Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x

CIS
linux/amd64
debian 13
Tags:

5.42, 5.42-debian, 5.42-debian13, 5.42.3, 5.42.3-debian, 5.42.3-debian13

Index digest:

sha256:03e80db3180b955cea3a8349d930cf490dfee2d28bd92be61f672bce4b7f4cdb

Manifest digest:

sha256:4c5ca023fd4f4ad88dca3e679b8e40f942b7625fc0ddedef4c979a694695b4b4

Size

22.71 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:51597842ac19667c768ee7a5f78461d3c43793952c429ae925112db4fe696bab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:abb7459ea939cec2e8f255c34ec0519e84116479e532533d80c8f39d66d6ee9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:e942fc1d6cee9a12c1980e806910ed0f7c54ba064311e4699138265a7cffaf35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:0af2fc5790163a8001a97340a0d2712049d9fc16364e1533c345053a562037a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:60f2721a6e902790165f8a6f7a6e992fb4aca3a8b6815636a1dcf3b8e81b5171
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:7d064f2cc2d46b6100b654de55cf30e4c236a333ec88e6b4f6d86a82d9fd6bd5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:c00eaf66c6547514dc2ce3d10e3ee327cb75a8f33461c0a7fb3b7affd866b2cd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:e58381d56bc5acde5327f078ef553574ea3ff84085fde99a8924c90570860eca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:217fed03b951edf3231c926a9fdfa4c8a8a8394e3fcff304f32cb16028f4d11d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:b84fa92620c0ea3ce6b6adfff3606ab3e231492bb589434db18e592c4d66ce65
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:27eebea5c1a64b8286691027d8f3a2161394c356cb73993ad07b414a43016f7d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:445a50ec5386d20bd61ca90d1d76e9bc0439f697a660666d7a6d99a6c2b59002
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:627ff780adbaff2e11aa73e9be284e8faa96ad882fa751d77ba71e762ad32f74
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:55955088b6282dd7b4c805a9714bfe7a37821193ef87e0d48679a331be13a7a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:08a00e1c7affae8e1d1b88f20c4a1f2fb853d1496eb92770932a1498ca5c5284