Sign inSign up
WordPress

dhi.io/wordpress

WordPress 7.1.2 (php8.4-fpm, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

7.1.2-alpine3.23-php8.4-fpm-fips

Index digest:

sha256:e0d511ffe60b85cbe3ca85fc97ff6411a41680b2a0a003149e01129a41e924ec

Manifest digest:

sha256:eec922d28ff93d77cb7333b8a837c20447a21b4e382fe6da9a315a58dcbc630d

Size

88.36 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
4
0
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:7.1.2-alpine3.23-php8.4-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:7.1.2-alpine3.23-php8.4-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:cf12e04e3c4778a5820f5871043d793c6351d767e8c8dc9e3ad0371b1c73ee93
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:fbe6c6e5475e45235250ff8acc0d7da979a64e7e290f7634a848806a3de33716
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:28e6a6a3078a51c18abc5092682fc5a83cbbe2a735cea7c48482aee696618399
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:838d6189eb172232122004560e0d97970bb37579675972746de265f6f9d735d3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:040045671891d3edffc579fc1845cb38b7c8966e2d8604bc782eb61eb193ec7d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:dbf6c28b303d26541351732f68d295e4d59e793859f4d1b23a20768359bb69fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:284c3043cd5c803f3325bbd541dbdc061b562fb0fd12690544414e4d696d8438
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:4e6a76e3e80118e537f72df65c6c30869b6fe63d4f4fff938239f3fc923d8b1b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:58b5e00a1dc86ae4f8ea97e29d189ba53246f232e0be4397353c1ae3568d8544
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:5e41405a205168442e36d268feef436ce0b873c020efc8f1db3400311dd0810f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:ff4c9bcdf2b99b59d134f9dbf198db1aabc027a5bfd6242b5c9f942b4d30cc68
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:2db3a80324e86568256c37340a68bdd5520c67377d920a4edc857aeb05845bfb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:3dcbcdb07ebcdd410592865eabcf52bf963d9b32d5c43934df758762a2c02df1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:a970f4dbc7fad837b64f67cfbfddb28687aa06237e51eca5aab22ab349e532be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:8113d8b9a13130e6792336be1d82719de0723cdb3a4cbf551e5a768dcb2aad01
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:717d1d5ba683759acf6ccc82f0288367a569799c8ef2f165b8de70f3bd35c5fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:cfc4a5015bbb39b4f1459e0e0f2a4be75f3187f659dfe87944bdaa428cf1d8eb