Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.2, 4.2-debian, 4.2-debian13, 4.2.0, 4.2.0-debian, 4.2.0-debian13

Index digest:

sha256:de361cf2029e821dc9181e7af6ef48bb292b5afbebb50f7ddafb996b61834ce2

Manifest digest:

sha256:74186db6f0317ee5500a53b6ffc6009c42fd1c8af4b660e5521dc457a0a8938d

Size

473.08 MB

Last pushed

3 days ago

Vulnerabilities

0
6
10
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:87dd7dab6e1768ebb8c6589b56bcbcd73ce529d110e31403d3d55b3425d125e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:511ca87d7d26cafa1064cc6f43e3226204dfed6d79e591d0979c783c3bd39158
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:efc0c6a4aec54d6d1a2cc5e52fb10b41949a37760dc5545c4f888d96e8422ad2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:f75475cf6f8a057704ad4a1da24f7d462833e23fcace9bc6ac8e65c07bc5569d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:cc25074d911d66c8ecc31db65b23d7b5a78879b287e5481e99cc7054fbcf51cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:5c7e582d96d944e4928e484f1ebfe4c757b2ae6d0facd172d613fc7dc7098ef0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:fa0f271547701ed83d85fa2facb8cd245b736bcc24eebbf6bef0ba4dc0e6ca87
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:093641003e3046250422c27b3b526417843aa19bf19012e75a0c9f19f1311424
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:401f624e5199e22aa323853a0136c745454f4834283284b5e545ef3696372db1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:12f70c053e866879b39e9d2bdbbf60bce0960dead7e9122f1d3d22f309d2cb68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:8a1f2cb05ea6c643c371b8dc28442a45ca1ee657dff37f05b688240a1eac39fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:c9005c79c2cb7c58a501c5bc1d96fb2916817294a073ddad99e4afae87cef7f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:475eeb5fcbef672a291bddcac2f3f5ca27492645028ce436d58c2bc0fbe8340b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:50cadd7eb97e9347ca2841ab7171c782a572e496a585c71163fd9bb0676d0214
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:e56df8774d42888b2494c22ea49b52b61f12658303a0fa752ed6dd027460127b