Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:9de7451924dc7423a1369dadd9e9529c6178e95c6ec1c2ce1547916b1b7c3104

Manifest digest:

sha256:6aaa315881cb6126cb8ecc94197707c848c2226c584c30f303c0731c8a4c52cb

Size

488.91 MB

Last pushed

16 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:3a4c99891ecb4228d876d8bb251456184349221df45c42817c3f57c82c31a859
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:4e00e9e093ee1ee666671ffbcf8add7ace9fcf4bf7b41a99a188b12ea0441f06
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:079b3d727bc6aac07ccc64be675ab9a24fbae526df5b36b16ae0a17a6d6d8b57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:8675f8cbd6627e1a28a05af715363de12ffae522d9ccf3a348a94335086d182d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:30b55b55c75d3197c029482de412f3a27d253dfce606886d9de574091aec5b87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:3244953f2e8443b70de524e3affa5c651f7cdab976a762506655c6636f940553
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:92ed152861aaee005d2e943dcf42683fa63c599689117ad22388151333a270f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:0bfe3fa97e0fe334cb4916ca8fc00c448c9178a39ae1549771c1b74f80878d4f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:0e7ec3d10b297cffa96b96ef9866ea0d668009c1fc32ef4e1ec1fe5f3dbb3950
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:6ed397bb6eca5bf1ff6d35411a6cc422163048c1978bb9b3d278ca6a1535249f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:aa9dbd4fc0c639cf42ffab4e6fbcdcd5984e3cc054319fa471ab8af43e204d7e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:5cdeda2e722731e096bf315d400fa269a8b4759a56f4bbe575b33de411acd82a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:622a51485e46b9d77712fddbcd94280d9ce2cbb8e34443a31f2b74f6e3632570
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:e30cdea217b318981d0e31098b0b19162d01826adf12c825aaf249e7a7dd599c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:92c61642c24915263c65cca83f0d004eb7efdc9004414be81b4dffc157e06d06