Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5.40-alpine-fips-dev, 5.40-alpine3.24-fips-dev, 5.40.5-alpine-fips-dev, 5.40.5-alpine3.24-fips-dev

Index digest:

sha256:36c957a4d9aa08bc8ee5420aefdb1443d8ed47de294f78bf5653d6f1d5a80b7c

Manifest digest:

sha256:b91c815906d0717d39f39f14f7dfdeb2f4c06aa9135f48d03713b5b4b70efa5b

Size

77.01 MB

Last pushed

7 days ago

Vulnerabilities

0
1
0
0
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:4bca3fd26667b777e03e6444daf54f872a87cd0c5074434aa049c39cc471582f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:1b6bff57461b62a99bf9dd605f0e9a8449e108feed9c103aeb87d7f78f0f7bba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:e0693bcd231aee810341126d425c3889f09ac588c07c0a3d5ad8df357aecdc0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:4d7985f88e6f10e64b57bcd465b1631ea6044446bff0d7777fee4f83bf903e2b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:73436c9e30d78df7b599868ea42538ff5615f6f7e276b68e44812df7b7e707fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:7ee9622e1c1f4a6ec5a5aa99bf7bef1c36722e5c949d0474f6da17cf4d1547bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:bb92961db2ff4edb6f5eca373beed6b4c93bf9b598984bd42b4599b05fe3ded6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:ce182cb055ca403efe758c63d5adde55a5fb1f2b7d49a0b297241158e3a3a19f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:af17941a986104b769656c17e20dd55477744f9fcf42ed4ec721151e83059437
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:9aa943e9a459bc551db0760a6670713d0620c69364d064f561f32103cf6e1f2c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:317db29336bb09e7d4505e4841eab4c22b5059f09875e96e9aa5dc1495484c3a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:85450f54f1a7b94548300b9275ab01b979dfc1afeeab71ca473b36452da36b31
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:19fba6acfe3bc3b50a832aa7a01131fb53694a25eb7ec9a698b9cd6d152e6cf0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:9923c9743f51f9301efe4b1724c08f2b43fc716091be3a7ea59894e64f30a294
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:54e9dc091b5ee98ab7f0b3f7a1eaa575ed5c59c01b5522dda23d4b962b2e7748
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:8c147f1cfc582885735154f60039f4f0e8a15091a3ab0474dd02368a9fc9b4aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:d0015e9ee81dbb43f966f15fd281c79b0ea15eb7f402f2d11077c6d97fd3169b