Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.5-fpm, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.1-debian-php8.5-fpm-fips-dev, 7.1-debian13-php8.5-fpm-fips-dev, 7.1-php8.5-fpm-fips-dev

Index digest:

sha256:6c97f980ae5e9730b9c24b79e117b20df26dc988d5068a999084c5b0061f67ad

Manifest digest:

sha256:f4e5b0843da44fbf5f6d111203f7293e0dada89d078ab5985375dd39abc8cead

Size

127.52 MB

Last pushed

2 days ago

Vulnerabilities

1
1
1
18
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-debian-php8.5-fpm-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-debian-php8.5-fpm-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:dab56b776439894fbae5a5442eb4029ca310b1d4681cc17992910df078c36615
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:7c682ff22b17e79da5783eb0ab604fb7494663fe17de7b4a0ee81024155bd687
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:21b9358745265d3241b8186fa00bf6bcd7548bb1968fadd1c6de6169bedf723b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:40071e5319bd49c9024e109bedad79f2fc0768cbfe53b2c29699106ab748c434
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:0c7daaae3f79251e8bb0bf0941300f32ca1fddfb4f06d5da83e43ff952795787
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:c49790b7229a91ac0440df6c669d436906f69509a2860be75cc31bb599a65fa6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:a2fb72537082b7f1fdd4142b76de93638945693750e9315a834b1ef68afe07de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:ae349ce65b414060bc8f945063266059fa835ec3aba3ad60c33707aa4550cea9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:ee29fbd9f8742a488cbb2409098de530a6a9d9cc6cb1cb3dbfeb4209fd103de2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:19e9da2ae162a6257eb2969e0b9a7303064dd93ec7351084f8505bce1df5b949
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:2f1337bbfbfb1a6a67033236a57e0341c4c35912963cc837e4ec2cb8c8b4f7be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:f3fb1f5ea4a02614eb4563f8edb575c4513e6784ced8c1402d504f8734288ed8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:10f4ef37bf159e78bd9ad499a43112ae5e28150d7151e7cd2dbb6ba2669f43be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:dac493fea888e216dca227f3c338307c36858f91bb30c58b9bd66cee797f2fe9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:06a67d33355f49b7529aeaabb0c75bdcbb7f72230395beff8c14184ecd439889
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:1b5a7f66a5cb110151e663889a38e9dc42b84909729cebb58b75f096ce2ecd0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:b265d99e8c467465ca9270eab869b3d6745173fd244ba20b34a23003190333ae