Sign inSign up
R

dhi.io/r-base

R 4.6.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.6, 4.6-debian, 4.6-debian13, 4.6.1, 4.6.1-debian, 4.6.1-debian13

Index digest:

sha256:760001b0e1bfbf470fde5d33309b96a6ef7e05ae9fe847322922b76c177e7af5

Manifest digest:

sha256:97ad2c887a9c76e506b4b4e7a60c66fd6a1ebaa591f3c685301ab6700f4affd6

Size

108.09 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:bb4a1debd82ed182d7db33f9fbd978aca9724e47d966cb5c5fda20eecdc427c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:ea0b0337f0b217b1e17b378ae036b717e5df47ba216608ed95da297bc1225cbf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:048c0393fff722139c89ded3f193d29442707dc27f3cc741da844797b3841245
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:7b6c9241853d56ce9c9c67c43e1d14557181f200f0616ffacf481430dd195ca2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:eaec0cd299a11f329ef953a68589fb06b45f63e2385031303e3e7a0521176816
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:507560e9a8126166dd0aab4f25560cf430f3eccfd6fec7ad377053cbafd76c0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:af3f04fcfb5d960e9c22442af359a14133bdfdf75057be1857bc6d1f895570bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:54dde40c64611872b70d58d7d771e415dcfb9109a22ff26d2a9379b49004bd8c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:ebf9ef55e6de5e248b7614386b0976a19d3ff665f0cbc4bf61d994a07d7e0364
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:0e160795315163d331eb50ac94436d97a720b26d2b63b4cf170fd2456fe56c24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:d9ea54058eed4f6fec0bb19e23ee45eb20497d98cf49baa6e56d4d8ba16833d6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:ffec992bab65ca812d192a656ac6d47f328fc419f2476fd082dfa9e8885b0d4e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:d12b255a16499e14fe40977a3666f96dcec4a6703e30d029608a6ababaf37baa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:72a98996c45acf702a8d6d2bfb804ab40606fb5a43a7aa8746e985834965d2dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:19d19c7afe793d4a7d1f2bc4869e3c7e70d97536f3a4e8f73488da216e085c9c