Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.1.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4.1, 4.1-debian, 4.1-debian13, 4.1.3, 4.1.3-debian, 4.1.3-debian13

Index digest:

sha256:e0a979bc7c1ce522bff844881b754fd3b1c2368d0fb8b21d020b0fc039dae751

Manifest digest:

sha256:79eb85a74d7251c727b0adbb962be9eff5f2e7a7d9ab147d42947f3e90f2a6bb

Size

477.57 MB

Last pushed

3 hours ago

Vulnerabilities

0
8
12
1
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:9ac22058ef7b9bdd297d961cff85d880063ee53a312bb5f830a3cfdec38029b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:dbda6f6ec0f23e47a06666adcb942be998358527774d8bbd617ec9663b324dff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:35078f0b411074accd3c5ad57308f7e8cb39cec40f549ccef6a9ccae975f5ab0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:338622c1d8a45c81663fa2b196250472d54a9a16420f7b0d69b72af598818aa9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:d04de6e6db6239888c91f7f577e57c13a8a92a767a5b53024c6c823519b33876
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:bfa33c01a96f771d659037364e10ccccf0a25fd7013d084780a34c418f342558
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:1ef4ba629f26b7cdf9de8f599f9d250e02eb760b414a48e733b71cd997daa31f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:e70c6e48a13dbf534978fdda2a4f0604a1bfee0aca284c3859e6229bdc5a2989
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:333f61b87dfe9ce98eda766083923b22b0494ebb762c9d60e0c6315ab240b80a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:bae0d69843acec82716cab7ca51738ceae7efec25cb8d9957069f42db202747d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:740dbd5e9d45953519fc8db19050ec5c452231fe6658f1eab01c32114a47829a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:16d58f2bb99386b8b7e74e5a67aee85f9130302ed1922c81653e3f1bf3cdf0cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:c3e1b5671cb70a81199a73f4597d5c37c8272e7393ebe6c1c3e6b2828759aadd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:2e48964a71807d657f4ad66c1884bfeb518de920ae832a5fbe86daf6a92adc1e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:67fd2aa5c33db3ff0cd583c5a4cd856e2f534ce58d171746d7e001d9f4591168