Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:76c3dcfbfbf179d68b85010b9bdb5da93b7c1775852ba872c16ef5e09b968313

Manifest digest:

sha256:8a48d0bdd66055f8bb07b73624e6b9991e04a861f99e0db3e826f87794f3f654

Size

476.22 MB

Last pushed

7 hours ago

Vulnerabilities

0
17
24
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:d48702dd289c5ca9b54a055e90e183275d25e50da2d6f6b918a68214797e7157
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:68e6cba828e255a60a6aad63cadbdb6fca91f1c3c72424f454958d4c0fb3ef0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:f30bdedd3e2fa44810698f2653fc136f92cb872cff4752f2581bb6c66ba4e438
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:f5483bc0ede04e7d77074ab6ea62e133fa8cfa5d65579ee507ce6e59825ae7f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:8abbeaa789530396553d8e4f9d67a8c03106c781bb7a3cf16b796b497b587b66
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:f19fc4ea8981afa25b04559514a7fb94213ff854855ea37891549e59f8636b9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:df786c9d961093ef443c722e2daf304f6ff2bbff89577ece412f65c1dd829546
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:bf1e023a8dc84fdd23c883189717027e5995571619affbbca5a42e232d4f7f8b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:704289eee39a5b234ff724130e592fbb7024e40e5421799b348e3402569172ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:1d596bc1af47eb84a2a17b569ea57c643acb4ddb75ae0d396305a1f8028f79f1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:b4bdf74a8856967c2de8ec1cbd58ca6ed958d93fa2fa277e3a98479c6cdda166
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:8fb764acbd3d7e945eb0143d8b95acd2e8fc6a5c0190aecf4b2c29af7c92fb66
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:559e984e1e72f512f4962a947ffb6b0f09b548806b1f0dfbd9ed2a8cd5a1b233
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:5dd9e1b208a267f6982ff356be885c9b1bfeb926126f8196edbf6b8287328848
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:f79adea8cc05e18165b0ef0c5d444d67ba35cf44841de81d984d125640b91d8d