Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:758370bdf4e6471e35100b6dcfe10df45eaf5cf0fbb1ae06e7402bdc9e5427a9

Manifest digest:

sha256:74f3ff319deb1a4ceaa432c36ba5dbd03a6c4a67e719d0bc8f9d45233be48460

Size

498.64 MB

Last pushed

2 days ago

Vulnerabilities

0
7
13
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:aff27c4980723b82283c8e57e5d646b2eda029495b106d14163e4446a7355b9d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:f8ace0e317b5d3deb7c54f743da703894b813d03fe7f77a65e558b7d80a3f108
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:08453abc33c145072eb77ff260a7290668f4b9d002b65cd40cc699b034aa805d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:8185e9f5ca1ccd9be5cbbc59d032f367dd36a49fd034c9fce70495d2e43079a0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:c24b90e6781014ac01d88460a95becbe4cb05029ab7c1f5390979e6be3803a97
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:f615265ea6a49187feb43570ee1c414bb6ecc8458d94ec08bebb1b50518dd92b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:8c7174d40d090c0b47e5a6c04ce23feb3bf48937eec9b5d83a205088614fd485
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:f38b72f1ba2a6af36650dd969e5ddbf67958c2b0ebe345b48e720c2b11e0f860
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:122e3cdfccf1dc9214619a0373052954bcd3a80928d57ce645b074c2a7b39602
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:2366a876d0e76887678d4a6a38eccd2db79fa2cf83534f5e68e483f1e91825f7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:4a46c7452f5562a84315ed5088a2b7ce5910e007de67344a447df5f7b03db93a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:b2bd0207b04886d5a0e4bdbbcdeb6ed9b56f87b9745de2e18a579250e7714366
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:3ec7354167c9ef9e33683a8f0123a59c045928e227dc02888156c0cb2be76267
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:4b943b7a199923b46848e4744188e67177aec39efc39e492c15176de6a015e62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:2d9b2a4324c516b7bf519fec66e6a1945ce5cef38bc9cb30e25ce86d9c51cd0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:436dc3c121d477bc7e1c67ecb80112f6e5ef9feaba30d132bc78c56d8c6a35a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:d4a6ba072257266b0fbb91fd7e5a426bd67f9b3e5ecb06579e4f95d27266d97e