Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:5318ab6f763b27ee0fb53b32da38f30492ea23b49603ce73ae183f75b04c4641

Manifest digest:

sha256:fa7e988e57f47d3178fb3d117f125f98166935fe198b437aab4f0f509e990714

Size

488.89 MB

Last pushed

11 hours ago

Vulnerabilities

0
7
13
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:7f521785f7bf5e24749af51bedaea9d8107d10e9c3e845ae68fbe50eff23aef2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:d959804ce4b51cfa82c2ad091a6ee6c3e09dc06b88a366c31105db198c98ba1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:4a4e22ce619ca71d656ad3731067bc357b2fa00042e8c770b989defc29710c6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:49294983a2f8503d350bb00f4ffe16a1580235f08f426eca26c9ae8fe4f5da8f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:9702071b201734b869315d9bc52667ed2b3f44f20ea70c6b142e51fda3ba3349
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:64f76890fe69f4a04b1366e0b0d83270f1a0c311092a776776819dbdca249f9c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:464c5c7f7a711236a9386070e01c615c62509f9fec4ed2a1f6a30bd9abcc0291
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:a922cf8a8b5dcd9e14ec1591c8d56f82932bb087c297d09e58bd3641387673dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:82db3f027abf4d17750fea37ec0faeae7267b71bb631672c423a7149d2c6c565
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:019e5b381626cd5d0c06e2d3080da532275feff264f5a5a468ac5ebd25ab1a2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:118a37f15f3ef95ffc8530577e52946bec123007809185aab68b56eba3996b59
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:aac614cf6ad23b08e865a278ec865b5a0acbe401112a49c6ee33ac8fa2ad3865
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:be5226392b6e7b38895f6416fa75c84b99b98983f58465d837470e69fd6442a7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:42ad4c886335eb960f582461d4fbe5583a8312664ea19d81b8c0072be7cba41a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:87040479fc62a9a5f642f27e90505003b9c962bae1d3d07ca8e71d5efab91ae8