Sign inSign up
R

dhi.io/r-base

R 4.6.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.6, 4.6-debian, 4.6-debian13, 4.6.1, 4.6.1-debian, 4.6.1-debian13

Index digest:

sha256:276d9c622224d2043d26d670c34cacf181de886497f15fc759947bb785b34657

Manifest digest:

sha256:a8a26c7686f34bf1974dca5f06cb48e7260a215a36ffbc08888509edeb43a58c

Size

108.10 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
17
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/r-base:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/r-base:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/r-base@sha256:447c85b5e59c13ad57022523332791ad1ae9c7ecde763d02b5cdcef56666f7df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/r-base@sha256:2d0bc378914e52ee5bcc6ac0de833a8ac0c210c7adae21747a6e80a392282089
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/r-base@sha256:0449d7d8d24644b23c15f4f11ff01e82d912f4ffc26443c4575736b3759764e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/r-base@sha256:19c72e07dc9b65db779c71686ede69feee61184ce6c0090d952b58d2401c42f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/r-base@sha256:e1b49158857cc517e26028b5427004d973f4b7b2673443062be8e4dcd15522fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/r-base@sha256:db5999b66c75a647e3f2c156d47ea6247edd5b67c0efb8d70c04bf04bd0b78c1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/r-base@sha256:c311c8f0d81538dd139cf4590bac1b713a4199ba45d90cf49cbd54d053059e5b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/r-base@sha256:0783d140aa48c3dd59a0a77233d1028e32a6579240f37e5d473b58472098f3e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/r-base@sha256:fde0a035e5eb86c6eb4041781f811fa7458b3963b23098584b6caf52d05ebf53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/r-base@sha256:d82c70b57dc664217d07e6d12887c922083b3c84666046eec17174e24fb85e98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/r-base@sha256:b697b05f08c7e9f76aa980dcd86d50257906f6703c3d9cd03dd04c2a46c68b5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/r-base@sha256:d18be875a0bcc69a0a05116444edea6ce8e8870a3cd0880ab26d6b3e2368f367
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/r-base@sha256:5d50b9d066e369d2262e7cb87408f2ae1e2a479c6049c33f1372a05df17ed43a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/r-base@sha256:d8d3998e5232f53c7be73e3b13c695b73870abf705c4223c8503b823aa3aeaa7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/r-base@sha256:ced8ecfa2328be879bf8627b95796e78616a5dfca3a8a7b17b108a8af12b5242