Sign inSign up
R

dhi.io/r-base

R 4.6.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.6-debian-dev, 4.6-debian13-dev, 4.6-dev, 4.6.1-debian-dev, 4.6.1-debian13-dev, 4.6.1-dev

Index digest:

sha256:25665be2156ab4e0819fa63826b34a38a466499b1f3a46d1b6dbdc1af66c2c70

Manifest digest:

sha256:688d08998cdb685fba33ecfabf2635712bac71412ef2dc67a85029495a47a2b2

Size

261.05 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
4
28
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:415ad9dc93ba6e4bdd1054123b53d437dd5900ac9660a7dc3715dd685884b6fd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:c38f1b4a226e973b7c667f29cd8b3c88e6b07d6918abf62664b8d06fa303e150
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:25f0c4fa30dc2b00d4c940187bcdef3e62952e9060d0809a2a2c2f16a3787b7e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:dabf47bcb9aab452b5491d9970ab3e995e760887e605c88d87e54cf2cd5d78b8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:68e8f50b379fd6249142a0028db652950f17e60b45cf9a42cb01b13b9919f580
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:0444ab5182d8d517ae59f871e93b14e726f041c1653e13aab2891370ade56da1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:bb3cfab6e75c6ebc71cd727a648daa1dcb5527a3aaa3a7ace37c325b3318dde6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:f7afcfa7f6d4b3d6d0bc31db841ef51769e080a4717d582ddbe75041393468cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:7d2b087dde0a99a9df7a16492d9d739238d8b6fd0294f55a152a6dd353f0d3c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:201edcb006ff99c6bab2fcef484a7d32ed64553f544fcf117d8520343c40b7d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:c4ba2dd226f34b6a3aae0892e9a5aed3e6b8fc45c43b315463fc50171612a30e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:23080a1981517933a163e504cc3376b70966e50106bb36fcc9d7e65120e17596
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:de5345b10d16924a3e698244c2fe4a7bc6d05d9deb1e0fdacd611fb1743f754e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:cd84f524a2533c0a47e2a40d694847f8da92065248e1ee92e27000b06bcdbf1e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:6ee520401ca056ca4ea598a565af419a33d6da771f3148627a25b6eafd5b378d