Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (dev)

CIS
linux/amd64
debian 13
Tags:

5.40-debian-dev, 5.40-debian13-dev, 5.40-dev, 5.40.5-debian-dev, 5.40.5-debian13-dev, 5.40.5-dev

Index digest:

sha256:48ad177ee5edd3c2d0bdd80b18e2e5bb2c6cbb4c2a4177ef29e43c1c23db033f

Manifest digest:

sha256:76e0c70e4b135f6d607bc62ab998353bcdd67699ac9bb23ced1c12c489ad50f8

Size

97.68 MB

Last pushed

1 month ago

Vulnerabilities

4
14
9
44
3

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:b1c3a66d5671446eada07797d691feea20474e6b8cc59c4c15069145360e7fc2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:be6b7a52afd4226f22da362f5460df5b19feaaeecf87774fef0d1bb7657b42b8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:08ee41de6242ce1dbef6916132905d93acec1536adacd282061fcd8b711f8ef5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:7274900d1649a8869162296ad69ad0001d5eff73126ef4b072661b7b7d46a3f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:e02b7c7169656bbfa33f00182d359b712312f1413159740ee74c3f5f0173cd53
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:8b678d20ca71af1912209d57d0a2d17ab1270863669ac18bd0cd74669e810b0b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:53b9e421d64b2ec62864e76e1d5afc05b4e7d61227582aaafc5c5630f078d8d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:564a44c197f0e741cd7ea0e2d43bf203d211cf41969d02a06e8fd5246f57eed1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:2f1db93f981372a8d7b2e5818a3aa0911f5ab4818095125fc9f052ee7a08d11a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:298e1eaab5cb25a97212d24264f33c5cec5f7eb1d71e58dc53e02529929510f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:20820558e7a423756bf28e2f7c447c7641f060f97d6833962bb15ac6f90fb4eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:6ae850722be53f8b8cf56d964dafbb0d187db742261f35aacf284b1155d0044b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:3fe6f7181093907288e9e09c43955fe6bcc6ad029185497291c33005b15a8a04
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:341db48ea961c68dc2ea1007e839c564b205e9473b5867c39c334b264970afdb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:ab47c888129397216ff7e97b4278ef84605a1f42dbc1bcce2e95ba202472363c