Sign inSign up
Perl

dhi.io/perl

Perl 5.42.x

CIS
linux/amd64
debian 13
Tags:

5.42, 5.42-debian, 5.42-debian13, 5.42.3, 5.42.3-debian, 5.42.3-debian13

Index digest:

sha256:78b961428e0a86471ffa29f6c9da1b1c2a079cceb4ecc29358a1c87b1a2cb0c3

Manifest digest:

sha256:44ca32d74debd96ca155a094362b5d858dc2f5fd0688ec7a2bb0c7335f425bea

Size

22.71 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
7
0

Support

Active until Jul 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/perl:5.42

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/perl:5.42 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/perl@sha256:03283cd0ff8b4eaa000400b68e481384cd1894834f7962f2867ee6d6865f2f91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/perl@sha256:0aa79582b570222273bb5192607d054dfb9169570ac355c1c7d14cd0add4554a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/perl@sha256:c5a304b8da14847f453bb567e763b11ffdb4780b0f1346d21f183cc809adca35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/perl@sha256:3e1f3dc019dfdefd213accc65044ff19612ee1004ae136cf03c315069d7b1b82
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/perl@sha256:7bb07ac27a1e4077999d147a7fc9c02d8ffded6a79f7cbd76581267b1275cf9f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/perl@sha256:4013c8e363619333b1eed7190af18bce5741bd900c307bc90ab039e340f540ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/perl@sha256:69293d153643ceaf015dcdab52739a1f7f58689be9a566d813d2315e3923975d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/perl@sha256:1bdd1f3eb55ebbf6409039777b34c2c63851719c8d4a239d3c2b1faac887e195
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/perl@sha256:0c6665bdf9dc8ab8dc12624867503b9a4568cd31aaac7509de956a09b0fafc0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/perl@sha256:49353941e579e02b4252ac1aeee343039134db3c8281817322e1911d886e8573
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/perl@sha256:d080f52649ddf65676bc9c6c8d683e31ffba39b3ee32864ff4e40d61b24dbebb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/perl@sha256:8551586ba214a0ecadcc0470a85a7bca09d4295c05b49163ad4de825c89a6a2b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/perl@sha256:883ef6a7b7cd905be8220b97dc801661dc750c007c70809d25b77c207589b64c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/perl@sha256:5356b869a83c34c983125ade8e2c380d2a47ab0fd4937c6ad06b4fdb380ef0d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/perl@sha256:a91c204c28422ccc00f40c5694593e5a7c51ce22af177d0669573d4950ca4234