Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.42-debian-fips, 5.42-debian13-fips, 5.42-fips, 5.42.3-debian-fips, 5.42.3-debian13-fips, 5.42.3-fips

Index digest:

sha256:a57f9c1d9e97c5f1b117a2d96cbc06c97faaa419561abc9f79d565325e00cb2d

Manifest digest:

sha256:486e9833159dca1df1deb1b452815fbb59f0d009902ecb658012db1e9b426ff3

Size

28.64 MB

Last pushed

4 days ago

Vulnerabilities

1
2
0
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:ffd9ba9cbae8c4d2606f5d734e4869d9710f7eed2b01e90d21e486f6cf7c98a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:5bcf7275dd93e2d8dd900606fabb74a5c0a91b28401618773d236fb38b1ff030
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:95f487f5a3257d57da70f6ae3028804863040815a5fb4e90aa9ee37503a7b38e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:5b5e5265bdc44ffe21dc0de2c98c2b9206d0d017c72b7be142bc2e3cd4adccc6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:6d96fa9b9415b1751ffe41b361f1f70cace326228db9b2981f0fda362f92af82
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:db4e22f7cb54de6220eb8f48dc1caaeb526cfead32c8a817c196ff8e7b175c98
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:2284b53b40637cd6893f364e64358883ff0092c1f525064825eca3535dcc6e4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:5e3d62b2a9964f64de8d1cbe53730f4255eeb84ca51daa470b755a74c52ed860
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:ac62df8c0190bae1f5eee29dd8aa9991f904a33a152b32453e0cfee512a38d64
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:383805755ec540128a1fd318cc0a8900ae49cd28f8c6530a9340d44b8970e44f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:a424c2a55d9179699bae44efd6622b16c0b4b8cfdc18c34d2a9eb5949f24fb3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:75920c7d557c6e945896b1098301f141a3322d411f8385056efe66012eccad53
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:4f8b813c658a1f2e5a4e16ae0e715439c17c5faa818ed47ff54cfcbe302c405a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:682d38737ec5f74b42ec27bcfe3eef0d756a69bb769fd3cb77b46284974fd455
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:c26967de5212cdc87f26ece1ff591dc7b17e042efaa032b8603932e4fe81de2d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:a7b9881bd5c7e9436a0e185a4bf5e7f69ed0e1b3540f43616c741f1ce2c4c1fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:215f8d4bb2fe613f2b6bb7a1cb7eec6eebffef8a29f4ca32d918633d96f52ade