Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:61cdd2fc362f41f221d871292ea1a891771989f940c3f7a98034b38660daa92c

Manifest digest:

sha256:155208d66430303b82e6131e8464c8bf59435a6e1e352c39c09fde79efb8be87

Size

488.91 MB

Last pushed

9 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:b28c2ab92439b1033be9974fe497071ce7f035b8f1e2855808d4a1ba769bb2b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:1378ccd4e998ca7ea9c9ed148cfbf0bfd56d4c5ba751336377088d5938b27a0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:54be6fce206d5c7eaa2f13d9450584d73225820307a808f4783bc2c65005f25a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:8d8dd4ec9350d5436bf4fb0ee0d41772ace8c721f98db1d42cc2f6e7eeb7ecbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:1e4cbf6f45438b31e8e722f687834d28e94caad73fe59d9f6b1672bd5e9f6fb0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:93e5b1eee205c46250aea3d982615e0c501942d4a76ab887fa5352260a889b6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:ebf630a32086c2e67ee239fbe6b0de873cafdc6a000efeb52d36f4eeb22cfd99
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:75572b33047cd84fc1bcf14516feb657d8920d9687c371c916577669129839ff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:df4952c34fe5bceb0b36380b3987865566710d2780e3ccd73c5da3567dd5e674
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:44d828a08db89ca3be66a585e7806661160409d28b6c7c762255052dc7bd4135
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:0a6a90d35300f88f218bf15b5a7e9deb8626c9bd7d8338740d26ffd708979012
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:2567097998477020eb645fd223121e1653f4b172e872169aaed33201cd41cc94
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:dd1da2ae474bd1d15da6ae4649d50d69079026714983dd1ab6d52541cd63eed6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:fd49c1b19dbbe88eee96815acd69b56641a84276767fe19517643a2909852ca5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:0e04653c637138ab8a8a097fceda7efa3627e13047a6dcd7e1210e21f71ea5c0