Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4.0, 4.0-debian, 4.0-debian13, 4.0.4, 4.0.4-debian, 4.0.4-debian13

Index digest:

sha256:236a85b8c46b887af07df4a48f6f4c1d6f41ea5ab6b1e8630d9263b377fc4c5b

Manifest digest:

sha256:ae3270de915a974f43f5537888461ace70bcc3d59196a64262ebdc512361f6d5

Size

459.27 MB

Last pushed

5 hours ago

Vulnerabilities

0
8
14
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:87fe2dcb6bfcd31b810b82d2427ff181b071b90496b9222836c752a1951a7492
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:aee04e3a415f7e0acc8bb2a247b406b414cd64bba441974341d7a04b9bd43774
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:072fe2be7423be874e9923651d8b3d0171334f726651919f380e075dc8b8bd8d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:546b5ddb1c94a9e882ca9d4f5cb3e3b1a39f3c136d27d803e8ce85ea05b1c232
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:ce9f081df9725ba1696ff44061a678d8422a7196231defb330aca9bddb3f5341
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:bb59a36e7407c8fde8860a19fd3a5d0af66c24ea479843b5ffeddd5939091700
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:83cc8a0eb0de51a51dde73d412cd4e1fd24c16e6bfaf9b41df58150f1c3fcf08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:fe002ddc9d60c86614b49185781ff49c876fce7252da9c4ef91f4ad5d886c2ff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:3f3e20bdce427c449ce642d4e05419f0705b390edffb6477df1d8ead72bb8476
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:16f231d24d26768d4b36b665c369848af783cdb8874e495808acfdf6157b7c4a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:ac0d0f960d9814b0aac66d4985ab36ee0a142fb27a7d9acdd83fa724f741454a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:7421c7aff6a562f492828660e15c754fa12c896e8fdc96525555ac295a55bf4d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:e637a50208b8bc001deacb5c5668bdc8067e2aebbd2280ef5f5be629a84df7bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:73de950aee387fea3e7f35b07aec5f46df8011b5608243b60ce81d9608379774
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:83cba305d589bf16d219269579f6f0baf8ee25318fabbaecc2ae746017ed6f88