Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.40-debian-fips, 5.40-debian13-fips, 5.40-fips, 5.40.5-debian-fips, 5.40.5-debian13-fips, 5.40.5-fips

Index digest:

sha256:b5bd5e8ec08df8d835072ec6959ef6119187c6190753313f93ea30fa47244fca

Manifest digest:

sha256:e9d3d9448e2d2dcd4202a99a5e111d2d8cd220decc083eb7dcf940cee42cbe59

Size

28.41 MB

Last pushed

4 hours ago

Vulnerabilities

1
2
0
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:6fbed1ac62fde72e8709efa16661e7d9409996085cb45a8cc0c388e19797fd98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:ec2d79bd1db0815074587e3bd2c8280319e3ffec1b18fc316de5fed8e9f4ae0c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:fdf3f2cecff387d10e31f7c892fe7cce689cb47db22e73d0fbdd83465536bfcb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:963daa8d90861ecc42a24cbac39153de4a8c26287951860f130722353dff5337
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:7622876b14e4d2a343d7ab7933e7e55007cb632b2bf7e4568475850d6c9b088e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:ca1e317dbea181e03325f28217010b4591831588eb207ecb51a5063ead75e12b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:51b2b6e339b3070bba1ea04f6d140fc409a3bb9240477c7ff1d9ae206f1c1afe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:9bae4c7ca1eb9f25635113e8f0972acbd1523fc0bc4c107c32fae67ee5a67854
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:f6ac36cfd408cb34b0841d01633bf7f5b32f6631d4a38532affd55642692340e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:8fc86edfc27ae478081ce5b006508f5eecf64f0f6b1b937050b5fa67c1b0ed78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:53ef434d04e10020f44428c971163c29186399e57589c9cbe09355ca884a820b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:93b87d970e472ad0af7af11b06524ee57552cae8d56d98c1ddf9ea8459c4d0da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:a808b5a2fe701b51c3fffb789757528935cb046e25c38a0f0097432610994e28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:f635bac949dce4189a139e62d94855742ac46d26b143fd1560f0f0dbb31b377f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:7cc1d21a34db0a67f155a7f81813e291dfb7d314f1492416fbe961bc9d67b3e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:99fc22ae78444dccb7e789612110b3964bdc907110e363572635e7acb4ae62ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:4d375b6f5f852cd557397c478ba03474f96cf9f016ec0425dbb701195bcc63fe