Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:35de7740cf3d18c13560049ca781e2ba0e4d643224e3ef8389943341536e6f6a

Manifest digest:

sha256:819c9935b64a7a8f90b6f0aad9c20ad8e5f9551c1b96751a068cae1af1ee331d

Size

488.91 MB

Last pushed

18 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:83ce98768647b962f5415d1453cc4b705dad277aff2289b0d5ac343483e793dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:45f445008bd6261f9815aaf49c0270d23d488b9400f603ad42998fb87ed172c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:6968500f7191778ad6a7a7bf547c6379651ca6ca0c64d52145f523ba202bd106
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:abd9931f04cdd1031fca23238038743fa8cc1f9c31ba4738568557ae3f77808a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:27fea0a92c714f85beede9cf6c2374fd31b53a965021a01457319787e8212114
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:01a123cbaa2ee036eb93ce84f8e9384b22a7d7409c83a60a6b6f4042fc4584c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:8059f942dc7752f33fe228b4ae8a30611cdcebe3902674175eab0c76b6ff23b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:0f1a9ef50acc202513a657de116b83688bcfda0e8e005bfdc80f94926614f814
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:2634e0e93d73666cf9d357d0a27c9bd0c88dca85b707acd7017b48e501a1583e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:9d08116703a1a340295325872c3d1cbcd071fb3f34683e6ae3361871e5284085
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:1319c87fa9258a0c843a38a5384a6abb35d26173302fe0a028a45273f2aa0098
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:6e269f21322293f2b84adb56d675091a87cdbf10db21ccbc7d507588408cbd30
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:2279ded67886984b22d0287ba0bf1ac0abee5c4b77a7252fca2cc80f3b5ef978
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:0a7c9e09b5f003a8c0db177f97e3347465dab14a597b7944e7c08f62a0fb4275
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:1a8c9910949771fe4ac81715d38dc89e305eaac08ec101052bac9731dcaf6007