Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5.40-alpine3.23-fips-dev, 5.40.5-alpine3.23-fips-dev

Index digest:

sha256:746c85e5111881be609569b55e8c0368b96bb4c30b6c49b64cd9fd3d27ffd5f6

Manifest digest:

sha256:b7bb04b30182abba5cf781f4982d78fc0e80b7c45c22f780805be19e350fb89d

Size

76.99 MB

Last pushed

10 hours ago

Vulnerabilities

0
3
7
2
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:9c948092510d9dac0fc15e6cef72209bdf0aeaf03e364757b47a3cb1491f98a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:48a0ceeda55355d521c9315690fe8ec4bcc0b2a59494a44442be9d0b824d96be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:a66b4a181d8b7e9103e82dc6301e23ecfc0e7032c9253da9f1077058e7c5b2d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:d24e44e7db1aab12c75655df84285297037817e3a5e75a567d18370cf4b3d41b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:deb164ebbdeadf6d7a431f14f019639a8e0742b93b32bd0b941f65f7410a0f93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:b02aa3fa029e0ab19ee06424295f1f0ba38881ad200a07f4df09197b8ad276c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:8c5c24de480940accd3b76a6e5934e46a96a8dc787c4666475ce6f0fbcbc6aff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:8a60abb03237bd43046067f532e583123fbf72c6290552cdd028fccc9b52ed24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:db82aed1bca6bbb9be5c4710e9a4a0218b3793e66c3606b45f073355cba532c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:de8b68c649c532134d244f127b9cbf52092d35b702a912ea24bf6fa996a8761d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:a0e6f2caacb4184eeea5f9e474303bfac663f2e9bdfb03974dd5b4990e58054a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:11a3a0c3e8179f895bf884c6c68d9fcb3ff73c4f94fddf570c797dac67e2db4c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:c5123407da02470a0adde6bdce506dca56881f5e19d89f9ab5b919708cb8ead2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:8eaae5f2dfd936df09c1fd6d57c798984d14c7c0eeaa6fd2d2d8923c237e3873
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:77d92dc99ac1b008d34f6bba48ebf88788988de596f20e749f5190b70648c264
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:c08d0b25087a57c9c3f86372c7c471995fbb9fa024d3a1ed8ba0067d74a4e5c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:e39c1a5f30d1985cc4a40a16e710abdb11cce8400b555b31f92410fbf0bd7b9c