Sign inSign up
R

dhi.io/r-base

R 4.6.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.6, 4.6-debian, 4.6-debian13, 4.6.1, 4.6.1-debian, 4.6.1-debian13

Index digest:

sha256:3b7ee40fd4daac75edead153d25a4327d58fe9c55d062bf4907ea92bc5e1d0ad

Manifest digest:

sha256:e82d3fed56fec72f582e8159595e3e6d091d988345fba2b45b866d4fa7b3c110

Size

108.09 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:bcb4db985ffa3545dff1c001881faf1366ff998d340477dbab8407e82c128215
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:535ceddf6c2455049e4a38d842d3931283ba5bb029d354f63e406945b8655a4b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:d1d003081c8e2dc02db2968aa733475f1d7c74a1dedcf9612f7dcd5f3eed73c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:3de0b0be073d54e03431f5c2dcc0baf40ed250b05ea03113c1585a3dce362a75
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:275295bfdd209b085f904af236a4f4cad2f0f72e226e9d587d38e8b305952c31
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:01471d64375ded4dfa76fad01822973ab99b5ac7e0713c5dd314f11aba72b238
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:8e18a3e285ade4f34c9d7d7183f34bcc3b95fb1d5a9c9a930f9aa22c1f8fe336
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:7593883e95b90c71219fbceaad423ae04c4c61901751102e002a2ad877118d82
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:65c2596e3ecb2d4083ea8ecdb1f5f8d93e466d4cbfe3171b7543ced658b19d58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:9c6c69bf7aff25d9facb0d3ed0a23c01d965a15c57b369f0ca89190209bc6b5e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:ad7d07ec602bab6baa68086fa0e03da23bb4c5ae9bafd1ea693ce4fe100e3f84
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:97809ae514fc3cbac1de8046632634c9bcd012195804094a6e14ad445d9035b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:69ea40d99730c7aa4e05ba1960d918704278acb8a6a2b62e41751987d6357cb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:8990413351658cc2325dc79242f9a17a4e34b9ba1f361cf5b7a9f8bdfa42802e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:fcfa1c6c25caaeb7971c246b9a2973c6203b5128aaa6cae77624a4f56828b608