Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5.40-alpine3.23-fips-dev, 5.40.5-alpine3.23-fips-dev

Index digest:

sha256:1cee2de597cb864eecfa734c6999bf643ab44bdaf153bfa0f49a0288a98f449e

Manifest digest:

sha256:a34cbd06995d8ba4c3a25436b123512e8cffc582da997af2335fde6e04b08158

Size

77.00 MB

Last pushed

1 day ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:39431ab2a53a26beda2e1903558dd50d74b06219acbf279e40f0d8b6c4575eff
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:2d0b47a80379e2800f3676d87bafe0fa8a5966b03b3a1cbc9973ba2061a2017a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:2be0dde58ce38c44dbd8d544ac14b86d4bf6677ef86d97a308e46e71e8a375af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:059e702132336da30466ac5872d6bf345a0af7e3c83fab65425a57c4af3afa39
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:123d38f51511fac056756ad45203308890ebd510bcd0fb7dca9e08bc6b16f2e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:4065d6b9e9f6461495d56c3aec144fb73e4d42cca434c4498085d0749c191767
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:741ee351d872e2da67932da4ef711fafba69ae47c0653765a56e4c40fd93b3f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:009783ee1a9ded43b139faef5d27b0848a4f4803e7fceba7d46b710bc76e8ab5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:408c8b623f1902da14360a855f709e3f89cf189d1d06e25c7551bd06cb9d3711
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:bf1087f14138e6e34576c9151101882a9beb20d2efc052ae452e894ec4fe70e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:60c97cf2f16807993d24a6ca871e0dbb6cbf8a1780f17c93c6d5bda060072c94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:d87f841be58e1ffcc3d34bbb9b6b2c5126b19fb00060732ac43979c66ed55089
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:8be282a72a70380bfd9660cf324571dd1dc4802c50cb6e2324c4d339531574aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:f935b8fb43bb4d2396bcf8dc8286f4227c8cb48a2c78b27781588bbdeb4444e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:80965d4f7e0c5dc5241ac97d774b233ef53472ee68300a5ba01ee73a3adaf470
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:1aa25db83f3308caa78eb5d5d0b2f200c93bd802b2ce3d11b5b1a8bebee4eb45
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:3477eeaa62445d8cb58fa6419b4388bf50be2bb9b95e9fa092a2ededdb7d01ef