Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips-dev, 5.42-alpine3.23-fips-dev, 5.42.3-alpine3.23-fips-dev

Index digest:

sha256:f4372f4503e906c4d7bc3d09484a427b1ece5586182ea55b5fc2a85608d07985

Manifest digest:

sha256:90cb24bff2eaa058ebe6e8518fc10097d43ea4cf60a8e7d735aab62d7c895872

Size

77.23 MB

Last pushed

10 hours ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:c97ad7f9025bbf28b6e8734a50572f0bb4b3533a064d6a923a8ba87a52f2b96b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:1649810b476db13205670c31d905acb83f11fc3f38ff33a8445b692e96b6ff36
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:07624ad64c866d29ad44ffc434ecdbdde508a5f9cc950d944db4898ed8f5e654
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:4093c62cd09841853a15e6970d75fc8c937ee8c98014aa163f18f53361fb78af
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:0f038a02f3e67596cbeeb0288731bc9568d3cb6b951203f9bfe1eb8b9642480e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:5b224e641c11cba36a40af8e222726cab49f2104104a1a4b6cd215172c6934cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:29f329e6029bd2d025afaca708a5a994ef310edb9a260f7898a3de9f15327a30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:60f342ddf591f8a15003896ecb3b33eec30448d7fbbde3498f32c6d807de3105
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:02c0ad1bdcce2e57586539731e2a1474295ae30bf5ca70f877b0cc39af1d3473
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:46aed0a3d2b5a64e21ded293d9f4a94e0deaa842d2034a3bb76362465c3bb576
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:7c1982b367de7fb8fcf87751f8acbfbc58fcd0c7fc343c1ef0e9122d51e376a2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:71f389da2c1403b0d3d271cd9bbfdd7c00098abda38a2a591a75140c5067bb22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:d1f2bc4c3852562f3e2995e60f50ac6eea50384e9477a36f027465e4be4c5242
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:0761ea107159c4d9f65ba87e70147b084b751ac092e4c8d3ad00da3977393b4f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:14ed79fb5f20e094ceff20bacf15ed2366736cc4d3dcb9f02576c811beb70da7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:1eb6660e31a8ce0609280f520160c7674262e3ddd01954b43ef5fa448e833072
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:30868cea2d1700e6bbc4dad77e54c76d58f05d27ddb34da0c55123c4326238b4