Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.2, 4.2-debian, 4.2-debian13, 4.2.0, 4.2.0-debian, 4.2.0-debian13

Index digest:

sha256:5f2057be10a0e861a464ae5e6f5436e7e9b51d4d97202f6264123ca1340fd991

Manifest digest:

sha256:4fdd5459d908f3ef13b2fa676092b80e23c0ace9c0822d35fddeb19f9816a01f

Size

473.08 MB

Last pushed

1 day ago

Vulnerabilities

0
7
14
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:6a19fa1f740aac9f95fa77501b8eff7ef56bf558e03187f545effe4a79980767
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:1f3cb2651d8d29f162b0871174d4b0348793aa7d9a08c75c3aac6579d61791ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:d9fd5aaf4cc8bb4e7930ff104a7d744549c8a4df7fb412fd10af5319ef2c418d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:a8ed921486133d9e12f566a69fc10b60e811604a2eea1c4173e654e716d02221
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:09825a72ed960ed8dcf52c49069cc3215fb01e184d0caacf423d544bdec66b87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:a3e24916135fbd9890c085b49a295dae437982c9d4b9ad3104e4c5fb54123bbe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:44c0da1164d0f0c489a056c2c2f2288ba606c826092cbd51a93f06eb512ba469
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:ab14268a69ff9f3177a6ab8cc48a52d5dd2898a682a3f35f569f6f6384a39e29
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:92800d3872480b810093e4dba8a1ad9a3086f51ba763fa176b6301d81017533c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:a183c198db11970cad4622a7f9d1ac65dd4331046ceaeb035b936ceaf48918f0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:ab0f1a89e214ca211a8a560d8fee8730d4c55b59eb193c9fd26b7aa5a5818d19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:041bf5ae5075f15e8f461c1bcb20a9efed69c7666b89a0ce94faeee0900ed1cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:0c3a5b4b55ee8c8de252171c574c2550553a73cbc020c09c7438656b61e86b21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:c4f7fb8b2d1afe34444d0830be31ca547adf3abc630ab4a93aff5130f78a98cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:6f3a2031fc8071a1d8f97fd1c071d62a291577e1576361a90875983121fdaa2d