Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x) (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.4-debian-fips, 4.0.4-debian13-fips, 4.0.4-fips

Index digest:

sha256:ccb61186a28e35891b040d638ae4988f6e65caee300e4acd42fd9a3a600f1d2d

Manifest digest:

sha256:7a1bea28b3cb855bb8c47cd9d6e95b7e92ea72fe0e7d64c47f5d72b985f228b4

Size

461.87 MB

Last pushed

8 hours ago

Vulnerabilities

0
15
22
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:a75c376c2566880e2b7f608c4314bc933e0c2bdc919ea4a8b1653da0ed1398c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:99a3a1204b5893fd9b29b2f8b764a056ecd542d1c8e322d217f8311eb185d2a2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:ea4f7421403712085042a91e0bd432da6c35c6c9a9e8b1b01a521b3798cd8310
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:553f4d8b9caf89ce48401c29130e42c4d760676345e57606f0a2f051ddc80eab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:bfb9266332dcfb6aaa3f26ee7b41803d9d50b337434f72c3271bd836b3ae52ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:03607a2399cff9dfbc9a38e797c506856daf7caa26d90267af4caa09f5ee3a65
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:0d5e28b113a4a602e92dbd27b90e1a3233865bf90814170883c102527ddf86a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:8b583731037cb53e13ebc9e8df5a76191d0c0c37697f74ec4d7fa5c30ad64f67
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:830eea3f748257ad668934759d8dfd8e6a79d91d58e139aecbfa09bbe49e872b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:1f285507965779f2cd2f82b2da5016960fc425f2410f4d7b392ec968f222540f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:be9b316a466fc324dc1dbb373684484ce67a1ebcff54ccb429e59f21e44e2a50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:505af8640f2c4a7649783eb35ba97863c06fd5b82f61a7bff049569a24961305
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:994db694c28fb2a611ec9cc7aa4f879fbe9c7cfbe05704a810f8a1096c24d660
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:02ec6c57c9dd7b6d3bf85cf2860f922e70279355954b8c13082bc69d0fa7b7e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:ebbae00d952978c2a768693ee4cef2418be58947a3796b2c628f960a0f2453fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:676309200fea3a82bfdfa41d0ff46f56bd0fd69ea2ad0b0a5be997858a007a9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:fee0709ef8ed6dff331009e5d0ea0244e8c54d23b63e37847305f0811a40a941