Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.4 (php8.4-fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.22
Tags:

7.0.4-alpine-php8.4-fpm-fips, 7.0.4-alpine3.22-php8.4-fpm-fips

Index digest:

sha256:8b553c03142384275bf5fd707423d61ba18f7d3e54a32fba2142389b652f9c86

Manifest digest:

sha256:31736bb1c249ec4ebd973b51239795763d1f5fcbffbf220e7bc574c9484617cd

Size

76.13 MB

Last pushed

13 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.4-alpine-php8.4-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.4-alpine-php8.4-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:25b840acb635fc3958c92cabc85f7ba9af8fba50c0eb44a3dd6880eadc007454
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:b5f7c0b246d44563775bbf8cb9fdc2af70b11c0eb67b5e1fc269414a7d2777e5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:26d5db124c470b3158e308b165c070944d9d0a5931307e047f07d6c97c9e35e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:c5297971c47da78f83e7f1d487683e3552e298f5cddff2147b7af542ff78bc31
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:4d976434d17d1e0b4d2ebc13704626cd584f47495a1b04971a4f27393c823787
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:9a7ce5f8c3eea95cdc83831fdd1649f55290a44e72d6e2642ee50517add9e3a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:15398d58640abc084a1a414507839d411dc088d632578c1a51b5d8f61feb09a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:a3e92ba2f81bcd8b78b51399bcb11132a71370ff632a4759656eba8d8a03fbdf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:966c47ae19bd3b50902444a54c6d866c00cd6e934b788622ea07c09265140ef8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:f45dc8ded999f40ad1d0e8a982d9d8908c7a66867cc9ed8645036287aa0e5236
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:90e9e5b8002269d1cbd49812655e39f6c7682b7034d58d15bfbbacc859b43af2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:620193fdbbdd3aacab2011562e491dd2f5a1bcb989afdc7e8bac9e1a7b5598ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:cf6b38c67eb3ce451a49b2d7b48b7d2291fbf788d736870a7df40b0b324775de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:1d991d81508d15029d9881404f6fe21da56d6c7dae35c95bb55f35ff6490e3ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:1f0d3f6cf604b9d60241f5ee17e97b96426ef96306b631c7bb038eaec2a84e40
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:216937a2352c436d0a8ecdf362ce5846c898cd2220d5316cc4f1537de81ea7dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:a9e71494a1ba43f5ff2851d97e195a79bf6a8d24751abbd7c0947791097ee974