Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.3-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6.9.9-debian-php8.3-fpm-fips-dev, 6.9.9-debian13-php8.3-fpm-fips-dev, 6.9.9-php8.3-fpm-fips-dev

Index digest:

sha256:4d8070d7fc85ce9690647f23fa133683e43068e6f8b350cf1da0927b1ce8d95a

Manifest digest:

sha256:c474dad80058a2d5839812ca6ee4a6c61678cf87fabf2bad5f4173dc342025c9

Size

118.51 MB

Last pushed

6 hours ago

Vulnerabilities

1
5
5
18
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.3-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.3-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:29b6b69917e0e0cad8f118b6f462db48d3c7d193c7e469dfa86a641904ac6456
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:f33b8e36f4d33f8c3a0035bc13a583821abb230360b0f2a5260353a5588eea76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:e2c1a47ed1bbfc80f29e0c3cb00d7f457159a0ac3a4d4cc2bfe2f6696e99185c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:963c9a20b4303ee67846ea31df836f8a505365aa07d7fbd6fac582f97b7e75b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:b6ac6cb5204e8ae8d66a28d9c3603438bf535a24ace942540cb8dc8a1397d259
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:a2bcb04bf8b2c8affdb7fcd9a48e6af249b8d65005294d3aa8d6dfc8967b0095
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:b0a824dde7616aa5949bc09eaa1188e33c70987aba048dab4ba4c8cbb07cfe7a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:aec28eca1234544a36417a8165c0b0e448e6d06b49938437ab25f6e4f8864e9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:568158338fdc1a5b5db3fab43099823ef875f6a4492ba65581e13a140dfb803e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:714fdbdeee8c454f47b38d3c7997e837791cf1033ef75577dedd8fce29e0c1a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:8138b589e4b949afe988d4c86a92bc930e978aa180ff5c9b571acb3b62622fa2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:aa851554efb908dce4e26c867fe6d8bcbcc886acd4fee4108d71446871eae566
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:a52424fa1d481ba1d62408c7b3b41e288e27b740c3ea770769de50865379e80c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:4e72b368b0b39d3d1aac565eed45c4f893b869ffd1f41f84c962abf466180f13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:c9794fac0ee78adf28d71358167c2c37263825627490b6c30bf6e9aa457e32bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:30a880b9b41cd7373588df2ed28f67dd6d66511e467b5f9fa7503ca649a7e227