Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.40-debian-fips, 5.40-debian13-fips, 5.40-fips, 5.40.5-debian-fips, 5.40.5-debian13-fips, 5.40.5-fips

Index digest:

sha256:f899a831ba07c6c2e9cfa66115984bee04f98e02eb20072da11bc6658e732697

Manifest digest:

sha256:15ee68c5ec0ec3e96a8b2ba61836234e534688593a9f752873a72b3ef4eb89b4

Size

28.41 MB

Last pushed

16 hours ago

Vulnerabilities

1
2
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:f5566f525d8cfda66a5088fcdaf3c89cf1f370069e064196231605606c2981e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:cd3498a89481169815272180fd13337e88e4ef613e6540e5b84df3b6261671cb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:33466392e8c3cbf21d289b7f163d650dc547ebf667ba3e5a46b4667c7d34f3c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:7abc3213c1a2b6d2d20ed435ff6b6c0e3614bc918395c38f094761e075111400
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:62cf28caa5cff6a7367c495efce1d218b7f390a41091cd8a64603acd94e28899
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:eafb14509eb961f73294b943604d7e73d39aa9215364bdc619c92e7505099e2e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:2bced68394c26b356206f663ce9d7c3cf11739d79dc45d7b8dd07ada5e083e3b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:8f9f4ebed4bff42fcfa7417969947e6e9af9fcd9e73624c3fec9bdacd4d24f75
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:709b837645e51b567e1d7c3ba9209fd6bd68b8d1ac948e30e2e11870eb10918f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:d312b9b5d75b9b6a443d3bcf8470cbe7cb1ee783795c7b6acf6dda430f54a149
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:1fd10d47fe0a395079b158af079fbdc22e4029cf4811cc9575dcdd4cc5195aca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:a9e5353faf78d65a5ea25bc58cdbbd5751530fa3a1655edc3e19d10354912a04
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:023a1f557f9cbf12debabed441f89ed86fb4356eb5b927264abf5d334b62bcbb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:7391247650d45a203fefc7f508bf9d0cd63cb04f7e790cd24ad0634effc8f0d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:d8a9bb61b98eda8f1a8ec45d0e78ac5d7bd3a5a01b4b55fd2df8613f8492f070
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:5e3fb2af87e18ed8a19aa01250f8fb9100f1ed8f0e3581ea134d73987d66a13d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:dc42cb22fa00bd1a4f03b3fe6479b6a5988548ef3813a9f68cc46e64f02f44ae