Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:77c88f3bf3879958398e3cd154d1980a362d66c039785d0697f9b38d4b0ff59c

Manifest digest:

sha256:87fade145bb011af2bda36d3ca259f99745602643c03113f7c875e056ada59a3

Size

488.92 MB

Last pushed

7 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:bbb55f8de74cca6f29384359281a79e22d23ffecf641390ff1e49905b898a81a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:e18cfd76ca8253c6eb2c409b39f07ca7e7432374c627ea2624c86660cc72f98c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:dcc540109c1b47919561e4bd1ca53b5b430ab945fced1ce5f476fb47d1012a38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:12767d8b4d543ff2a7db61c25b7cb535372579d1d035d157be67767f91839367
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:1b11228f5edc20a4cf6971664f7f1de0202a0c887d0f4ca374c76073659cbb4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:79eb77c70ff3852b58092f34eeb4ac9e76cfbfcfb20ee61399e2ee7f549973df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:e2e61f9ae00c269bbdf7d619e659d86055f1a61cfecbf791cab5f1d8c1f7f43e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:cb5775e7708ca2655e93fceb208519ec643e50517639734511f48d8440feff33
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:164c5b99f2704d4143ab03e736c3e42dbf167f84e456c5316f0ed1c12cfefb60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:1a195a1deae6e5d7b62a1047cff7d5afee0c8a582a9ab08288a12c0e1f33d35b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:82e8b02a71d6faa3b9e5322a9d15589a6277c158fb8b95a312f3a876507ea0af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:edaa316856022e24eb0087e7542ed6e409c0209f24f266e8dfe5aedc14f4d7b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:14814a3296c46572e86aea73982b7b69f91a26cf0c731d39586203a50675659e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:fc327418be576eac17047321e25dee16db5e6ec07e518ead487fbdda028aaf32
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:d1a088d63cff73ca5cb7fff5dfe0b1e5e9ea3a16c3892faeff1d43d507db75b8