Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:1e49307bb947c360a8ab04dd8ad9ae6ace15ec29c5af86ac0a50aab143c782a2

Manifest digest:

sha256:dc5b086ca788705dd2a464702680e7c48245b0b8a2bf86dc7eeee11b4e26e7fe

Size

476.20 MB

Last pushed

11 hours ago

Vulnerabilities

0
11
22
10
1

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:b3c24c95f61d3bbc5939dadb456e6dff7ea54ab5e52d89a9033051b87e341418
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:0bf3fa3fd55fa6e43496c48975370331bc6f0ae8c0c4488639cd042b8668283d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:69b9890483c76b0518a55c22a5e5477b86201a3005998264a4a98de5b6077750
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:a39a83fef7a98c8f1e5d69caaa909397518081457ebeafbb2a9ff5f1fa071fa2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:7836e765f73afce04bc4db4ac43a28226f4b8638c149aba1bbd06ccba77e200b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:ea2600f7d769b82329608488dd39362e0f6f26e130f90239d838fe685ff524fa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:37f2520867d5ebceefff714196acb36c70ebf9c7b3f454e92717730418fcb39f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:f172d315c9ad0edaba59f03dd08fcd22567cd0082033bf11d629b5ff19685f57
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:bf0782a1b5513a535bdb9f569be4f82b182656a989177decf6ddbbdd147f7d29
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:4d5ee69b25a261f16b2fb7edb706bd73220099da49fcf65c9b9cc4bfee9245a3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:a225fb46a003d5f79ea2f34b7e68eb49e9d8ca65864e2dee4e18d2384a6e3630
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:b4373adf78eb7375680a6ca64b5a588baf97be2e5d82ee956035ad3c3d5af26f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:e43c4775a80f65b74376458f9c840cfc5b8d5bc8f8efeb5357002c3c90cb146b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:35504933099b8295b319c513c5008a7624f3f31fc2324dd4f8c78df08da8b467
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:d819cb1dd0427d98408c39fd72390f8bc56e4a4c538307c886c1797f6dc3c1f8