Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:52b5299db0acf37d41fbed6a11d2986cff0bf1f651ad138b522d32bcbb8dd6f6

Manifest digest:

sha256:d0ca546520609a08269537f4ad8da3defe9767200899c247f2efa4db566dc264

Size

499.32 MB

Last pushed

3 hours ago

Vulnerabilities

1
9
12
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:0d4deb1d36423f0dc4f18ee90b0d8a9ce15e85c6fda31721f8b95afb0d64bad2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:04e4f408c3c5532d9c2c113f88e7c154fe5999015474f5fea6d8d12ffa6c09ae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:728a76275e098c3c5b142e891a3cdbccc44b4b06a4c31b0c61a901bdfe95672a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:ff17937f7ccb0453fe67a51628d5683065cb48cf0c18f16ed32cea6d33c25219
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:a8b87d07d47f5dd745f5a18dd6703cec56d253b6c56fa009ddd42d06aff345dc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:2850a426ebb48b636a1daf8fb540d341c62c336887d33f5a136b2c983b836e23
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:cbeaba84005e01ba4f59ffe5d07ce9e331bfa484a9d70eaef7c246344a636333
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:314c03edd3afcfe28b45a58c2b37e1390e42467c2f229ceacec59a7df3016fec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:0259966bd1e56d594c2271db1f499081481e1d47eb6bfa80d5581d241eb3f1bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:44d0750494d6391612b4d0984d8a936bc7228886595a4ed616a9518a7689a4b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:7e1516a6d136e94b25658bab25d45d0ed6cd975feeb17d91288a03024e00bf1c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:d81f9184e3e0434a08f28eaee7c4235019261aaa04df142fe1d822c5ae3e5c00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:a1ab8f046d9938129f5ca2ac3be5a0c834e25684dbb0963c97804273848c4805
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:9e01bb2ca11fd761a05836c7646db71a4a82ae81b92b7bdfff23c93cde310343
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:d9697524ff453882da2eadb1eb7827b6dee2e713f441c20da507742d594e562f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:7a218ffe89d5793e25fdebece73c0dcc7a57ed83d373bdbbd0344c4cd236e60f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:be93e7da7c8d2a45d7375e1939f65394ed76c45ca1d166188e5c82ba41ec58e9