Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.3-fpm, dev)

CIS
linux/amd64
alpine 3.23
Tags:

7.1.2-alpine3.23-php8.3-fpm-dev

Index digest:

sha256:f3fae00beb35d8fed093fb6dd2f6de6a4d045ebf8c75f99be6d1c17db2afde9b

Manifest digest:

sha256:e25c057eb65c0de37eb00f5bff8e4743d30ae4c7c8586e02087d90815b391633

Size

85.00 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
4
0
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-alpine3.23-php8.3-fpm-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-alpine3.23-php8.3-fpm-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:6ac2477e890302909c99dff77022d546a230a8386339b7c2b09c339af5a6e814
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:9ed018ec53156c338353c7d56e4e8be378d54ff283e860ae044c5f5e854b95ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:faa8a0f1103ac7afb7df0ef8080b25d014f7649f787cd9deb154037e4f2a27cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:d5224ebfe25aa9c417d35c110bdb1f5e85f53900a657a6b65eca4033eac39dee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:c07575f7d58ab39ea8c0b3d44a5191ec442cdb3a4ae5c2b8a66939e7b8e19c43
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:3d0ffdba9070c279368834c6f93161874411cbf780bdcc2b2a29f9baac4e6f1f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:e7ce7630b97a1807978edc65bf40eb111007f2f884dbd586d80d252de66dd3db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:e1303f8a8f1d55fd41fe2cc3ec4c3393666e9a955e3063c1abf94b6c711b303f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:46d190dfdb34f2265a3e768150530916abf49b95c878bab61c58f05274213c24
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:abb2940e9b0be0def39e06d1ad3fc1097385b530c42811999c484a3898a4d7a9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:831f4a0c4a699f3766e0adfdd90f37425d1729f718c1b92bff76ca1f016f0a9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:5d934f2d6546a338c25dd92a998e46e4759cc06a31df42738681745bb6b321e4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:2a755c37b431a7d33d29360a0160ef065792d6561493c6484f2980bfdff2a693
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:1db2faebefea13208fe8555967f128b68d078cfba910128df759c3f1bdb46f6d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:0920246d238bdb32463f76f503764ef0ab93732603f8b99d412b26ed05ac28ba