Sign inSign up
R

dhi.io/r-base

R 4.6.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.6-debian-dev, 4.6-debian13-dev, 4.6-dev, 4.6.1-debian-dev, 4.6.1-debian13-dev, 4.6.1-dev

Index digest:

sha256:587e2700b13691a75f9c606bef42e74922ff92a536d93a02f90f175720a4b72e

Manifest digest:

sha256:0e5403a0430d2008efeb82d8d13b2448d94667f1e5fa1b0fc4c33f3e6b5bbaeb

Size

261.03 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
2
40
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:98137a2210764ccde56990e02c82ac559b539136231a3f013ccacb2c4103382d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:add797d5a080d68bcdc785bfbab61ce960624618a884891ee24929b2b503517f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:24df09a0ab1ad3ab15dd26565386f16ea426dccc54b8bd986f8ca7251edac307
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:f7e8f20479ab53eb1d2dcaec4aa33fe64a93f8ddacdbc6d0bef3bbc82e9b54a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:a74f285065fb981d4ffd5477d08e8347a6d6b00902919b4e1625c63f98b926d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:b5018e402bb16cb8f6412082814b0438f05163578da32f72b2da4c28f6f5adb0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:1184ffa12d1b1d2b992427fa81894e145967a029a378a9ac9aa0a938098beec8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:8fef34832be8e24e066e03808294a0f72d4ec9ccfcea75d543881458c4199430
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:94c96e537f77938d6a26a97357474f475b674e46380e678757ce5e5de619aad4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:7fddfd7e5a97a977e7d48237502c32a08fe31963de69a2a507c56d6f7783e5a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:2de5032f5dc51eba762e8c7288aea9b79b61ac26ab022b5138df801ae19851e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:19d1cb6a561a10d82e3561e617d754414e60a30326b160002122dff911e92813
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:11075fd970e5784c7a4c989668021da390a62a2eba4445d43cb1fbfc159c40f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:2a213d32715a570979b68a5403a9cb1fb2df5c5183345978518a4f5d3ce2873b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:93d0677b2cbed2506af8b8abc7f14bef8d57fe3b998ef4690d45e9d60cc16d19