Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:1c3401ca5b4c5ba26a7311448ea6f88eff0338d2990dd5d8ea9a2bb5057f58ef

Manifest digest:

sha256:ba52a9b5f35904951559a4377860c77ebde5f08f003ba231086ff464e42899d8

Size

488.91 MB

Last pushed

7 hours ago

Vulnerabilities

0
16
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:ba220b0408dddcd530bee28514bbfd4ff7ff97d57dbeeb6f372dbc407607e581
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:3ec24c802a9b5a1b8fcb7efc9556c9359ca590f292f8800f8d397868a196ce4c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:d88571560356dd26a2faa309142f23e51ab91c19e6cb01d873f23f086b2c4c20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:bed09070e521bcb4b238760ba9619eb76457ac511d4602b0b0a7098bd2e34983
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:dcb11ebfa84e12f99631929e176b58bd007bac178b9761bf39c6f5d2a881143c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:9f820f1ec27d0cba006a7932c6750ec3d5f5811cc81a5a025404ed7e2a1bf742
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:825c267e3a9c5eddd0b1785eb031205bcaa177dff515a719e05847d05e2b7b98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:702750739a15201a4f17efa7dd96d5761684e8b3d4391be3186a9192a478bc99
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:af6e6272b34e56c57df147655783b75da3af60d60fddb3a9a91affe62b313186
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:201836f6cf81b59b89b4c98914e14c4ac9c9c15119f02bc113b5ea45e4b2bb37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:8d082e812a4d3fcc0a7e82efb3251548d884291651c525809dd80b4f7e10d261
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:7e7a534c1a34790e8cc5ffe29860778eb212be4869856eb4ad9ec81f99537f43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:e5a4820d295809d9ecbd0898239785fdb22b76dc859f8b37f4260c610581aed3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:85af84341084bdc1de83df5097663d53d1d8414a5955983208df05a0e68892cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:9ccbef18c725dc1ea3891e7a25bf22ea38484f061bee329b1e957c833ab98fc5