Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x

CIS
linux/amd64
alpine 3.23
Tags:

5-alpine3.23, 5.42-alpine3.23, 5.42.3-alpine3.23

Index digest:

sha256:f55d36cfa26e31142ceafb43ca716e3b63ea3215b61ed9334c00977fee0a3b8f

Manifest digest:

sha256:51e8b331c1e83218e9be4cc61be6b881c1a20dfb423dbf92fceca5146db6b426

Size

16.49 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:eca2cdb27bec0cd881ecda9046b5dba073f9ffe45559019b48aa4c116533d907
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:f243d6912731eb521295c7773ee186170f8f968792ea0dc19df401ea710ba160
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:ecc163435c95cc9c0ec9b2833e6d7b01def2389460a612aa016bcfe9d5491839
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:b2ae307a992488f0ffdb70cbc31e69795207ec7b3f58ec2454b8a0e3e6d011ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:256851fbd1663ca4123cd06141ab30410db4712c905dc1e027f4c328a5a41e7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:0995ee4657244aae4660e806fe70be1ca06dcbf6103713972ba4d8c8cfa00016
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:1daf5a6ad9b01b088a5355f0c5e2db9b87dbbfa4b1170ca86de2f0c890991995
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:7b88c6def0cdcced61ec943e9b31e34709845fb4c4c4cfcdcbdd8d718075d502
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:c49fd1d89de91e8fe00d9b9950e025864ff2c15482685cb2a9fc8fa08ecaa8ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:2c210e618418022bfbb655c8e96e34241bd1ac3a8aab19144fb70fc3fd67c935
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:2c425cc712a512ad50580afc3a5cd1a434548de72090860abc10cf3a085e0dd2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:fc0cf4fc9c2f7d4882ba72fb5cfdfe33033840af040f4e52ce1376f8cc719528
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:998065a5725ca43c02ddf47f9fa3b84efebd2d336f52481b24c1d4682bb1fa20
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:7bdce1ccf4c53af8010167bc274ebde4cdb6ea61199be0489f9051e1e93135b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:64d3d233c08c596363889d3acaf723f772583e8a65bea4084446f300201bab42