Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:f574671ab9132ee5fa916ef30515ffd427cb5eb03a9cb9fe427aab9f7b0624df

Manifest digest:

sha256:d037b211ff460d937af280ad51646b985c8493689318dbc06cc85a3f430d8d29

Size

478.40 MB

Last pushed

10 hours ago

Vulnerabilities

0
8
15
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:9d9a5b5b7d5691f5b2880cc6e0e08e86b3dc0477a91d6f6563a2471f20d94471
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:4009439364594fe4b286cda6233d9333d4ad44fc016d1a824d11d4166c313e92
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:1141c22e34b06ce9ceb0e77b78091fcbf675b4a9a83348a8f25a727ef836dcc8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:e0c6cb5281961fe1ae5db3d284c8e8dbb03998ca330fca8353dd78456698b07f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:8e4d7239734715d6ed5f31b9a1822a87a115e5fa739fc72d507a6f6d17c6e412
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:806090c944a458a68e483c676dcba45341414102fb06c4336bf97b4990497f47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:9fe8ce7a19188b68d0ec22801d4170b6512668f850533011969914caaaec4ebf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:68582d8a3074ab524411a01abcb65f6dd8e7b4ec09088e95d985fda560525505
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:9dd68be734732ca6cfbe3b664ecdcc453ecd206bd3e5f317de4105d1a33b6015
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:fbeffcebb9aec3e76ef8f30b036d0aa508f0b18157d7b915444a3b0dfbb19a38
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:04fc296657c563a450b90880f21bbc9c6dae877971a518a2c6ad17a61fc729cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:3cc767d6aa514b5b1695fa21d6cf40cb6405f214c17a69b0aa17bb419b8d7813
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:bb8c7ad6a83734d89f18f4eebb3ca8431e16ea18260187015523c2e5d61c5d54
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:e1bbec6e42301636e71b6716dcb11eefc29d408889fed82e59f2becc4ac3f308
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:776c8c2965ddc7f47f3aaeb45b4af460202b53602bca4f03c7cabc5ddaffd1f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:af9810fbeb0047d0b7719c7ba62707374096e205e8abf660f37ee0f8811a958c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:046c42a355fd7b7eb2766c2656ca88507689995c6bae5d0c1e68e0d6e25afea5