Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x

CIS
linux/amd64
debian 13
Tags:

5.40, 5.40-debian, 5.40-debian13, 5.40.5, 5.40.5-debian, 5.40.5-debian13

Index digest:

sha256:efe4ae1a91ae585aad2d320d058c034a351a2d026da3bcca8d8ed884d240574e

Manifest digest:

sha256:04917039f522c1ead0e9932cea30cd7adf5b997cc8b8374d414965a57cb98f81

Size

22.48 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:e53a2ec69cc45eb19adc5b29da55349f6ad21e97002202e58d78b616a98a5dab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:84b2e49dce6445884b8edbf6acf6c0d7ed285b264a2fd5c38851114527992ce6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:b7d10e8bc6db781be1dcbd30336f434d2268a0a523b93063e665900a80850050
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:5d1daace3d7dfd617fa7dc4c18d3b66ee17424f1f827b7d7792bba0de060e6cf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:bdc4b28b18d316cf90b1137f6a88f6e81c9a4f21bdf48b86170a7e72a5cfded7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:2a39097d2ba9a6dec4d7d5804d0a2b26dbc4ded279adbe61da4d6bdfdeb7ba1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:a666c92da4b04315f792bbacad7fe03fea50cbd3521f52a83a04069f0c29f9d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:6435ca5700cd9ab763186fb4d7afe8ef95d18c51eab932c836f16305ab25286d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:b451413077113ab5f213fb3c856c322222a6b6d0bf44f6e6eca1580a6774ed6d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:179176000bf67a33a920ff9a1b66888a9a8ab2b459a898b09e95a6023c5241e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:498434132f3a519909236fbca169eb05c3d538281a517052861dc26f871a77bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:daa432371a6c4c580df5e91a9bfac70daaf1a17b69ffbd4d482960d55ccf3fbb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:3fea666189b122b37376a27cbd26a6fbf503d798291a8d25ed2ef6dee68107a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:cb038e7980df36ee23a6217e66b6215532702c66f9cd82cfa228674ed0a1d23d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:9e593662e272ab9532468053b92066cabadbb5bad6d72867e5fe16f6b09db144