Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x

CIS
linux/amd64
debian 13
Tags:

5.42, 5.42-debian, 5.42-debian13, 5.42.3, 5.42.3-debian, 5.42.3-debian13

Index digest:

sha256:a61b48e4afb92471a8d17d56943dd2b35956d8e453cbd2cfdc102e1dc2c24354

Manifest digest:

sha256:9f14908ea87de00e6f69af0a63febaae843495aa934cf96f9565c1a2385571dd

Size

22.71 MB

Last pushed

3 days ago

Vulnerabilities

0
3
0
8
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:ee760b1e886f6a3d2726509dcaac2239b3da4eb81f9fe2f3bae98a2bcf1a7690
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:918ef1aeb1286c5d4b0e7655076328ce22118a441a72ca4c56a7867190744255
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:855021e9b3ca1af4b5229dfcddc5427ad43384c7ed5050608f6f22cfd63028e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:f598295448c14a076be14c55a10a0f7b3f75bd084f1ffbb115d20ce269062056
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:f2279214ce4478256d0c2fa4ec367ba511d5b1f03b4f1193fd665c01e589f5d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:4139f54e8c3d13c653aeeb93bed384c886d8dfd74580fae821dc8f7caf000155
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:8fbc9c07c2de24d21e3218f6a6d99578577366c53d8ebb0ec2baef43c934c589
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:031a85ec3f980d0c1bad82df772b003fc0d376b9a6abdb0e2cb87c347aede198
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:c1b9fc950312e08b6e92762a74599654eb745deb02e22e1785a639dd557b9207
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:15566aa4effa2a466ec604ff0e1d1b81b83dc46475e4d9a2128b76815e997c0e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:dab53cb233498902bceb6605dd5d7031e0a7451f8328de01fe05ad43a6821f08
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:48f50306d61a40828dfd2a358dbd160f75170662ea4423fbe104f9a5db69316a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:abf8888d5df639c488c14e9df05fda24199a35b9f776b68e92a3a096d7b3f350
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:ffd402e4b1cf5be95445f95bfb750469bcca2b2be71fb2e2dae5bb0098b423c3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:98cc1541524f13a0366a828670d501968aea727a3a20d56aa00625a1ad7a120f