Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.1.2-debian-php8.5-fpm-fips, 7.1.2-debian13-php8.5-fpm-fips, 7.1.2-php8.5-fpm-fips

Index digest:

sha256:46747fa8a822d5435aeae3fe294d5f3d7db11fcb9d5f9c488d10f22e08958d86

Manifest digest:

sha256:67b90d1af2c32343a379a0f1afaf79c70f14d93ea5c6626a61a68c82c22adb1e

Size

121.18 MB

Last pushed

8 hours ago

Vulnerabilities

0
4
3
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:3aad6d84b4d8b839588fbe077126322eaaf1ecfaa21b2df9d5ede30a4c7257f7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:f5d4c1aa2d2a550190de1cff7e95c0271d60b26c50b405aa93940eccf9598783
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:46ac6481e21cc04503a49b45dcd6d7bff9feb160ad71255878fa36278dd27d98
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:54a54a0f0c397cd10644a48be9eae9b4d83ec4926d3016d668a6793b1959c2da
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:f16e69676c66bd26e27a68ca793ba37e4ae142b40d789ecc0394807426c74764
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:3fb97e5c8800da7263b32426034518d6e249d63713bb0c23afeac5ad6fb70100
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:e6ac8d224aa5443d63e574fbf4b1c5d5389eb3a3dd0758849bbb5c0b03b716b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a131c66f48117558d43701285a8048fc233ba3022cfc3aabffa9ecfc8e3fcd41
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:d8601f3a0edf065a495ee9f4e186f140fd154eb3a9275abf59eb5f6e38960244
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:4501ec89d67f44209043bf56e4ee2d557500affc2347591c3694e4464ad22bee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:97b65aac42bb36e6961305398d5f31c13ed75d4ce7f85de2724beb34a49dd546
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:848d56d1296989ac1e21beb787cd7c3563c1c8d14ff45d5bf10818289ec01e36
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:df819b93e6bc9de8bc3d7f71dad5a41db7b0a5eb0b9971bc5bd69a84c9c95e2d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:5b9631b4fe232b4faae85d5bac432553ac0105805a33d943618f07ed835096c7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:08f9cc350102b80e7119df682b9f1b39a830819e2ad4bc1dc17e2cba8e9db3c6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:ee7da5d9fd4be4eacdf8152b8ecf03137f22395aa682f27b2400a7ce799870e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:0fe1b0c422dee5233cd584e0f037c9e0e11d1b48aece193f658c455b8a05a6dd