Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips, 5.42-alpine3.23-fips, 5.42.3-alpine3.23-fips

Index digest:

sha256:b21883f141ae6bf6db10e2cdec65440c394e436c012d712b57de67f690a0b94a

Manifest digest:

sha256:8f9624fb09a2b6aba60e8130698252c7c58b3a01173f12ce5012470088dfbac1

Size

17.14 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:51ba5051db00e61dbd375e89ec5a4e43362b382554af3b1a71b2383e9f059d4b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:3573d7105d6ec1f67f884903053fe34d24a7746b2d4871b246cd95787d147170
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:aad53aec96a7da9353335ace1560f7dfb28500162a57ff42809278b6c1b835e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:2788fef8f7784d9dab937fb80d71b60ceb832dbf45a34429e761f8bd6956a3fb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:eb369ae3b73318a850e4bcfa2dcf8e93234e6605f972c805c3685ddf1b97a3c6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:d43107f6c03ec444395858c86e16ff40d703c3214d52636c9cf21e67dc7159c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:ef6507cb3e0409d3147ab5465f906989cacf30c5a3df73486921f865781dfde1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:21ffabcf64b06091e4bf907cbb7dc4237ffcc585d4acf4be5bfba1799e976cb4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:17d0b115c190a4914cf88aae8dc506490ca0dbe90822dd53709cb0c007945271
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:11dd915ad990206356666aa69e8f20b62fdeae5300f169d10351dec8cf48ff6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:0e8ff7c4a0c95cdeb06cbd980c17d789baf0be823167e99c472ac63f82b1e44f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:52f1343129ae78e804531693bdd665e803e66d0fff98ea2e2bd6edfa42a1f8c7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:a70b9e6d0b786f97a060b7efced405f06f50fab6c69807d23dde5baaad71d56c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:76a8ce94df315a6ce65255716dcb183bd05fb3b3894d834e9a927d1a6063ed52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:653c3d8dd7d64b6dc64ce25905b84a93f25391cc081016e6a2f82b5fc1504dea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:bf770c9dfdf7460ca68bae39a103f42ccf607e8a5de2b86bd562b23580e7d42a