dhi.io/wordpress
7.1-debian-php8.5-fpm-fips-dev, 7.1-debian13-php8.5-fpm-fips-dev, 7.1-php8.5-fpm-fips-dev
sha256:6c97f980ae5e9730b9c24b79e117b20df26dc988d5068a999084c5b0061f67ad
Manifest digest:sha256:f4e5b0843da44fbf5f6d111203f7293e0dada89d078ab5985375dd39abc8cead
Size
127.52 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/wordpress:7.1-debian-php8.5-fpm-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/wordpress:7.1-debian-php8.5-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/wordpress@sha256:dab56b776439894fbae5a5442eb4029ca310b1d4681cc17992910df078c36615 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/wordpress@sha256:7c682ff22b17e79da5783eb0ab604fb7494663fe17de7b4a0ee81024155bd687 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/wordpress@sha256:21b9358745265d3241b8186fa00bf6bcd7548bb1968fadd1c6de6169bedf723b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/wordpress@sha256:40071e5319bd49c9024e109bedad79f2fc0768cbfe53b2c29699106ab748c434 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/wordpress@sha256:0c7daaae3f79251e8bb0bf0941300f32ca1fddfb4f06d5da83e43ff952795787 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/wordpress@sha256:c49790b7229a91ac0440df6c669d436906f69509a2860be75cc31bb599a65fa6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/wordpress@sha256:a2fb72537082b7f1fdd4142b76de93638945693750e9315a834b1ef68afe07de |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/wordpress@sha256:ae349ce65b414060bc8f945063266059fa835ec3aba3ad60c33707aa4550cea9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/wordpress@sha256:ee29fbd9f8742a488cbb2409098de530a6a9d9cc6cb1cb3dbfeb4209fd103de2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/wordpress@sha256:19e9da2ae162a6257eb2969e0b9a7303064dd93ec7351084f8505bce1df5b949 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/wordpress@sha256:2f1337bbfbfb1a6a67033236a57e0341c4c35912963cc837e4ec2cb8c8b4f7be |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/wordpress@sha256:f3fb1f5ea4a02614eb4563f8edb575c4513e6784ced8c1402d504f8734288ed8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/wordpress@sha256:10f4ef37bf159e78bd9ad499a43112ae5e28150d7151e7cd2dbb6ba2669f43be |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/wordpress@sha256:dac493fea888e216dca227f3c338307c36858f91bb30c58b9bd66cee797f2fe9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/wordpress@sha256:06a67d33355f49b7529aeaabb0c75bdcbb7f72230395beff8c14184ecd439889 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/wordpress@sha256:1b5a7f66a5cb110151e663889a38e9dc42b84909729cebb58b75f096ce2ecd0c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/wordpress@sha256:b265d99e8c467465ca9270eab869b3d6745173fd244ba20b34a23003190333ae |