Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-fips, 5.42-alpine3.23-fips, 5.42.3-alpine3.23-fips

Index digest:

sha256:755b82c99e50565ca34182519111dee39121214edacb278a4b9b8029617fd513

Manifest digest:

sha256:de53aa992324f95256f45ee608c721b2eb41ffdf1335f7e1bdf2946f14043883

Size

17.14 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:473eb7133116550ffcaad21581744cd2af311a26c94f05bf72169a7ed453843f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:df85603f741ad183fbb52af1a0a394c7b426a5d41d851c98d28f410df9dac5f6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:bca1eb636e883d8d8df13ae98332a2e155a31c6f91a2c093fc56563580333960
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:ece3686510066950bda6f3d6a59dc693a4169787d767902bddcd6fbc9a42cf43
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:2c7d62755b47990fdb797c60e7f2b2eee99e957ce3464bdc15182a7e63129662
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:796de7fe66e2c86c6b946f7daeee0bca77982adf0ad0e6a223b0d867a45f5f51
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:8b7c76730c7f67f9aee2f37de46fb03ea54ac9d6627336e50f2bf71e4dc1a94b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:8cca96dfd0797ac0ff4cc957024fc48baf7fce689bcc5b4c6b89ac6cc547d67c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:8de1ab87302e6c929db9479ea551aa0bf30cd7a303e53433f37884587f6b91f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:e3c3c7b56f8102f54078e3ff50e9f8934042b4552340978ebd30f60dadfe1b09
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:e2523d79a1368c1c6571cac86b6e2cb2db459f575c6031f0ba87c905baad2026
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:67b0731206894d29499f3d4cc7aa9eaa69f687316d713e4bd88103a952879dbd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:7e8e2c0ef96752e7acf32992979393f4a12ae7dce37e8ab8a05304b53b1338fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:578beebcb2b98b168d3a020d1afebf56881ecc01395d4e65d54d7df7eed9e2f1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:4a36682af1dbbdfa20df5d83dbd6bd63bffe933b3ec4a6533de930c8cf2b2ab2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:8da40c3148464a52fda3dc71d8c93c30a49e6305f75095daaa0e498c6882e3d1