Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.40-debian-fips, 5.40-debian13-fips, 5.40-fips, 5.40.5-debian-fips, 5.40.5-debian13-fips, 5.40.5-fips

Index digest:

sha256:ff630ff8e56abf8c9a99a408e135ec676ae64bed427266848e625e231030d7d8

Manifest digest:

sha256:e0e8adbe14b67479d63e8823f65b5578bac080b546c30a49a5dfeedd426c8d5c

Size

28.41 MB

Last pushed

6 hours ago

Vulnerabilities

1
2
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:88c4912e790a92acd7bff1e12ce0ef44986245c68962f135780cc3dd943da939
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:fba9e6ff7aa01fe1b77fdc648176161afd637edc4d6fd4a19d4b88315639d152
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:a3641cfc144a22e8ab3ad4641da3450db3c43497c798401aa309783ed26fc8fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:5aee176dec7ce40c2379604cdbb1ef6ebc0f6a9481288e1043aa73ebac8b0745
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:ee6a58a217fdc44f6a79ec04089b874c18ae7ef056416f730518de548a76d276
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:6e7ae04643a8d4820ee8c6fd1121abb3e2383239a6faf59c992cfe11cc128d17
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:90781ed1ca537c40a1857b6cf7bf7e1a08fd6d1f92e2c46546024b5ef6ae5acb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:8ea266e8f4b83c80637402457a4b21df625fdc154a5056d18e3ebf2b9c9bfadd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:94afaa026446c894cccc0c3fc4e1a0ebc5e4ecd2301c549fe4b3c95ee6b94c90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:8d00843999186c4f7c44baed3886ee8a1af6e6a6a2c8d4476ee0e3285a0d96b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:31c2cd19b2a66fbfbc3ae7abac9a4946011a9d0a7cc4d37a8d8f7e594c698095
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:e9c1162e19162d2dc420c980b4205d0b263f90a15a480f6af96342ef4be3b0ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:3faea8d4616afd168494719f4d5774cb69c902b05dd0b1d6b38c615c63fde0bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:8ad824270a1b8fe87ecd0cb1d2cafa25a2f2ead6d74fa86a4dd9b04535a2a352
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:27ec0c39f4b5a06bab73d10acba946aac89bca0660b19d7122d610268cdcfa42
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:5a780cf243d2ca95311169fe05f596ea8a7ad47bf9dc7e2b2d7ed110a6234b3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:d3678ca320faa8b4d253728022c1b71f1230bd150c160b004f01c188d983cfa1