Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4.0-debian-python, 4.0-debian13-python, 4.0-python, 4.0.4-debian-python, 4.0.4-debian13-python, 4.0.4-python

Index digest:

sha256:345ecc4fc4817a9a08e55abce6d531f3070d33ac01181dc978fe0bbab5556f8f

Manifest digest:

sha256:eaab5acbbd6b9454ba57825478f8483d9cab4c063575bf6c234045160cf708e9

Size

475.07 MB

Last pushed

4 hours ago

Vulnerabilities

0
8
15
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:14940726d06591f4d3170cb8ca9696ab12539e52c0168bced576283cea96d358
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:343ce6392d068a8e3566bee6c1eab9cb1278ceebcae0f29ad56e7c60aacefbee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:7cb4846563e620ea197ec30237105e093b9174c32b32eee394375d02a16cca84
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:d0b786ea74b0aa28596ce9d129d967e663e9dc6d3b97d0a52e97fea31deb8b8d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:8b59cf79b205d969ba4e65fb0b94b7662ce6759813943587c611d53e26b59555
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:2ae805beab323f1a3de2a91c4eee4993e72ed0929764272ce22260c88f85973b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:b49fd6d8d792b5e927c6153b749b1c51e979b4e98419f5b49531c80613f69764
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:0fc55a62c0f7193d3144723ad33962c22229caf692e8375e9f74f4fd875e9a73
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:49dd160fb6ca76b3764be3b1d843949c5d6b017cdc927eb8ab16bdd996d5d5ea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:5d528fd02e01ed9df546263a52c96e15e4739d7c85c9d897aaa0a1aefbf17d81
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:8deedf555c97f98b59e90d098f11ffe71a16b86414e4e00fef7099e78359b029
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:ebbafde7473fd00e78ee9e026e0491a473c97c79fb71d7f763559025784e8d04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:07cc35062ae70cc9e41e7f751168907f1a79ab57c0ee858aae7464e709bc2bd3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:e19c9ac51cc7e8fd4a851c2c1b157d8b8ae34cdbc7816c8af340fab3132ccc00
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:dda63050f1170d694e56716fff6277243654e9e8598751e3178e266e03a960e0