Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.42-alpine3.23-fips-dev, 5.42.3-alpine3.23-fips-dev

Index digest:

sha256:0c25d80a0519a462a10f3f7580cd6af471c706468baf0a90804947b76eb0bda6

Manifest digest:

sha256:2bc7c547bdbb5acdfd538dfce55b8e243b796154a88a652cf90be29e4541fc1f

Size

77.23 MB

Last pushed

9 hours ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:d0917f68517e061c6ec77097d58f909306319da8e36af4313ca91d66df834f3a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:b98006a4d26db2bdb7ed8afe88b1a1a53e3b81e7c5886d69319654fe80bf12f4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:512d2629c87d82f0c6404d096730ac8b7f941acc2b5a52960b96a1b333bf5393
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:41f8c8a132c9744d0eee082745b402e9840569f5d851a8e321e4c8e728a4ef0d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:98357f8945fe52c8154b636d3dd0052e385857a24c20f04ca202d85a44dd0e63
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:79b2a9a44b401a3c5a1d88c297c3aeb136f53fe3297569fa937d45beb4c0d5a8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:c8dc2e9c023596df10f4d249e9a35417cc68731a08dc9bf3a7cb92d66cfc8d3b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:7cdad042bdca782fe847ca3b511d2fba522a8ddbd9c9e1953df383b5594170d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:65edcb2121fd1e388387845ce61ea96cc2743b7a78b5c4b56b6c981bb4d325cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:053fce291cb253402051f64ab9cc98936488e571d940e2e31205b622b7d284cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:faed181b02c760fddd2b9c3328233189bdb4f945cd4c13b3e3841aac35bc869f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:641cfde463729fcfea11125d1723df4bd9c6981ecfaef3f9482cad769d6fc31d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:7b840617f2684c684f2d9d882cce28db2968ea17fecfcd197eaf868997f81af2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:32ae74f38777c6e394af7a580b2513e3ade08be7ff4523449a65aefd958d4ccd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:4294155a5f3debc0501aadb37718c05a0b706710d737edc52a61e505bba47f23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:abe8af2aa0fa69dd6dbee31a2cbc89d2ec325cef21209f9ecdb7a1b7a6c6b312
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:5ce7e69d40b2464f494ca9a68e6c956d1f0b09f3041feae1fac865a73a0c6449