Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

5-alpine-dev, 5-alpine3.24-dev, 5.42-alpine-dev, 5.42-alpine3.24-dev, 5.42.3-alpine-dev, 5.42.3-alpine3.24-dev

Index digest:

sha256:e8784ccb6da4ea324018b275a11f3ec2035f95cd2f55141808e13524fd5fa6de

Manifest digest:

sha256:522ba8e14b1cb54d230a2e5dff55e85367a447d629ef43d17ff04ab3bf2dc20a

Size

76.19 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:fd78f6a3e0a94d9c1ba4910b8f93b9272670fbc326e0aa41412851d3ce191950
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:2e6d60a1360b407e5ec40bb39294ae2cce23e09c5e2c5555b2c5f4e2e449e9f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:7180268b4c211de32559cb57da8af9c712f6250b003d32d17a03c5066f788d4f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:01965412fbdd48ea5d4755fa6d2a1f96224b04a7aca63b8d9f57564108eab6b8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:04cf54222c1b4eea5b9710323f54302ff11a75d04c1d947eb13281c980af708b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:ee34796173558d03edad0706c912004d8c990adc09fd9267b7b0287652f6939b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:77b123858f15e25e24193814a203db5a9024f2bb25140f681a083e852db5b4bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:b3e56a426c62366c4490abb1711650129fd2196b75355abeb09d0f419658e6bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:8d19fca84db1e17d57cd7bd0e52656a9d2aeec4fa34b4128ddc4408bbfe132e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:a8fa81cadd6312e730e752f809b2720f6748dbea306ada3e08093f097465fe21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:b4d27259fd41197b9bda554972583d6abea61cda30512dde070a3768da8a5f5b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:7eccbf768c958da1fe560afb2386c785d55be452a65a62d09d8addf8ab7835d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:3a2e68dc92cb2ac72f17b40f31ec00e1eb18fc15213de2142ce8c19c976c2986
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:1f55467a31334f0eed8838612d4f1ec39597997f76707cb123d2c547c0dfb502
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:59c8e7878ff7a7994a0b0a4aee3d30000a045048557ec537911014bf15e5f28b