Sign inSign up

readystack/wordpress

By readystack

•Updated about 15 hours ago

Image
0

725

readystack/wordpress repository overview

⁠WordPress

Docker Scout: Grade A Fixable Critical/High CVEs: 0 Signed: cosign

readystack/wordpress:7.1.2-CE-debian-bookworm-r1

A hardened, cosign-signed, offline-rebuildable build of github.com/WordPress/WordPress 7.1.2 (GPL-2.0-or-later), WordPress.org's Git mirror of the WordPress core release builds, with WordPress.org's SQLite Database Integration 3.0.2 (github.com/WordPress/sqlite-database-integration, GPL-2.0-or-later) as the default database layer, built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout Grade A — 0 fixable Critical/High, non-root, SBOM + provenance attestations; re-checked daily at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/wordpress:7.1.2-CE-debian-bookworm-r1.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is 7.1.2-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/wordpress:7.1.2-CE-debian-bookworm-r1

# ✗ unsupported (do not pull)
docker pull readystack/wordpress:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/wordpress:7.1.2-CE-debian-bookworm-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container: Apache with mod_php, one foreground process, running WordPress 7.1.2 as www-data (uid 33) on port 8080. Self-contained by default: the database is an embedded SQLite file on the wordpress-data volume, through WordPress.org's SQLite Database Integration drop-in, so no database server and no second container are needed. Set WORDPRESS_DB_HOST and WORDPRESS_DB_PASSWORD (WORDPRESS_DB_NAME and WORDPRESS_DB_USER default to wordpress) to use your own MySQL or MariaDB server instead, the databases WordPress itself is built for. WordPress is installed by the container at its first start; the web installer is never served.

docker run -d --name wordpress -p 8080:8080 -e WORDPRESS_URL=http://localhost:8080 -e WORDPRESS_ADMIN_USER=admin -e [email protected] -e WORDPRESS_ADMIN_PASSWORD=YOUR_ADMIN_PASSWORD -v wordpress-content:/var/www/html/wp-content -v wordpress-data:/var/lib/wordpress readystack/wordpress:7.1.2-CE-debian-bookworm-r1

Set WORDPRESS_URL to the exact address people will open, for example https://blog.example.com⁠ behind your TLS proxy: WordPress builds every link and redirect from it. Leave out WORDPRESS_ADMIN_PASSWORD and the first start generates a password into /var/lib/wordpress/initial_admin_password instead.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:655a38dd2…

Size

250.1 MB

Last updated

about 15 hours ago

docker pull readystack/wordpress:7.1.2-CE-debian-bookworm-r1