Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

5-alpine3.23-dev, 5.42-alpine3.23-dev, 5.42.3-alpine3.23-dev

Index digest:

sha256:827ab921eeda273e4e8c4402673c85587a909446f50e7241c3c858e2360c1782

Manifest digest:

sha256:8c5cb6536e1a710e3779db422c0373cb905456cbe1cec8b53fea99bfeb358f56

Size

76.21 MB

Last pushed

3 days ago

Vulnerabilities

0
3
6
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:4e08308157bc1556dee17a8afcd628dffab3cab48544ff960ea2868ad480c0de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:97094e3e752b6aa414559442e95079e5afff589286d2d71a5ff17b1fa4f24e12
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:517f17f7a7faab3bd88ab1d95329f1c0cb9b71e02a32d9b53198a2ae35385879
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:f930cff59a509cb417958d4bf03cc742136f34eaff9abac421e51ac47b6893fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:551edc9493840297987b2ca60522e264144935591e303806b7a1b9af55c8e899
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:046ed774beaeafe117a119292dcf8a60a35ccd82fb16ec558cdb3fc8c8e37087
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:8bdc6e702117fd67f47856127659c4add208f071e8783e93ab25adf0ca9ae2e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:916f013420187abd15e5ca003d5908f4e04feb1e6f7c31210151ca1405d65be2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:f29cfaba2e041bf6aecc7c2eb01b3ca70321aa89e10da1109d10b4e46c24d3ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:be14c4ce3db7a02913481d0eff24ad3a66dbfc7c5bf91d7ebe368059690c372b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:5dca4dfa8b6bb042af6568581d79e6db57ca24a3f9e09887ec5ffcf52403856b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:f0abf7493217c1a082baef39c0a50f23d0db07259630240ab7826e1793a92037
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:a5ee377e39fdd91d66d9943795eced0c7eaadb697d5610797592dbbe1c4a42ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:4f1ee461cbf4939890eb2a3729b05cc56ebba165fa575ac8da8d43d7455816ad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:fc12216ab74bda0862abefaf2daef8cd4650740b5ed09135b0c19312f5f3f778