Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

5.40-alpine3.23-dev, 5.40.5-alpine3.23-dev

Index digest:

sha256:b186d1ad2505ac5db85146247a758c76d28f5ea33caaf20604d97014e9b2ccad

Manifest digest:

sha256:2d969d1a9fd8cebb914080b86ad99030b6d06a653882c18552d7cbf8c04633bc

Size

75.97 MB

Last pushed

2 days ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:d51aa7f2ecea33c935b08b9d134a9169225693116ab615dbaff24d7ad19b00c7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:191eb3ab381b69934dec800c9b8aa299e0b07cc083aa50d6f18ae475c590454f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:b7c5739d57c9692c30e3070c241b17522b2868983ce2171552bc5e1131a9c1c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:db645e26eda39739a2bd9bc5ac22c30954574fddb8e4404d9063e76fd81a5bbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:23f9c84b57e973f609a5c230ace1418f8004154a4a57eca9d02364921874c292
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:73734b3e3e9b7f67978f50293f0fc161c2da3a3b61bf477534805d3c7a281211
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:87dae6eabf67481345d6cc63e6ec104fb9890bb7fc4814d5a63ba9bd3e549b5b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:915491d68626211ea1df8838de92188ec12efa057d37c3a11ab6b6847fabe527
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:ecb5f1051a5b2c3f8cc0df7b08354a451916137e5f9a8d867f0bc4492615460b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:39d496089b9385c40258b593e05d20f1094422b955003ac51066c586fd4d5bd4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:37a821f06ef8009a13485dc2f6ac5f8c2e47541ac7f28b712daf7fd0c0b9d434
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:747b686257ba91f2b768d3794a0579322cc2e6b6081bb901459ed3d2a5f27826
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:25586e82bdea578ea69e0d16d7b15d15f116d615153d2b7186a6f3c8a54b1630
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:f2118a38ac1fd2e06d68feced8c9e17df5ea429d0ffa1e2016e701988c728b44
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:25c1be6a1ad255e65b2576f852785377dafdf450af9602e7efb94d908b712d7f