Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.42-debian-fips-dev, 5.42-debian13-fips-dev, 5.42-fips-dev, 5.42.3-debian-fips-dev, 5.42.3-debian13-fips-dev, 5.42.3-fips-dev

Index digest:

sha256:e874c81f88f1f6dc3fa861056c7b3ff30cae9b559ba560d8ffdd94cde78a481e

Manifest digest:

sha256:220c0ac8a8e65509cd242a02e930a4987b9e1b9cb86a39e391decf8c8b9b681b

Size

103.71 MB

Last pushed

16 days ago

Vulnerabilities

4
11
5
36
3

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:6782787d9221045530c3639b486e37c9ce7edf7a8fd9c9b50114c9b7ad4b80fe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:6c0659f3ba264c768d11145262d6f82f21d46ecfbd81a7f28385900856e9cc98
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:f1b49ceed3de043f942496bee892a5da72fe72f8901efa9d2eeeff2ae4d66de0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:cdb01b959b7d2d8ef765191a41c7bf6e265c18e7311ce10863553815cbd6f7ff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:97777781a5408ae3c03082674a020a86302c27fc227116508407b6b051be9bf8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:48f2111c40a67eb4e0b209ed01d05c00a1f9045ac831efab00cba665f1f6393f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:af38ca182f47fc852a71e813435410883f6080a977a6d0b592048603cfcc7e50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:73bbe9217ec9f7901a58ecf78062bbaee5f5dbe3865f3ccb8a5a1424bdd1d21c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:1d3486162f8c57974a2580aa49e0da352160d7ff773b2ab38aa12dad88c43410
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:2ee6022280af5116f2972b62476b08793da1beb4f97bb4d6605d6d2cee78625e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:0b249c2375d2d753e15be79af39076c5366f577a088def598621aa9671d74db5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:85c565ee03e6ba23a0d0690bf5924f48e31f3d15c19c95bc731110cd0b107ed6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:203b3f5d6a3bc0f7368cb514c307bc10685798c236189d76a25b1f04ab15516b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:6e12fcd462114b5e2a71f15acdfec90b45563511db1e7350c704c67d648fcbd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:629d6d08e232548bb47d73a95f3984e56fb356b68ab6bdaa7eac88ea1557d4e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:6afcec36622ea3cb6604f8110b84fda1d8ea1e2722a2510e066c97e1315ab644
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:74d6f82e28699ce5f2d73cbcb1eac8cad9a01b119a1216f7a3638e003912e501