Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5-alpine-fips-dev, 5-alpine3.24-fips-dev, 5.42-alpine-fips-dev, 5.42-alpine3.24-fips-dev, 5.42.3-alpine-fips-dev, 5.42.3-alpine3.24-fips-dev

Index digest:

sha256:c5eacbe0f38abc3bb4d5822c45a9d999bf4fbf05c8663356966b6c14926b22fb

Manifest digest:

sha256:b45a89d19eb802c532c87070806e7f33bc54876898432f788fe70ab4ae431d80

Size

77.25 MB

Last pushed

13 days ago

Vulnerabilities

0
0
0
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:fba6ce1e5677ff303af200a89b85e5703a285235ddcc8f9536d6ea4b25581cba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:685bea57b10ec2bcc8aa9fb91b829bee96e6a247d8b96f90e379826b1711a364
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:eec24ed0699a3fd34eac5b2c2c09875fe6a6c64002298ceb2aa5a467e49adad5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:1839c90ebdfcd905b340ee8e5829b68cf5c0bd0a89cefe7390ed29c4339419c6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:11931f86a90a0b4a742015dca682cb9950d8d55db772dd23a7dcc7069c61dd84
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:ea4605bc1d936ecca3eaabb9922f56414c6f495f7ff7d70ede1d0b16b3e5ed8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:a79457d33f76075380fb1e456ac3ba669743be634a451ae8bf6db64c04ae2497
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:83df8edf571562934c91df6a5f69d690a2e834371997d011814f89d39946c4f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:285ea66191422f2836652f4b96f24a32aae9b135110629e92efad703efa482e7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:55a7f56c56aca8b2575c85f68977bd407e167f8c95da907aac7f07ccfb04734e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:e10b3666bb6af4f9d941394ebea264bf9b1e7ea639dc7d8ca29a33724b407747
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:78d15b301c752d576472c4d08c72c7c85936d661a919735d3a495b6b17311a5c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:64176c2368b04c591fb4495ff3231881e208f97647fa4a1d5814fe9595b1d87c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:14863a087d098e131fe547a7305aacadf7f5f024307fafa4be31e6fbfeca3db5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:8369742636d0df3d74c899b00c2657be68888603d2b755ea7b78cc024c3977c4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:5a10011859a47562482e04f7a33e92eb537b3b0d8fa7850ba6632171fbdd3b6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:5e306e522ca4aa075e6d776ba21bef9439e8823448835ec724623342eb44bcce