Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python)

CIS
linux/amd64
debian 13
Tags:

4-debian-python, 4-debian13-python, 4-python, 4.2-debian-python, 4.2-debian13-python, 4.2-python, 4.2.0-debian-python, 4.2.0-debian13-python, 4.2.0-python

Index digest:

sha256:f971cc945b91cc087286bfc438605fb025aeb636d294fdbd4638ae2f12b3f707

Manifest digest:

sha256:fb67e7069256f50c62fe84373c555c26bccd0cbef01197af84c1e6dc2749de14

Size

488.88 MB

Last pushed

4 hours ago

Vulnerabilities

0
6
11
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:83dc717e9c8c06c656dea8171859d5daa6dbb22abbf936f731e838e51c94e626
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:ca7083ac8bd3ca71d4c945a84aaefdf3feb7a7a90fe2bfe3eb195cf279f547bb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:6e09ca200cb36ac22c19d069ad6d8b1dbf1a2a35acb0cbd514560424ad74402f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:0384cc951f63b5ef245593f7fc41ca3c597c161ce370f407dc027c1831908505
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:05628dc64e5f4fa8a774c4f999257a61fa6a7427d748f3fad8d5d06708a4446a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:2349e6caaa2a582d638594152527b9035a0ab891c19aef87bc9e9e750e7c7203
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:43ec288c6c9b021b864e4f0b35bf4709bda83d60ef711967a44f56be0e46ed3b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:10f60c48ef062a35a1af33ace29a01ef202a90fa7efe42fde009221eb0b4801d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:8bbbdc266a7cb7b69614e50095e1f337c817ad09ca830b9f835d096b05519b73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:bc6914f6a5a58781c3d41f1a9b54d5dbef4229e6b133e7fcbdfabc1532efdb89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:e0cdf1a455d019a1a0c8f4285a47549b47e384024100193e65011956a0f36c97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:1d47c2a23e44417ae910a5bd2bf75054687dcf4d75bdf10aa71644a36f86954f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:19e78de559b444755b963633f597d8c35aef97068bf7379b266236fa75b5f2ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:45f8eab1768b579d9137a57d47892bd2019bf9b882f6c0c8b4b5db7bf125506a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:164e085f0625c18f80fee6acb30403f10e2b8812ec45ec82db89226ce29629d5