Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

5.40-alpine-fips-dev, 5.40-alpine3.24-fips-dev, 5.40.5-alpine-fips-dev, 5.40.5-alpine3.24-fips-dev

Index digest:

sha256:e2f00f2d7c1c9165d500b42058350147f24fbd71f6b8b333d0cb6e2b0edbd607

Manifest digest:

sha256:990536df1e0220ca2d1adf98ebba3d79ab7bfb40b9676bc490a7d1e3be5e25f5

Size

77.02 MB

Last pushed

18 days ago

Vulnerabilities

0
0
0
0
4

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:9df14032cb8a65338756aa12ff0faf36a6ec9c768e5b246f0dcfe328426fc629
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:b1a88432ab6e6dc15cc1bcad941a88e4e9aeaf6284a8f851be4e34366a17ccf7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:9a2cfb017ecfa4a1d4d08f292652fa2d15ef21fde6e1a818601a2c0729256c0e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:55abd9e21ba0571be8c0740257094266a35afd6acfb26fa5cc0c70251795bb97
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:67a639622f809c6d04904e82d2a1db8ffe8a79fec60eb10d8aaca816b484e11e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:3fac3cbcdfef2848d89c84b1186aa8cb453a79d5d6b77e40c7ae8d3cf2c8bfd6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:9c00b6b4c39c10c21621acbc3bcac7bff694ec1997e66c1dd72326e08670848f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:a4144af41869335a6967dc12c454824f19b327ceb8e9680f9497c429fe19603d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:14ae33600aa8036415084e2524b809ae98c1f701d909faf121f01677ac80c3ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:f6bc42f94de491b144851bdc70d92cda82b56866c6b0408f31fcd6d38f322afd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:96d34af6924e075794962ec148a895d802aa7559e2d4087fdb3d3d6b5f65d4bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:705bf495f015ce9ca163b357c98230840f3c01803ee1e86e8e14f6300fc3fea0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:55735d2ecdb4b953fdb91ff4497ed0895b833cf614ad76b1577619cb29a6e6d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:59c313e214d12941e5c6a4858b7b835fc26036ae958cd1ce225d15e0e7c6f534
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:5f6e90acaa27ce629dde0f8eb2585bea818c9eb87e34fdeaaa8d8158a0a3fe17
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:6c2ac8bd4ea1e562936d74c8d50c7344b0e5de34106d97824f47facbe94d8571
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:b389045986af8a242d2c7861b94a7b8ca18c9b7ab9b94d5b0fbaa86975778348