998cbb94955d8875b09fd9581018de4a3ee875531807b47c140259540
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:6216a9888e6d8333ffc4ecff3b461931c2c77a3dc4d94449f13075d1c7e6a25d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:bda9a6631c898e0bbe39839a518edd7fc52b71fd7811b267d81baee04c167e65
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:b75168231ceab11d3348242012a6bea4d80129d4257bb10950d1305e8b059182