Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.42-debian-fips, 5.42-debian13-fips, 5.42-fips, 5.42.3-debian-fips, 5.42.3-debian13-fips, 5.42.3-fips

Index digest:

sha256:818bdd10dbf4adea9e2a6341a2a2993554d61ba77c3d2d8d4016d0ba6eaae2d9

Manifest digest:

sha256:9480e93734ba5105f86adc9fdacc3610886e11cf1510e810273d9fe19a87f723

Size

28.64 MB

Last pushed

4 hours ago

Vulnerabilities

1
2
0
1
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:28f7097eb9260be0e2499f5c9fc2f3eb17ac2835c28f8a184422bf4dd8d8423a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:0de36ecebc260b643356cc5c6dea5c37591ea82bbefa7cf997db9f9e59ba330b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:09136368d82ca1a502e70994f06f7bc8433a84ce67db47546ac73a8b7d9c84cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:59f8b3b0327d0bf2b99b6b5c37386f38fe86a9eb05cb06af6a2a2186300f9420
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:7e2f4a4dfdca0349659b1cf934ffb2e19e00fe4684a1bbd91272692878a2db3a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:b1a2b7961f9ee1d036253fdfe0d332a8dae9b6d428f115cf7138fb1c96b0db3d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:beba1c42ce84b0a81f595dd11b7beb7ab7719965febe0beb9edba701c84e5b53
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:99ece90871f5014ef6f6ce5adaca0fd214df295a907a82863d27ead1767ccfb4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:4ac4ab1657db6d75f1661f736cad6e1d53a2db148106adb1c57f42831fba1e41
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:aba86afb72244c7dac31e0ab6ffec78953c6a0ee83e72e42f1eb22aacd98090b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:68fe9e905602e439d2571a045155731301a54d5f20340d8bf18ecfc63d8c9e27
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:12fc0832254be4e58b595d8af82d092106d721ce9d79e5dbb89d889aa520db95
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:c06f78f1dc7831b6a9ae152158deed8b905e243e2bc3f6531f6cf7047acd7fbc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:6a95df6a22c2f49a842fe16ee8ce43d7fffb0b7d8780cdb4dadc843913c34b79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:add70a0af99a8d3a1b85d26c9b4225ace229254f2e3f4f4f38fcd5d419134a86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:daf238e46395a916412d488067ddeb325c3f92b52398b118115a9d0775a041a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:cdd3ddd2f847c7f81db14025e2d70e07d1d8deaa4af27203098ba84f1b755d8a