Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.0.4 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.22
Tags:

7.0.4-alpine-php8.5-fpm-fips, 7.0.4-alpine3.22-php8.5-fpm-fips

Index digest:

sha256:b18ee9ea234feb6109e2bb2014189fb2b05b31e83c4257828a58ed40a00fdb84

Manifest digest:

sha256:55debfd31865c5e0d355fc4bcfe1260ce60268aa02a96d828ff77c4b9f17d3a9

Size

76.40 MB

Last pushed

21 hours ago

Vulnerabilities

8
19
27
9
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.0.4-alpine-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.0.4-alpine-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:8cc501fb70e1de5e6164ad97da8abc934ff912e30fd66334370cf60d0f38dbe3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:ac39eb0aace913194e13a8e2763bd01b5242f37fa9938edbfdb4b2b6a4ec9387
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:3e5136660ecb5049520578d0f9e20e59f6badf6faf97016c4df23aa4e778813e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:08629a85a77e8c8ab41d9050f2cd57c0da66d3b45ab0828a898f4bb6140a1a94
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:9b29edf0da40bdca7a12c5b6950257e46e9d2ad9fc5eb8fb718e36296775f83d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:e42fb82582061c48277c04347ef242e59050fdaa31468b014475eb83df9762bd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:c6dae35062c8c4e3143d670bce1582c8ab9b25d9b665fde06cf0dbb0b864b7c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:b8aa73768ea6f3def357829845965938bac1ea2199afa16b568e1e91b886712f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:cbce4210668d3a7b00d36b9f265acc393b7454dad170e79953d32d674a418c94
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:9266cfca221bf77befb7cf1b09dbfcb6370760e9f7273825354a7046e7d2a6b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:5370fb4dcedb279b880b5c0e781245d83979c3bad1f04ea72c36a81eb0150c28
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:72eaafa8a7d2024f38d07999da03c5aff4466d10b886579db7e2c6edb0ca653e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:9f071436c29536368390c498fda0d3ae43ce1e4ae362f4ee13774d124d0cfede
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:59f89f66f95324f289abe7e0946b49819be16f3bc113c8ed0f0918fbd2bd7a27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:96d2ae0a614f78924ce678d35fcd2489c15bfa3bb4e0c1bbbf07a0edb3b1a228
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:7f362f1a2734a9827ddf965cfc89dff46a1d11a30cdcaf2f498ba129217a450e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:2c34255a1247cc00874ad6b983a93dfd612b812b20c92b89171731225c4543db