Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:0d6c9be7fb38d28d298757a6254bf620e252fb68285e827fdd45fd1a3564ee5e

Manifest digest:

sha256:c47f318d7ee8a577d670c675ab623a10c695ee2b44094ac33e1c579abe47ea49

Size

488.91 MB

Last pushed

12 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:5aaa7d85c449b1acebcd9a70e2aa2268134d6f76ae0a814931bb5bb8d201827e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:6dcee8a6ca563ea55ee7ab0f50e76a13ed11ba10e150a5daf1a1c8b6a47237f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:c50a5852f72e466790f1092f4a0cfad9a69be0541c233eab4639ae8f697fa0bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:9bb7a80510bf74c4109f4fc8e73ea171178cdd6ab34c1b869f99a0623e678797
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:31b1bfab2ed5ff1fa22fa0456e782b4870e52fceb0a908e2d40611228ac4c934
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:589c886a07e5abd9b5d2dbb314f406e0380312277fd5db7500c88b73c2091857
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:10fafe48891f75cd8086fbe395879fc05bc8f9ae10151848370a4cd0b241bffa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:a4ecbbcda30f3034e0530aa8c7b1e3060c4b47ca41bb0c50660f399142b77f65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:1cd8796ddf96542916fe05c6f099b5d4d83d7e1651bfff5efed6011651f64f1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:47c021d9c2f2ae1bb72b9b9ddfbfc27fbfc00e6aae4b2c1aeff748ce0ff65478
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:69ea82ffef91fb2e2682f6559718834eb87688a1b3436d0cc1999f31c4b72c20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:0d42fc1dde9acfd5559f5c57bda555edb13123012a95f3b6c40317b2d68cf65c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:0750fe5c6ed9f54f64c5458444d11d6d90337e71de6d171807d981e4a984209d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:cc60b7bec78110be21f6b757025131d0b44e4e0292c192fb56e08adf3d73161a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:7d1ecbe0f05ca4817df2bcc0c1b06dc5b96cf980c94e75542dbb7fb7ef03e0ae