Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:44ba399e3308631b5ae5519764b826bcabcf7efe9b64d1731bb9edf71289fe4d

Manifest digest:

sha256:7fc84d51d88bc2b1d495621e1a50f700fd8e8b012e4c5c3ccd50770b7bcd7f45

Size

477.76 MB

Last pushed

7 hours ago

Vulnerabilities

0
17
24
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:c7c11afd07a337195c7359841bbfd7fcf2756b794b665bdbc05faf800bc6189e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:414ad65d9b835acbdf53b328857b00ae2b96f272b9f6ed83dc61caa1638cb45d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:99cf39c736af805b72d92afa48e596b08d65111f27e0ece3889e6164a14bccc9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:fc864e4c1cf2b960b21d32f26079b71c8cdea834e7d7378e720c4b9b8a715280
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:7ea0d0755d491738e66d13c6fcb68ca4d95527bbaa9fe715dfa62145f50281f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:519a3b9b2a4c7ddc2c84ec2eb2bb050dcf99f92f13cf6dfa30451bbcb1f76c3b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:85c25e98a331717d80228adf26b50ec22585581e83aaf058aff78418a2e0448d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:2ddc5a4cbe5f18cf895efce0c670f15fe2c3ed967b054144f108b82dac285059
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:56c9caf7159356176ff7133f1664a9452646efe1882f28be1c3b5017fdb7df8c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:c0ecd0a1ab480d8b530fe9d0ced389c92ef45fbe1feed354d76fe4c5e73cf6db
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:3e9aa57e15db8de2b2832f76153d0e2713ea9e901432ae6b325c28a53a1acd0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:98b58c54a1e48e8043e1e576c65b2601b72c32c7a1edadae017bf0dc6ab465ae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:ae891c3088c2e7a99ce7633dbde6f31d03e1b2a46bb4c9b48fea43de4f207159
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:0c6acfe59aca314ebc904e487627c32783696b332a7bbc9d1c5af3c4fba0d8ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:fb1feb34008ba405650293b1f29f08ee2ee64c7d4f4bad1a790445dff450434d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:e55a7fba5edf966aea8aacd700bf43965e9f72edab2339ca15f3bc28387c1617