Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

5.40-alpine3.23-dev, 5.40.5-alpine3.23-dev

Index digest:

sha256:9608857b35e07e837eefe1bd1404ad21a950f1d022b4061a4bafa9f56bd9d3d9

Manifest digest:

sha256:5637b908739f0ff5214f8f470ae04a5a40b7b628d102c7977cea95923a610245

Size

75.98 MB

Last pushed

1 day ago

Vulnerabilities

0
3
7
2
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:242f898f48761650a8cbe99a9bdccbe6d981a59813f1a7c84a1b6e747bf24e7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:a6c8aa48bf751ee3af143ec0c387389424e8ec2a300c3957596c91d6e42a9442
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:80ad1810759bc3ad2b83ffe496c72ad57aeb9c49e449f03cafaff184f070bf6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:aaca8b6ae3799fbfc3e11f39680b3911389601f2211089fd2378a425d8e36eea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:5b616000483b9bd390777f64f8d49e3fb8271b2e76a42af39ed73f62cde0b528
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:9089333d3d14eb8f7b67197e2319eb982bd62cc6bfc19253cc62ec3eae53741d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:004485e1d73f37602fdc263540d22832678f6613f9af4aed980bc7cb33987be7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:612ecffd4aa848415918a62631e720b58f6e3badd4b6337534bec692d7556c16
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:59ad1e85d0c863e6f72bab5d4270d36ad3d566fa2bdee5b853034b301a08f14b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:2dd10478d837dea6f1c7ed68de5694e9882cced63b16907feed32f255869c4ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:0e1b2f1b80c249d5a6ee420c2e9f6cad9886ad52009106125bca7898ea48296b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:c9973257c9a14c01d81c73032343f193f8025963f1f929e7f73c05b7a2633b0b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:4eec3a672126c5f9ef3bd636713b2e8ee5e1ff51dbd435837cc99457ca3594c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:5e4e4b4f8d0063f3b082921a2ee8f7e045189e2d1a6fd2c20df4c09800f9fff4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:7e4a2e66da61beffe896e727c031f1c6676f0493c809d1a7fef52124ac71f9f9