Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

5-alpine-dev, 5-alpine3.24-dev, 5.42-alpine-dev, 5.42-alpine3.24-dev, 5.42.3-alpine-dev, 5.42.3-alpine3.24-dev

Index digest:

sha256:da4ebbb19754857e88018f1aa4c0256520e7e85edc0468f8473c3f2ab64d7cba

Manifest digest:

sha256:6c0abeb584e0a26fd9e0bc3ce182a9e1c05fca38043698c15ceaaee2476e106e

Size

76.19 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:624c8071a093238db731f7c289e9fe771b2b04f8f41b26ded55c6b6b8d8162fd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:699e3ec5012741c30d30e3a10eb8ba58a3e0872bc0ef03945376ae435e2922b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:ba73678fb49d3243a298a8fd3488a6d5370f717dbd2fee7ed955d5ef80fb5a93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:908261c73bd6ea84e72bc607b0f20f3fd9b100224b144408a750e38ef227b3f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:8cc5f4aa70626e593f780a72fa9e37b1eaeb12c3cbb3c7ce090496c87be4ed12
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:716dae87233f107d179b1f2b06653858003133da5523422452eae79b7b839bfc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:6ddd6513701861c450de2e102184afef6d780992fb1b6d71854dc8ed279c55c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:796e8f38c1e6db90d606e71b61ef28d5ba4f1002bd36496c728eb1468c2de2ec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:cc276e573600c31446f2775821b824b46d446e20b41030e2ae535a4911b372bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:c7df41eb5689b64136b0e3268638379085a2032729fe3e94c2dcc0740bbec743
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:fb3a502ab4d5282d6d5b861390e486d5008218a50522f0862fc524099c094443
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:36cc79abe9cbc5ed8311237e519864bc71a86ed638bf22c7367890fb2ad23f3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:b65b286b9f016bd7ba25d2c0f5cbb3d58eef199d2234a1f52c5a6b61b88f367c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:956479234584398d6e8570ab42cfcf58acc821f74a2b39843bc64f4f1fc74523
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:e8924f9bd3ae4cb6e17c2623a5807cbd21b147349603dbed0fef80486a28ee0d