Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:4b217ce40f40899b4b0c12ec03f69fa366097c98f2cc8f6bd756f55e3833f7c9

Manifest digest:

sha256:889a12b1783e28ce60a233647a803a246cba37a10ab971eb099190f16672e677

Size

488.88 MB

Last pushed

5 hours ago

Vulnerabilities

0
6
12
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:967252819ac9d21e47ca433f4ff4de8834c9b961ab5349dd1d0b56f8be6f7bf1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:5d37867b9fb9804737abbdbbb3fdb3350fb00a61ed9ab1a69bc7f60335c09034
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:59e563b8ef1ce386ca9b64c1957cf0eddc3ab28a1387b43bed881c28f399cb90
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:dc602670d9dbdb4448a683a91740cc177fa4e3752dbd2865a2a1004394eec7cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:83eacb2b691f3b2603c7003ae738088e3c8c05934162442ceba0ee784721c929
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:e35ae0ab429ecde6d1e360c2d3c3f5fd7247b0060b0674da287f476ac28f2b84
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:709654b8d5cbd22a0fe961d3da86aa9434399230119ea6405562583b397e0a37
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:f16a866b859593494357dae4e66daee3d658413ec1b6cb1e07fe1208443ab144
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:7472ff6a0a9c55c589f593f95dfc26fecd46108008ababae96efdd3558afd606
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:45a96e2c5b5c8ee4201f3e158865c0290816cfe6a03f5855ff18499b5e52631d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:6c43e2d9613de7b13ceb2d9b1cf65bf71f1906f92292116f4f576849c2405049
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:2262ab80c0dbb2612e28c49c7f159392158643d195e758584bf9a1b365e4b59f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:1ec3154d6d4b9b0a3be042e0fa5029748ea88510b479f355ec798494216dffe5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:5b8578f77dff7a1c13d905b4bc90b78935289ddad245ad1b6d81c681e9cf682a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:92e4dcd86dcf820d06a3738b089bcf7c535c84915f8686f0d4436dd7dec1afda