Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.42-debian-fips, 5.42-debian13-fips, 5.42-fips, 5.42.3-debian-fips, 5.42.3-debian13-fips, 5.42.3-fips

Index digest:

sha256:9557547b8319805b422cb91da24d3b13454411a7ecb394f6de73d3b54f5d738e

Manifest digest:

sha256:b2e5258ea54bf89ec59713aa8918eb805c18d3582f9d9d88d172ad410b2b6a45

Size

28.64 MB

Last pushed

4 hours ago

Vulnerabilities

1
2
0
1
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:1693c21d198480d97d0f01b7bd02ca133a294e0e687bfaea08505aa6b04d9754
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:7fb4ba08b4bf33edc35edd531c03508a84d7a243a6dcbece8b43658d7087ef8f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:a4e36253901eb3e87617df5559d7414438e595280991bc169cbb6f589ebbc6a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:0793f41fb135bf604f5f454075075fe553b7a7f71e706cf26c3ea3365e839f69
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:1ab3edfdc7f8709d4147e2b9a658f06513d871f11fb702066f83fa6e40e04701
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:0ac048e3b242ccd5171506c2c592557958f337b555cd967a6d70c2ce89ff6f66
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:a17da577819c1c0034d6c9b1dcca5e76da521b1bf2de4f11be8039003131f9c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:731b6122ea9fbbb0365562a67002f0670cfa40e59ce4d07c8402e49a5cb85c97
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:8e021850b6cfb61b88a6c2bcc9609e84f51cfc2c9335f0006c29bb9f74142978
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:1cfe26fad3ff3d8f0d040322dc628ee6d1c514cb4f31784f0344192841bfa57d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:25a71ab9d62e0049f98227056d25d11c1e3fcffae62032f5d27395b41b63f087
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:c32428cb8bd03993a2922d6a3f1c646c4ecceebf94bb3e597d29ac8fa0990321
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:64f244c6127263d55eeac564973fe1a02f27c0ce3027966fdfce009feabffa25
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:4faec09eebc0653b8101b77c9593560d5df2e87243981f83d58fe50c20ab710d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:de060abde92e4325cbe7a75a2a9f1e63eb49a208ffcbc9571a7d6030b6e41a0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:84fb18bfe0743b485e45b8861e313becf09131499d72aed43a096306261aef4c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:f58a3fd4f172920fbdd2965e64d19a11d772463851a911746230c7e2e2a69b19