Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.42-alpine3.23-fips-dev, 5.42.3-alpine3.23-fips-dev

Index digest:

sha256:baab45098b998f77b8ffed485f15bd851a9d40d4eb8b2e73057d2c534a6e37ba

Manifest digest:

sha256:131a3533b38ba0921c484360403955b4353877ef3eda017cefedd77881e217a4

Size

77.22 MB

Last pushed

8 hours ago

Vulnerabilities

0
3
7
2
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:07a4ea71f4484dd5a38065a9ab388e44c92fca5b91c91d960780badff9ce2017
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:6ff14bdb5543ad2cde812ad05ad496f5189e258d1bc1197ff9eb513cbee0716f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:0f9448b82a58f7a2c8803b4e02c0c98851d8af1fb6a1842d31ef86c0da073e8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:ab709ff279329e6e23287febd4d33d685a0494341c747b60e573bb920760e0df
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:2731807f25abe410e716f1b652e0424a1a92b4cf2f0cfe945c98c3a010f3bf5f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:9cfc135179ebeb4d099cedeca5e7ed0f0474a276112f99e8a00abf15d0cc20c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:8d785f316b3b44e1fd8f9f1709d09364c1a2ed6abf4edcb2278c662378dd9da7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:239768d912041f3c906962577b7b9e6f5e51ae154ad189e35d02f55915d82bb1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:bc0576bf5570a2b775eeef7761a95f20c8227e351463d8daf8250a101861fd41
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:b6965a42330ce2bbe2c59605fca841a64c42e1bce69a89aa91be16103de2f313
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:b4193fc2289fb767c9f95774b470af204a25135b7490be4ed796ca0e2786af43
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:821785199ca7e0f77b246a5193d8047b9399787e737c5568058b32266a6a1695
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:ed5e4eed51d0a74f2981115d1525b25f782d61e94e83093426c20b99c79d8e7f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:2d6c98b785d227b28f5f76d93c05d7f3df8356d8bce73a5a4ea490279d7a5321
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:00866b3ce03b0b907d62473ab222cfe72eddae2feebc06224b7dcf468a61bff6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:52a63a633a59400803974f13dca1eaf98e0ed646fac1f0fd5343c8ab621b75ac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:df2d595c521a64612f79d70e82dcc99c3dbc753a8094f90ed5d5c54ce82a9a0c