Sign inSign up
Perl

dhi.io/perl

Perl 5.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5.40-debian-fips-dev, 5.40-debian13-fips-dev, 5.40-fips-dev, 5.40.5-debian-fips-dev, 5.40.5-debian13-fips-dev, 5.40.5-fips-dev

Index digest:

sha256:997a17ad37253b375589afb2012072f0872a47dddc53348f6fa7c306d329b67e

Manifest digest:

sha256:052edaac97e9ec992dea602f8a7047127ac825e87ecd4654f9df81b70c2ffbc6

Size

103.48 MB

Last pushed

18 days ago

Vulnerabilities

4
11
6
36
3

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.40-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.40-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:2370ca67e5fe64d810fd2ae5f348091befac57d540ce726a2942a2f6ebb95431
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:470ac6ff6c244eaa5dc8dd9825477b0ca861e252c30f86ea6851c90537333c12
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/perl@sha256:a8e26fe6fe7a75d79bf46d8932e184af2866964ae5944086aa7f4f3c1cec6221
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:41f9ddad350c08ab34fd31cda6e9d70de676847b7352bc598471e27b7142a003
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/perl@sha256:a1ff07bb1d15f862dea1732b524acc377aa2ee2da7ef03d90108a2080d2af288
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:75ac688bb38bb3f9a6ace2745d8d69da2066906350b13ea0bfc7afdeaf576755
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:21dd7dc9d039cf46e46624b43831c31746e84848e2040ec08141813d06cff16b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:7ddbbc3c915af6939dc9e2f0f657c0df1f4482fb5d0a50aed8465d1e00db1f24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:d4ab02dbd2199a608cab8dbb0b9e6169dac55b3540095cb12a32f771fe4bd47a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:a691ca66bc7a6997f20dfbafc7b662b93bc244a8e0cde5231fc55ac38fb98f0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:7793466a59dbd656b8f2eed5219278cc64f74f2eea1ca1ba8d4e8c48f5f83d61
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:3da7e249bb540f1595781ac02284590beb3488cf2652d69d88ef1925bc45da05
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:1d62b33a2ffd305aa85f937d9cf1fd606199c3600c7a1cad717a08c9446fa82d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:a2ef97827af4d6669a7373670986031bcfcc9650cdd843442f4cc0fa9b46f47b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:b62d878b3cf2298fe61ee224cd8067e973b8ad4e26d2f6793c2c3b6b08e15176
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:521d1ce891a6b42f9ba1f0441e4d130c30825ee2476438c5aedbfcc0e6ab3a07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:622d1c029af48d918a229b5ee1526a30c582c2a7b0a06e988b6a30feb9352438