Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:bcae09f840c582dea0bcb4764346240dd8fadb8b354fec9f23086f7899240b50

Manifest digest:

sha256:97ca93a25f987f9d0f8da4593bb15a5df086a375fd93d8beba0b29bb00b27e7b

Size

488.92 MB

Last pushed

12 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:c167b5487a91e86398d86ed12894300729131956da6bdd5f297442851815e40b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:621b06fce96076923719f56c313f6261da3753d99c169196de6fd6473be5995f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:c7d673eea5084d138eed27c053e2464f8a2b0f1aac8dc6f67a1b3b7f7b252eb1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:d92d051cb839d74bc1d8ffc7baa8cc0ba7dd0564a0596cebdc36be5684767e80
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:304316f8f3ffd7c28d867d3bf079299f943696e46d5a04d1c88470529e612a9d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:f6a10b434ce379f57c0b7976fc077b6200f9d9536ef99b8b3dbe6540f9b89ad5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:42fc745f9359651acda3aaad4e494163c4ba2f9564a70dca0e762c664c97bc97
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:01afe738eec0542daf3387aee108c8172de0d7517ab8130653d654be25dfee14
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:71a48acae64b93dff4582c51bc13c273bce192d4986413a2d0ea5642ec32cc96
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:f7ed45523744842816e8e53d3415d6b15b3044abe7ec6cb525dce7ee768101f4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:34cad16a084d341f82b986bb1b6802cd7524de9e3d87a0f0041e4d93ebdf436c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:5a4c55e5bb48546eca8934d94e03f2882a6408c83e58dc69733830e27414f91b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:7a0cd94da0f4614c908ac46a2bb04fa43878a4e612de3d4fdba9e6ba197e8b1c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:716b56dfa0cc8c5616bb8354706e6e87e8e1e31655fd46e575686a54a4392238
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:77ea213e831c2b059d4cb458d7998542fdaa478b8742737b08b95ab2f6a11e44