Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips, 5.42-alpine3.23-fips, 5.42.3-alpine3.23-fips

Index digest:

sha256:352b8d1bbb2724bc750acd65ad1ee3341be3883a59ac557a5f58d241a7e960e7

Manifest digest:

sha256:853a65fc2504e8a0222422e9142086e3d755c6d111bd12a6497e0ee53188ad18

Size

17.14 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:aee0d7145daf3bd005e84af08a6cdff9d021c3a443d09085894d22079e8446ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:38ba4fb0bf0283212328fd049cfc0c1b36ed87655903aee7bbbe5fa560b0dd8d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:dd548e933ee66068efc6aa0588a3bca0f6af43a29beee1536371acecfd17ab53
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:f0c9e48ac58dfa3806bfcbbfe44775b774b15c7ac931bb7b40f90e57bdb53523
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:bdc553cb6349e6b197c872d889a2d2ffb617bb6f354dcd480088ab02c27944b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:554795449eac4dd3ddd4ef557f320f2ef2453658eef919ee7a4c4574a82c1166
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:44a2fde666e33dcc279bd0dafb789fc6b3219e2b34745aede13240230d30d713
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:e2750518c12f34515dcc89abfae70b9873104122242f516ffb5a364331f89b73
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:00c9021cb348dab7f7fcdf7008920ee0feaf71084fec555f1212c1402f56f6c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:6178dcd2a48430d04096237d5565c713c507f23f0ab8d9cb13b71008aa17f624
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:b511a664f99750113b73c67568438612b02bc08ddec2a10036881dc25d36603b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:420111174f96f65bc8a939a309e57190141f09672c81f20a1194e4a24fdd1ca3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:63328225a004411a00734de58fee9b4395662655f8c294608d5b5202c5fdf906
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:f1213146af464e75958978625bcb485f46f69fe765ef339e6812a6b6d2791d39
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:55a58b14edeaf23dc477127f996c9cdbbaa009fe0a4f78b0db07404a3136929d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:e7b7905010b5f096fa969a4bfaf886a0ed42de84cbfc6619cb5d75d5335cf7cd