Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.42-alpine3.23-fips-dev, 5.42.3-alpine3.23-fips-dev

Index digest:

sha256:b054f53ad6b681565023f70f7822c878f72289ae0f10c872db43db6e581d2c72

Manifest digest:

sha256:18f6568fe8b070b2ca8da8c8db1ac780c65d98b7d0a4eeae1e5c784994ed9d08

Size

77.23 MB

Last pushed

7 hours ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:c8c5cd08e632c4fd0e601cf1ae589c8b0003b792debb841670c0a7877b79a295
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:500272bf7fbfb08a9c1996dfe7b44d6887f70f7c434800956d9e3d85a79ea5f1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:ef7f2ecc2a87d37a07c8b1042612d05b75006763aee0440c15afa9cbccf66fb6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:c3e3b9b00ad200734e5136e0f2215588623631f9f844d401790255473437a9d3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:7020544c8acf6e389e6a57c75cd0a057e047d962200de9236320d6c24962e640
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:679473c6d32d12f758a6becbdeef2b250e5ce80fccd55571432d0ea45876f0da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:e2838948c1db856cf7ba5f745dc39c1d064bc5b0926d8c6da4af9edb502e5136
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:9f19a511226efcc80282f4d07b9aec1292ec467b2c18bcb2a2057ac7f747978a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:98b69950e23a9ffafe9d9e94ca9e7cd50596f6485539cb4bb77bc2347b465b2d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:6d3200d365b7f24e838be0529365425945d56dccfe97d4a2126aa0ae456bc694
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:c10e7261e378809ae473aeb9331892c72a9aa65ef97aaff4fc2d954ee29fc1bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:33e21b571cc74dac1a6719a0232ca285578a459e4bf79bc834978b61c1f49c58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:30f75009ba8352097d9558df7dd8057f04ca8299ab41b1d8a4d86cd869046fb0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:4146667054de4284a13457b86e27172bf7ae75d17087ce34076a904c198a0a3e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:bf8c0c125eac58f2d9ec63f7a455554a3c64c02e43dcbaa3f75383da819071d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:e0c5ffc5a1744c5945a72945becbe821540a4102ebf1e23e76e7202a35a1f0a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:acbec00703330c51e92fad4693903e6892c2f67b47b807397ddc7bfcfe25e2ca