Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:a9c0a6a3c81992054056b448d4cb0a3af69bc15f8e2aa760666b1dcc9d3ad84c

Manifest digest:

sha256:90032ad57bbfb05537810be8f4e61fd3d357330f425db4c14b88c0bf85e3043c

Size

476.20 MB

Last pushed

22 hours ago

Vulnerabilities

0
10
20
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:70642378640252213db0ba021b654ac46e02edb1ee8e506cc7e3a6b2bd09214f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:457de14c5016d1fa4d4a174ec9aac20a4d1fc97924726e7530baa945c4a4871b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:ecd85cebea5450d30cfb67dc622f7a9068117a992ed47d5a21a41826eee36b5d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:69055c6dbf18162d4c64f90a60a72207971972ce6c882087aafca4555e24b436
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:95c235a95f5ec99f26295c9fb5c3c282389c67dd8da97fdb240222aae3e69462
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:e75582c693d17ccfcc73fbf1bcd2208e7382916812e26d93f937226b89452eab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:3286223258d59561ef44ffd8bf4b94fe2bd4dda38e326966213f4de9e7b19068
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:888afaa7a360e393f8dfaae93b7d40f4e7f8dd5c7a55eed502d59662371ec936
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:ab0beedf7bd9d3596a245bd01ef3fa57c3baad85e3d8c84dc21b21526fdf4f03
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:2981777321b77c8543f9ef4be10b1bf84bbd194d9d6a44fac4b690a98c4ab093
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:2370a97f38b7b2f196e1ec1042273c789bd60cf212c4bad8af782efa472b7257
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:4cbdcdeea0c7d374b00bf02416f0ff10ab57c46f39298b981a8b80adc997d64a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:ff8200a57db5521bf86a9ad3aa240ad3aa2e514309c8d3153ce3facbea0addde
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:56996b12dac805714c11843e0a333bea97fbf404581ef112416eb1117d69fa81
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:3c6c9e4600e939465944fcc863b3deca4c0ee77ebf9e835249cc5f1bb4c3af4b