Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/arm64
alpine 3.23
Tags:

5-alpine3.23-fips, 5.42-alpine3.23-fips, 5.42.3-alpine3.23-fips

Index digest:

sha256:755b82c99e50565ca34182519111dee39121214edacb278a4b9b8029617fd513

Manifest digest:

sha256:4ab3efbcbb6524ece0f467ba8af2493cd5592544d40236a963fee5c968dee8dc

Size

17.24 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:d12641487bc7901be02df8d666ba1852859df4ef05dd0dd2bbb6c50bcf410752
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:be0ba44d162af4413860c77fcff640ae747cc5bcc1c406d36b5123a9620fa41d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:4478785854a8b40841dfcef835b5868b44001b248fb7baca20c7f9ee286e3744
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:50d58c9a610828972171d65ae6090636dca5dfb856fa9666314c0ce2d6d1e1ec
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:6d3b4813c7f4b5fbfde11160afdf21b4beaf0f34d2d21d2f14d3a90194c7cb2a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:e4334ae281983ed2cb05746d29d533f944046d5e70efa64a98b28cf621b2cd67
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:6bb29bea72b3795997660afff9ca4aa085cf1526e62a4d337841661b27ebcee3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:a499f4fa426bf23ad4bc142412bfb5a5659d1065fb9ad75042834ee03d9367b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:45c0e4daaaae839b28e71870b731c844a1283b480abf5c49f7da34d254ffb287
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:1dd6515ac74e6689ffa52753efb7556184ad293bc1f985e2cc28357bdbcacad8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:ee98f66631a7339f44d8cc081f935bdbb59d0dd92f2ad9cae2a4fa47abfb67b9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:65b538f3b7fc02bef3ee3bc975157743605dd26acf7c8284f6713e6eefd79aa0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:48b15d772154700cbdac8f31d18d6f2804cadc6f6172daa3970556459bdda1df
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:d532addee15f439729642c71998d3e7b4dfe86010e30d041765531f3553e3ce1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:9346bdb2c0c57f364b3898dc479f02501ae4c649c4ad2e8b300d9f0a01b5f434
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:29fe20e46d9eaf78b166fb42fb14612c17a2b25651d36758d04ec693cbb3ff95