Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:6123848622bf31e7f48bbd9f0b28c383204854c3c7a443ccb6289b658e4f97c3

Manifest digest:

sha256:bab514d6ea98b79d108fe5d343d0540f5ddd8b22b4a02d372d0fa7a25bbb1800

Size

477.76 MB

Last pushed

12 hours ago

Vulnerabilities

0
17
24
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:e6e015912fd883c6be9f2f97ad440a99fb664353628a5c2538cc671e7c23f697
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:e1a97c06660a1e2b7253f15ec47becd144be3feb391447752b17e65b87552c8b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:2bb78b002309df1ac5963485a7e1d75c57b772531312a5264fc0b1d187b446ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:0f52e7ab062e26c89076073bd3b5a350ff7e5bdc8725c33a0d45d2054c486c0e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:18fc6714076c9bb353ba05ea59303cffe9d35b43171f1ef28a418df9d1dd96ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:87e6b5816f9d83924855a318581335491ccc36f63c14155d771e4b21353e08b3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:e8bff6233dc53f2061f1c3bb9ed0fac85dace77051b44ea6af788249437d0db0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:79695ea1d8a949d96c8b217191407eea5cac0e1942dc089559f20c7968e28dfb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:69f58d830dad8b1e41559834b837bac625b30e15a1a67c55f6eb604004c10e9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:65fc90bed37bb6144dceaff0f85e1c2f56e2fb5e4b3eef6154b6d18154c1d64d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:ee9306332c68eb9cf2e6e845a181a152a1a05a20eb672000518616745f4a684f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:cd2281cc22d9fcd0309f6c189625bee006b6a4cc0894185470dd661abc649075
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:f955fb73b652cb693d254a81782a34a75a380c719d3e1855149a836fd043ed05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:53d0253dbde50e261c998746394fddcfb142fc70a2db2fb06470634113649836
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:b894141d7cad2fffbfb7e399376e271a2a3570ecf8b0bba76f46bf43122956cb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:2fe6999b257408f4f08ba7ea0cf7c376d4aaf51eb5e4bc995c4f641476eb7b50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:682ef5d036573565b23d52e0c99f73aeac58cddf5c1081e3e6317a700ea160a4