Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5.40-alpine3.23-fips, 5.40.5-alpine3.23-fips

Index digest:

sha256:bc536b76e33ac62fd9fc784994133f9d00c073b2edd88c400feda6c9bd858b07

Manifest digest:

sha256:2c1ac15e0ea7e81e3d47e95e750759e6e07a5d55c7c464cefa6282729dba7fdc

Size

16.92 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:c3ebd2c7f8bb13f5352b71645c656e3e2330d71fedf147af3547734f69ef2b87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:308003f0098fac0bd9ed8417d48baa9f6799546e331969845a8b1818cc348ac2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:ec223dccbe9f90d0892a1ef3750eb461f4fb6e74373804eda5ef7dd6441cc2cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:26f2abc7b66ac9e57f3cd67038e7c1ec5043f711ac88490ee031388dc2f97a78
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:c2f4d79efca7bc158184a4dc729ab1699c84d262bb19bf33daeed200eb862639
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:84782bee16fce44f6c25fadfd21e40a6a7799f3d76a4d4422de3c0fec47a7939
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:77b313c12c128dba0b86eb7b403cc9b1412e1daa23a19ef40c6aaf88c3d3cf82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:5ab8e312b589c29133a1e4f9084424746bfd9b25cb9bc702e3c0fe5f9b075a10
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:ab792b12f13992587ed0f84b0bbb66e54d3c593379a1565dd98002b508edc88e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:c4429cd91fd28463d12e536aaecdb67461dc5aed84d861c98ddf5fb9b74e59d4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:453035664221db7c61f52f99623f8a06608c6624a29e8943f538f4593c9550c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:15702085b2f911162404d6cbe062b46191d9e9819d5e2f14c8427a9d3eb3d57f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:b1b727c87ea2fa0e6955ec53fef8cee1df5a14a8a49f1cf5e6690a711ec88768
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:9c447ae39eec01b9567007e479313ed81b16f4fb6ef2853be6d9b3ec33a19db2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:a53dc83376469c581a66393a7d1dccb9db969cd66894f541c27669f474431154
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:ad092fb6e9fc852a21854f0370cee4e75a42940eae7c694124d95df2c0f662b4