Sign inSign up
R

dhi.io/r-base

R 4.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.6-debian-fips-dev, 4.6-debian13-fips-dev, 4.6-fips-dev, 4.6.1-debian-fips-dev, 4.6.1-debian13-fips-dev, 4.6.1-fips-dev

Index digest:

sha256:bf19880aff0a7e8b8403d2fc2910f4966410d013ca3ed0a7e13e23d76fb47701

Manifest digest:

sha256:e7088062204cfd30441a06c073dcabadd83536b49452903fa2b1ba28e09e41e5

Size

261.83 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
27
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:b208e5f7bbc234a37b299bb7e73088bbb824c5ed4705473f8efdd3c7bf6ad3c5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:1b4a9a6abf4a7e8b4b4abccd6d91d2740a3dfe6d7e26b4de5fe1cfb5ed29771d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/r-base@sha256:33c39567b29d4a31ad03ebdf0908f402794c1d6949ebffd42fed4772cffc9798
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:98727494f9de351f4feef1b7ffb7ae041405a69649f4c9253ac00c10405b43de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/r-base@sha256:30bca73e97a44296b58a03b273513014b21dca4c498dc0184c3ed7b289ea6fea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:8ef15d58f963679593786a90d99c82fa4416f393732ade135310828c2957c4a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:00f1990fd99a263fc7ea2d77b573a025d7d538141ad1388a1c3d72c5c06df579
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:2b5b856e2e8a2843ab968cd5e45d034c64678c3d075a37ebe0f99836ba185674
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:492d6d927cd2033ad30ba9e78a6fa0eaeacf97ec896250b0183c99996a214174
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:76301494e39426153af85797226f7e15c5c4fbf1b004a821762343aa03b2b846
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:1f6ebfcb90bcf04c2306990da283c652761ca5301c09493af0ca8d6f15092f51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:9c739686a53be44520acf75ab9decce51fc18ee121689b82148e2f925c561a8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:f3014fa3dd2ab22a30719a85d3c41da53573e317963ae028cbf7cfe9742e0049
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:96922b379586b4c274bc6dbaa5956fc35c50f59f9e3320f23e8a32419ce89f6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:d62504cdc25faa7be55ee27534a41aa0a80420ffb9e801059ddf7c7310ea8558
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:44a0505c3e89a3b4b233096ca8ae95287461fc37e6ee8339d28430374e9b95cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:eb070b27c2334cb35507fdcfc3ed54f4e748fe26d143785b5a06eea74ff07375