Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5.40-alpine3.23-fips-dev, 5.40.5-alpine3.23-fips-dev

Index digest:

sha256:796cff87e3a3e5259f6b4e22e025ec057e705753e0137f64092781b10d6eb2fb

Manifest digest:

sha256:8501d210466ea091e3346861dc44eb4881630246672e3c73dc6c1a468cd249d0

Size

76.99 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
7
2
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:389bb06d843d9c711a064ac0e33c1cb47d56c0f888f97e07876327a5fa4859f7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:714795353a05b2e9cb669b74dd96a2ceaa2d87b7f0a4a8fd1f3502801fbceab0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:a497f7a94a51e45aab3755d5ca60f496ec673c1c61ebbd11a70c856a438d8196
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:e65cc70081368d89c657321bc4d84ce58fb9a59554c595f43e46631aa54c2cf2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:a2f234c428a5d0f52270a644e70b985b80b5ffdda6dbe3cf3abbc8a16a70c828
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:22921e0d5f2000176e5697a09e7ff654aea7078925b2cbc72ffb5647d53a5614
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:3e3995af563aedc04f2b08eff0d80d526cd1ae7e8db6c2c0d076a35cab6b0ac6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:78311ef22caa4777edfaccdb0ead93bf18c1f57e127735187407549908986ac5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:1a8a7101dab83bb930aa3a3afcce8527b8cc511d6ec5254230461a95573ea1e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:414978a39e5156837b86e54f329996e8eb05756215f3f2606f7c0183dd59ec83
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:4ce61a2a82f0237b0b01446233c007de706c8bb1315c76a6f83f185f32015eb5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:37e928e3d8640c34549867d47e411913fbc7bcc5a0465c0d731a56afc712c647
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:7b5c1d021415735c6905e1f14e59a0c69f1d3e774827b0ea5b9e02eb5214608b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:f1fbcaaa4009319fd270b606df54f6f0ab019acc2bd045e97c5487e2202f531b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:c65e0729f793067ca473693f74b8d60391aca829e155358d54f6eb13d6edcbb8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:91eaae61233a4e860454e33f4d73cd86796b22be0c57a54a3aed560255769427
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:b9b239534068f6387f9e64792843b21cb2b0950f68587ca6cb517e3f9c07a497