Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:fc4cde6e6708b6b68af767b009717be2628ea0b89b9cfbd0025054768c9f2aaa

Manifest digest:

sha256:84537c2bef8aa8d569eb9e3077c62c0a98925614cbec97fa33b7ae0833179451

Size

477.66 MB

Last pushed

2 days ago

Vulnerabilities

0
17
24
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:5d491ad23c4c3a73270442726bb335d77850696f2218ea323ba89d21c56add83
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:a1b34184cd3fde17064db0449aa0229855cd21a88b2f7bc028655243897f4b7a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:66035dcbe9e0a7ae9cf9f8e9a65c9bfc23bc5cb9d5586e26ea8fcb542eaf3dd7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:faa85a4b6a11734d366b424bd8121baa86ec6f36b08280511b763f16abaee82f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:2e840b1405ba1eae6608d84032eb60501c237635bd8cca52ab61b1140e3f35cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:b74b1209339372f36f720718f423cb4dfecb8dabf79f5adccd85e8e12af3f3a2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:eaf3a74684f7479286f914fb991e8083d7fd5b53448dee21e550b3d1c952fad5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:68e430e3834fb867c23bbf28a0a7c3f488a3953876ab6eee5fc99769369c9648
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:a17ca9b404956b8616ffc8e51abf8e6eaa797a6c4565e8e5ecd15cf4cb7d9f01
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:c80f0a2c806b2e80d1fc12e3614bbede52f4706f98d1c180fd5e06f2638c374f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:449b1c3e535e9abfca3ca6f9b250c30d3578177f3e577e67b7c25654a3f4cd37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:ba75be6cb5868d54c4f13a93eb241b7bfdd1080c0e07f83d265502d52c734dff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:f5d287bce91137827b073214c3a572898126ea35cbecd3e8b0d0915603d1fab9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:1dcc7cc5810a0b61c724bbe9f3d827d7258376580b9c8e462bd9b9620511bf24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:9df00a044d8eeea809b7da3a6a2ceef89fc9a421fba229c80d5550485a22cd9e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:f72d09a421701276529a38c2cfde60e60fe4f357ac83a8b33ceb32dae74c82d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:e2c3954c724e38073a24504d1cb8f58e1783fb2a4d7b3f7f474c8af8e0f3008d