Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x

CIS
linux/amd64
debian 13
Tags:

5.40, 5.40-debian, 5.40-debian13, 5.40.5, 5.40.5-debian, 5.40.5-debian13

Index digest:

sha256:475d525ec68e2e0044e1bf972da850fa0b09a2490b6f670c18f33b0edd311bcb

Manifest digest:

sha256:9f9ef4c13dfbd78714009679cb58d6b57e25adaf7e290d35fa20f69de4e82b72

Size

22.47 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:de54e27a5ef18edac721ddc5dfb367a1c09a605a1cf15418c2e150fa71a4f0a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:2b82dcc3c12da1db2aacc3aea4f58aac85a88b6c38cd8020fadb87177db5330c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:2aef4bec9deaeb67ec0aede677232c92b46bdf5b6b5cf6a194975a734169794f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:8147c5deb39bb4a6cdfe331ece8c9936b6aef1a3289e29ac19164cb4c47ffaab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:d316f2ef122b9a6aede70571d884d697bf6ac105db2b49a243548495a346a0a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:3d2a7682dc266cf75058bc78535bad9f352588f65f9313ef61b4df4ebc145b4b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:8c15706f95e50ee4f789ae5cdbf7956403c2ef0c97603382dcbfaaae40f65f20
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:8fdbe0cef0cce2d1d498dba2c728397738f6df1423703bac5ffc5cad54ebd55d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:a6c652dcc48fb7128c8b1e0b3b06987d2d57b89ce42ae5d8800914695d76bc80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:cb73bc324b52ba4c62722c40e464c1d28f542c3c583c6281c71091c02b84c170
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:b9b81c3a45442271dededb0ac95a46f490c9d587c9edea5178a9c346b5718e20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:89ba41291dd322676ded99776ac056140a3d3c6830c935d262affef8b267e40e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:0740cac2acdc9410eac115214e471ee50942e52008f1514579d40ca669b8f3df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:c831494d8be59c7c311063acc4596ddad49cfde0be7286e545cfbd7cc35e2f93
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:c84f5ddef92056ad2308a53f37d0602f8b7640daa368bf806ed8be6b091fb8f3