Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.42-debian-fips, 5.42-debian13-fips, 5.42-fips, 5.42.3-debian-fips, 5.42.3-debian13-fips, 5.42.3-fips

Index digest:

sha256:feaf0179faf28ddeb543944c5409ec2671f038a1ce78a5f1146e795c16836f61

Manifest digest:

sha256:385adbc2a352175699027d6fe6887d6f14284e1a1fed58fdbd78824fecb0f679

Size

28.64 MB

Last pushed

10 hours ago

Vulnerabilities

1
2
0
1
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:08cc5dc5220ce9b5ebe880ba0355fb3e2650457e03ed5ad305e80320cea861a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:ef73f231932f6f63ef16893c2dbf1a3896806144da8a2a053410ad7061ec63be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:37557415fb2b587183c05c0bc9c37b48eff9f25ffa69721759884ae14d433687
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:249e53a5b85422076e2342b04780ad239d35204dfd94cf8a48043a2b5f39be40
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:1b4068131ffae7b05a814c0c4ed39f21bd3fb2decf01f69a2c951abb9471f265
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:aef531a0d3b1fe14b7dcb150514358faeb223cd2e042df5f34fe389228bfbb98
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:bebd88eee66f31c53db6d4607130eca9d835fdf04555e3727c468b29736a4e58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:f70f8b282b7ca6deb2e94291364ca8305b30ccb1190573f04149c48673759b93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:97acac05f7f2b4789061a16945b7ec1ab9e52dfb3364877fe3c350ebffe5c376
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:3fc0495fca793d95e11657e365d315f451ada703bd10906945d31e2a32e8a24c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:a56096e16920cdfc40a003331e6df3777ee9ff4c1c2356d67bfed3ff73ccc60b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:20e1673a284519252130c493fc21daee6ac28862787b0612b810e380e96908e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:8ac6b91ddf672b05870f933204810e3dcba22ac1b14f76067d0cbefc7fee6c78
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:cb0567c317de10f26cb221a511666d28a3adb1192ff5a9b03cd4ed3c65df4914
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:4904f28813dfe9f545b4e0d3db72d5d93dccec27cea0f58ed57a7d003a5797bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:b127c85041ed923c8f62c409718ce9b884340f436f935b9fded2da381ac778b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:997a752f093c23a77c3da68bf278cb7e83c9bee72b3f7d1169099d4ff823ed4c