Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:cce2f7170943e2fc45d8d67a5b1d0d8869d427a12afb0f97cff5456456e45f4e

Manifest digest:

sha256:c4d0f7d2dacc4152e040551036400072f09cc9ee9064fc3649ce95c9bdf28f94

Size

488.90 MB

Last pushed

5 hours ago

Vulnerabilities

0
15
17
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:ce72c459b8d12237b1647d88adad7d5ee719cd7094907fb23cc1498a533d61a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:f6ec84701382fbb3e0b53987a1ca896cf3019a61bf373532890fe405912bd04d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:dd5ef547918fc228c46316091fc1551171649459ca817e593355be0e9f99d5ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:419229522b63b7da12e6c7740eeda0e70cc1f7569193ccd8a6d9374f7386ff19
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:5cae1abe614d28592f6e1e904a19e66f81ec1c67005ab7fd9c1dd4a0c8af548b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:a80bb1e674027500d5249aab66d277be48de617ca6dc2a023dcc56d9c482f829
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:a27fe6e52865b1bf1b24918d2c030f6f7a59b925e1c034174ed9111690ef9bc9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:8ae6d6b13dc4cc43d3d6a9abfee5f0d4c00f213392a79549779d7ed8ab6d310e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:4399ca1b24b4a9419fdfff9ebcdde3c48771828bdda421603d759f6b514b7e5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:a89ca7f5a53a33da3edcf7c0ea15f4d1e83fc9eed98ab1ed73cce9844e0e130d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:4cc896413764b043261c9e36ce49bd38e4f59eaf6a19c1572eb483365d2cff95
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:ab09069b76f7b319e1350df119fe6795fddaaf428ceb6a118164b10f03410abd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:e99d41770d9ff8e956f87bdb71cef357abbac90b507cfc75ced0a53c4f2ab722
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:5eafb104656b1f349a7afe94c97d3dbd7ddbb7287a559fb5101314d05e1926dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:26f0dbffaa0f39fb1bdcd44fd8331ac4d4536d97fb8a4233ff5d9997556d910a