Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-dev, 5.42-alpine3.23-dev, 5.42.3-alpine3.23-dev

Index digest:

sha256:42dd7e45c24925d48c482fd6d0c7a64a913e9befe31186262f164e45c2393134

Manifest digest:

sha256:eab3aed8e8793741218cea6571be02847f681c39404c4c848c7ed12c387514d4

Size

76.20 MB

Last pushed

1 day ago

Vulnerabilities

0
4
6
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:5a2c3c333c36651f887bbe3fb3843a926200ab88883be5bf46fb4ff5d21d80ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:e4bf1d8289ca60146e04e788861b3b6c1208b4ed61288170e90edc7de28f81fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:f0f813a3c2b0ce192ae06dfdda1c7596d6144b8a707e36ffb8fb858f7aedb3e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:4c2f9c38c94b25b90e01d4a730f76167e504fb39acf809e65b824d5b37d1e795
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:85f4bc1a2bbee15ee8ccf13365a26769d02bb152cea29f78c07783f2410ebb3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:4ac8673af9fbe549787c02d8911bf6195729ee5aeb2d9cddfcd1c9116bca3f07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:f06e2efc95cae127d492d2260f2d37f35198135689d65784dde515a812859b70
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:f8eb4cbc7a49517a625b1178a702a1f2ef9448a9921712ce8efb55edb2c9b1b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:3be7526f5d9fb88c79f5f9c740412913337d447aefe25e8eab0683e335f2eaaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:f123fc72fbf9b79b4eaebfeafe1e0e6d5d5c0b2243bd56f9754e0e04bb3e5040
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:1518f8071d12b62feccaa615ea24e0081bb30a043a5bbe86f46eaef494b9f2ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:4ee2c1abcec6330593f2d6a4be7668e288860dc60e166524e796a357182adb4c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:e9361a60d8f792f3d1ba8744eaac1f3399ccceef3156459b3707f153b6173395
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:572dd7415eb9e900570e3451fde84b06afd3fdbc4e8bffe5dc49f166f875cd27
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:dd11077e94b98d6789e09e0f948c7324c0ba724cb4a97e095046c9a38603b13a