Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:2a1ec533ce18118864616a097357b3747eb6d0a560d8e06c846d924e5a7cb164

Manifest digest:

sha256:26f21971d04b90d0758da87dc74e5f5a125d0dce45237393c5678bb52ba64b05

Size

475.08 MB

Last pushed

15 hours ago

Vulnerabilities

1
10
19
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:8465d450fa79421ef0c67f3463dc5ed4c0cfbd58d9f007aa62d5f053319f5dc5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:d6055a2451d674c7aec98966f4c5e0d2b34f2fc0b49e3deab0b8b73bbf22d971
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:21ef9bf343dc36ca631fb0d8ecbf17c38f417f0aedf3f8372b1d604045913009
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:6b20edb0d2d98a28fb391fdf186d1b8af9c3924633835f5ad5aaf0c2cfea5dad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:f472de44525cc59f5fea9497b6058a11dc3ed5ea388028e37e0b492092045f20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:0c437cde1ae232e902d154e1c8db574a3c1cb7eba061c5ab495aa32abd113627
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:579e38a11420e043e3bf690653e8161f950e0697b75290d983ebd893f0446dba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:643f2252566190f1ed1c5245bf94fca01a0753ef59f38e523432f4acdec35124
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:1f9eb4205c44a09840e988ca9e993076a6b5faa57e73600c157bafc929972a70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:9f9ce88358bb49b18196da1973274b40c44cd6395652868d56741d0f85aadc13
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:0254953e0a7bc9b12c403478704c1f756ec13a6dce6fca4f49eff485761e9545
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:31d3ee686dfcea9143947ed22d0b6b9fecc8a6ed53ec99c184db3451fe04dd3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:c6f26c8bda371c6c979b91f013c42f654f03910321f4ee1c6e11a25991a713be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:0721e018254dfc3b72d2e8381c12c5b117d8912e3416ab24542583c4e3af2269
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:32568b39bf53ad8341f475697d503809cfc2e06f03814bbbc1215fb6a689917f