Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

5.40-alpine-dev, 5.40-alpine3.24-dev, 5.40.5-alpine-dev, 5.40.5-alpine3.24-dev

Index digest:

sha256:62cb5936a68a71b355db13861fc1ff33d9acef9e3b085e77308fa950c4597f9e

Manifest digest:

sha256:106111d10ba671b5696a8b464c2eaa621719190772903de3cdcc5de91186f75f

Size

75.99 MB

Last pushed

21 days ago

Vulnerabilities

0
0
0
0
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:c534fc8743d9f1b2d80d7917042815f2de3198980fd951241c6279a486f0c513
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:ae1b4f2899c489278cf7d131d0633160f8245680b89b6793997a6b711c1015f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:1a6bd3b6519291114f60f9274453e1eaa329586481e74bb45e2538447c0ad838
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:6cc526c0e75dafa0bc26b2a449a95be906a8d5ba2b128a9d08f8b638c3562adf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:06232315ce6af1bb21cc063a3f6880f8e8a27c926a742a6c8c31ebc39261ebb4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:3e087b475f14f8f4f42de7816bdb20655861753aa0211cccab05e0c8d699a3ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:ac1fd0687b29463a489fff765b043f17f59712fe0e0d27d1cee1a65586194bfc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:fe850d885635ea81013e5260a4bffc6aa14dc0583a4188d3d3b749b5d1e9e942
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:0409912198275e0da8270c20796691c8d00ac6baa786d77cee2390b80360f54a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:0124c763b91e6acfe670edf422b0517add00b85c2d4f20fb7dd45323d5fc6cbb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:c5fac9e62a5dc953c87d8a00d3a6054719c11bc052e1487b10f43f748767be2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:fa03c122bf640eb4f34987f445c889c0afcbd1ed7632251020d9bd80d3c7a008
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:ea8faeffa48abc09e6f56a5bcb7bb65d9725b5ff2565da527b74996332f64ad4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:103ecaa938cdf0ca28de6d5a0b82eeee0a95b24bbe9a8ddcaa06ed20e8c3b2e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:c7798fa551787c9723df8b7d9eb95aa1aa1e24e49847c42d02380bcb7c589b59