Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:3c46f85cb75a305752fb799070f600c38f8dfb4371e1777d6a1e6e6184f3b99e

Manifest digest:

sha256:fb0f5cce253740195222c82e5d02d06cd40e088cbc0fda6d93e3b6ed6c997df4

Size

476.14 MB

Last pushed

1 day ago

Vulnerabilities

0
17
24
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:b961a091c7219c54e8aa849dede0abcf5d3694d96790fe1e6aa40bebf512c6d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:4628c7216341362c61cb8da24e79859dfd4d593de0346b46449f9afdfd28a448
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:11922145e378d85aaea517244cb0839547aab4d338fcd940d301876147a63e0d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:9efa7fec37f1e8b9ba184260301ac69f49f463ab3cad094508a90b43c42f4553
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:18c5a296329a9480aa55f0058abd1b7fbf3cc6194f88406fe5fdfbb31d8b1585
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:39556f80b3b68484828df55e0687c056a22b79888795dec9986626e2ba65fe10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:e22fe9092f3c5072ebb7f36580ba2182f1830dbd237796fb9cf5aa2658c4452a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:c4e2eb12f20e81983386ca5b1eb7e42cc7d2b4a592cf5fe12bed426b61bac74e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:d9d090391c1869c348e383ac1a637c14cefb779d0678a18520ff7f94675b7ef4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:74fdcf0d6683f9911de52a902174ffadba5a18e8345158502df8d2eef9dab359
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:9fa60c6cbb8eb78006d0da60ae5e532d1e1b2ab33696bb90b5425592bfa604c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:d5d0a56bb0d2a5deda8593e52dfcf1725a573cbd24c4706e4f403080869e6db7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:ef9402fe53d7bb8497618ceb734af18e9f6bfe22b7d7c235b8e753e1dfdca5b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:28a4f0993afcbbfbff6f94059b34f744ee6f8765c43ce315b65bd13b832a62ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:62461f97fc17583fe69512149d6e8c4375176a7ad88cf0291d1c06aa52674c30