Sign inSign up
Perl

dhi.io/perl

Perl 5.44.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips, 5-debian13-fips, 5-fips, 5.44-debian-fips, 5.44-debian13-fips, 5.44-fips, 5.44.0-debian-fips, 5.44.0-debian13-fips, 5.44.0-fips

Index digest:

sha256:7841ead91ed99c922d0b1e4761848266b9065c71c5c7ad5a0ea23030c6700a77

Manifest digest:

sha256:0a2c551662968cb5cd80a20cb45f11cdbd9cb6e8f8c492f84b2939250bb50103

Size

28.86 MB

Last pushed

2 days ago

Vulnerabilities

1
4
0
0
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:5f1047dad09de12a040f5f0f333bafbc8bcc5c9d1bbf5a6811d930700d33b18d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:998a90ca5ecbbc67acb13062c3eed8acfe6e2771ee574ddf1b34bb23085e3b0a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:d2f1ae0c8412dafa0986142146457fbc8e09ef8ea0df000a76a07846ff25672f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:86529053b65d07735aa4512b1d2fc95be8e5dfe37054913f1d504082a5c9569a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:281adf9c3ca8e2d83c50a40ab9be5fbae7594c76ab459e7c888ae5900595cd6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:87ab9f260cfe25d432f648ff9cc17bf3d58bf615de24873608e543baf15042cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:bfab68f47b7d002cfbe1cb3441f7b55276e39ebc89999a999229f440a8487b21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:2c8e463d29e0c2cf27e113c4a4c7504a07f1dffa7910a0833920383b8b085921
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:715baa44b43299d4eab5052f7a802a53e648579f8c8594d84883c0cb2c893525
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:8dd6b26d8a35c78b17308965b2ad858108a29435f8f3117cfc6a24f400094f0f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:d84d33fca82f573133f41c7d8f8907fd9703003cf93afbbca605aea21a0919a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:ad4733d2ae796869a1766413aae1d15e00c54ffcf13d2b176107dd32a9366d26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:a34b65ad45956e62ce56ece91c7a75a710565d499622b246739f141ed996b0a3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:f44ad32c1e62780b3febfa44caf67ab88926516a0602cd6814d0d59992c7b69e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:4d612c69083e6afdd16311c0f41b5599700fcfe99fd26d39505cf6a0d18e456f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:08f6a6dfcf783b746b6dbcae8fa1be6f640976a6587680e86011ac947a0b8094
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:ca5aa5508f845e35c375596d40658540e9e38a4b1407a4fbfb33b1b1b9b189b7