Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:f48c938fad9254db0b5bae0851d092a11eff3d639595aa9b9fda8ac9cf96852b

Manifest digest:

sha256:ab480a2a38fef608bcb798d51e8b9a8da421a6fc41148597734e62fb904db0b2

Size

488.92 MB

Last pushed

1 day ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:4b7959279c9b80d109b1dda1429d5b2b03f2fb19ffa00769161c19e8f8325b9a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:58cf5a281314d90f9e45f80f36622e99778339ccd07437f6f846cdc750c0153c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:96533bd2041656714d64e8e8c6ca5b27627dec458d071be639da9c83ef5e5a98
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:a87993f72bb752ebb39c1f30752f0723f43fe0312c7c4ce7c2f7a80304c66ccf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:5eb277842114ab39562898fc188f8da8d0c93450204e8752477978b98a5a9d94
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:9a0831f397d5d6d877cf5e7b5130142ccb83d93a0b40e71f812b12b50d495482
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:26679e202748562e5d31d5fd69d71f0eb672914bede461e6270afb6c61c817b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:a94875f9d7d76d0802e59813a176ef1ce6f6ac1cf825f757fd221501c30cbcf6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:3f4ff7bd706be807ae494150aea06bda821da7c30870eaf0717ca4a4b7dd8fde
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:5c566c96147b27e118b90cc06a8b4b6e4b089839fd1cf81da7b36f842912b3ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:821f8fbed8a8b367ab13c7c9a1619faa9d7c1a99dbac6ebeeba9aa4d84edf7eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:25d51cf04a36e18a28de1f3383567f017d7e973ccc9644346a713e480e6424a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:a29bf4af16b3edb18b147ba32795b0fb068c5ca04c5b623aee3288d1418f9772
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:34133db14c34a06a7e7483562770a700c2ea4e0d54a8e4e0456cc7b2168be70b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:0103ff582676fd43217b3ab8eb1c4d01edd6c58034876cb3119edd5f31a5814a