Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7.1-debian-php8.5-fpm-fips, 7.1-debian13-php8.5-fpm-fips, 7.1-php8.5-fpm-fips

Index digest:

sha256:ca030931ca2faa7383bf227b5eaa0965a25db567366f02dc13019c570c4907f8

Manifest digest:

sha256:7521eed47dd35dd2410b0ded9af51590b837cd1af214515b38894e7f61327119

Size

121.17 MB

Last pushed

2 days ago

Vulnerabilities

1
5
5
17
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:3520b4cfbef92b60a600331f37f28dffaea2c81a042a48ba1060f21d92b93116
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:055c3fc9c5cb2522b524dc8046b61b001365fbbd4c73808867b1375b992f6d5d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:da5bfd146d335a99713545b8662f5ed892e713dae3bfe58da7eb38ce18165b3b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:fd88badb818b9f581d75d46dc5aa9d5f0eb8c93c7c956a3efaaaacdd277aa557
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:e1c6aee244e78df1970e8caa1147da36cb101ae4322ce63b08cb9278d60639a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:69c7a4ca806206f8e7659680a23c09fc1f35e092c193b49d16ea65410f0c0e22
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:4f4cb9cd8f6a9365782b645243812ba89e1728b709b3bd15d5464d829f1dd498
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:bb09063357393030368561e4189670c7ddbe93ec8c07c74c765ab2aff7adeacb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:613a7ec6a6e137a66f5f301e4851e4b785a874d92d29547b363421d0deaaa1fe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:a4395c39ee79622344f50649584fb6bc404e03da8cc7394c889561b26c9583a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:4f9c4b8aa97d12314a440828b525d59e0c6be85c379e3aa12ea722488e636dfd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:c826578dea5b7cc92e6759d9a5622558c41fb0d1d7055a15b7035dc3df9202dc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:2e8342ac60c9080970d87ada1cc106832e80e8d0537da1fe6a42bacd83e99786
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:3939d643dc52a95e7824c811049cfa1c185f6114317b439da37662616835e431
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:a7b698ca018c991553423c36363977b2ceedf0f270ac0ad11f6735e011c7f793
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:8dc2665b6c676c22d391df71e4d6107f4a2f2c4c1c6e6c3f25710d9ae330b327
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:856cda84adfa5f303d3c7bf5504dbcc5b75ec079272dd934ad64646194b1246c