Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:27ca75ab8427f461750f151e6c6480d0c4840639157067d17231cab7c4451b78

Manifest digest:

sha256:cb3563fe5eca5f7f4c28cbfdfbb38d8e7eef94a66ac7f7529303e790d522f341

Size

488.91 MB

Last pushed

2 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:1cb1ad2e41de51d7ae25ea953640c0a257eba92ec42b221257e68093b1b76289
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:d3e30a4b11d396595a85213852e91a6ada09f8885e5a86e91f253d91e4afacaf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:792d022b2b6e3b1ac4dd07f0977dc134522d1e8327788a3f3a4624c3574915ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:a571ebb8bec5c77f6a2a9f61cc33a87f6651246173dac05e2351abba1b419b10
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:9046257e7c226abd03e81c6c09a66572a1c6b097280f0a97eb6c8c906081f065
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:532e1a5b016b84302aaa482092bea921d316f81f3fb47594e8e100bda634e94a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:3838a3bc378e9e4418f4ce1d0e0f72e1e7e54eb29a92a7d45aaa7f20fca2ef86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:14db5caa3148ea5c88b2ba4c037ebd1970d0b08ab5d908869e4878c37ac49437
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:b9e68f9bd979437f77f01f0e4974b887e5e033b843aa317828ece2a3305cf1f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:eef0fb6098526deecaa4462618ee55f8162c39215cb29580d7c97e8c5298d50e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:436fa224bcdffd8b9ac85e5ced50837cd447a364ff1ec1052cede7964238ee08
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:2b5a40129e14f607780a2e968322e3a89a57853ed200cd12add09bc21e8fee6f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:f509453002a67bc8256349008acbf7ea8a5c205968922a8909078308cacc20ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:e9db5ef33f2d73500e236c6075826823eaffba7f1e09483e826ad3ad2b6ea779
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:5bdb43446e7a20357df796db42c9aee9dc9a74a5644e6f33d27595dca14c1be0