Sign inSign up
R

dhi.io/r-base

R 4.6.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.6-debian-dev, 4.6-debian13-dev, 4.6-dev, 4.6.1-debian-dev, 4.6.1-debian13-dev, 4.6.1-dev

Index digest:

sha256:f3cdece141403a207201935d413cee76b3894a229c47aaa3e00d05cc3bfe2c27

Manifest digest:

sha256:4753160727a132c8fe2735603d6637c3afadfa55af602883cab5bdead8e3597f

Size

261.04 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
2
40
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:bc7294f50a803984eb6bb84df2dc9211113b398ba9a7c0a26f7d1a0e0e9e48a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:1fe6a46a15356db156ba40c63481cffa298002abde49806fdd479894e330aa97
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:69184e1e293fd68ce9bc968b74eeff2d06e700ca6a8982942788ca9d0c5b19c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:b5d45c7aa3c8171ba3fd4fe393b0709a2126049cde3b2f6188a3cd22e02562ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:0dce8168a7f4f073b56d11ea7904bf7e3483bb910095bf089de8a46e839c3e70
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:1a340514036e0ec436d5a95b3433ed3a36d91f767c6d367c1d2c2561749d8f02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:4b40d2aa1550746b5e4dbfdbcf75dc11699ed7e1b6e148caf0c4773da9067aed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:80b8c97a73d33bb367a92a79d85e21ab323ad4eba30dbee3873fd1fe55f8d0c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:536d54b2f245fb1c31fc714c6619ed8acc0fc3bb3511f8e47ae1a84425ffae94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:bbfb2e104b5e944fc08c79462d75f9611aa20338cff26a3f4893c8081d549f17
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:9141fe1651f57e5ccf0b714c69a5a8f4f4704e24188caad402de4558714fd83b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:bcaec8e71d542d6b93767a00ccc137c91b0351f41a23eecbc8e278e6e01b4e10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:334b8df23319a94416e7a0512cecb19c07d3bf88a0384d437697a2fbeca0c51b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:ad00c3577f16515c9e179afc62746ce2a8148d815e88e5cb463169a401f0e7cd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:6c5eb6eb05dca081905bc311559c5bf57d1aa5232f399ef28a26e9e121d3ce88