Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

5-alpine-dev, 5-alpine3.24-dev, 5.42-alpine-dev, 5.42-alpine3.24-dev, 5.42.3-alpine-dev, 5.42.3-alpine3.24-dev

Index digest:

sha256:74c96e40e26bc61bcee8fe24a796937268d86eaa71c9852609ee6b9779847006

Manifest digest:

sha256:7e2a820284f215d6b17c6c2a5b6293803cc2d9511461f9c1d5e3099ca034df42

Size

76.22 MB

Last pushed

20 days ago

Vulnerabilities

0
0
0
0
4

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:d827d8b1bec4a3bb6ea03458b3bea7b03ca55826c1cefc5e5041deec3eff22ee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:15e05fb9e4f129cba527676066d2b14b5f61f2f84d5f12127ee479ca2d2fe894
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:d20a2a056c97661131fcfbeba211c240c40b3eafb58812f43c739ea720ca5ff0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:95d105c9d78d6023136f2229a93e83eba0259529beb11eeed2895f9a6a78222e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:9e8709e564217df519bb72d57bca825172f415e7bdad25faabe2262747d37bb1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:d8a7929526f33c3ac3bdccd061097d77f5bbe8a2935edf7d8f9d9d752b25e901
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:51cb74a550f61bcdec8cfe5a8993a282cfc553d6776ae1674d2a729f9d33e632
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:511d5e31ee9ef76dedfecc204ec4610f5f9252c16a3c8a5a12cdb461d014fbba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:78910ee96eb4a1c68bb6ac3fd21d2e89bf52382559ae424a97f7f3ce5095bee4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:1b610893e288cce8c297b1154b013730cdd5fe2e0dfbc01d191427eba4b39956
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:b443ae06798c06132045e4ff8c1a1d184e632a9b05bd8d6f6e1121909ab9a1fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:625e336b2b54069342db2d5a967a8f7b0c16318987219e46f1981b9c1b37db5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:94e49240e1042433f0edc673a77e5a50308fa0a4e628ff697780daf7921f92b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:e09d4935a5a8dcf54c1576e01d4d45288a5e6780b1852c952d2cff5bad724e8d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:c8ac0508ab4370c1b20069a033fa6b10989506535bf487f3595014242f26ef7a