Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.42-alpine3.23-fips-dev, 5.42.3-alpine3.23-fips-dev

Index digest:

sha256:b7afe31757bab13969288c2ebe8fca9e9ceee535596f67494d67c7dda53ca720

Manifest digest:

sha256:b29ad5995076add4c23fcfaa9caaa8f2a3e6528545f59603c9fe865ea701ce9d

Size

77.22 MB

Last pushed

1 day ago

Vulnerabilities

0
3
7
2
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:2ad204e04c3aca07919a3dfbd5f1962446e7d1e77a920e4f98d0b7001dae15eb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:56a8219dd122bbe48f1728a4c45535b92222f0ead601c1005d569ec5a642f065
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:dd8eea1df10f4fe82b5422acba4ec0b97c29f04e9b492172eaddf58f054525a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:ca676dd88a0a0b799136d2de53bc6b4b231fb896a2d52325f40cd5c7cf65b3d7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:ef8b82fc393b4d677fd1f68f5452439b0476d6f4880b00c2b00fa0e71a034748
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:fe5030734b55d2bbf351ad73b02ab1cb5a1a3b51a19b8c6f1b881e63efb701c0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:852d701cfa95943f7b0f6e2062dec34aaac94f59cb9b28264c880699471a4c7a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:ba997439ca270eb196aa8ffaf962873e517a56419024d416bb82d6c2b8fd7aa3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:60f7c0f2d07fce7a2586784df366d3ff82e03b2701701933831d87b5ad1c8afe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:fb65c8837c97bb8c346effe129591450f9e7383cb18b624042cf12d2d99280a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:4c019ed25b5150f1c482528e6a7570efa7e1ba584dffe7c63d54e92c3b59031c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:061104b29262b8162bb8b679610d35105fdc890a2fa537e2553690348daf3a02
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:84be521a6a750798e22c9cc1d47f9d90e953b9ea4f0da5ee5c102e56030661e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:cb1e97452dc90fde459a5e1a69eb96837fc67604cf8a3b9cd1c8cc8c88be7faa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:32a35530d9bad6bd2a2ccdd1309a541f9ff0b2fe90ba103753dae893fe518250
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:f698839bb2281576951b91e3b6feda7deccf66ebb006c9080876e89fe643f2b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:16373a792f19239e2d7028c3b0a7122d26223793a519071719ad34fe7259b1ac