Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:466fac8bec3dcaa157efee28a1aceca5e121ee6644becc24c63d29951821b8c3

Manifest digest:

sha256:9622ac82aafcdd4dc33b9fd1d898c966ad3177f02a48f9949e29a54b7b22b216

Size

477.73 MB

Last pushed

1 day ago

Vulnerabilities

0
9
17
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:9b903352fa2619b95d26bbb521dd2ffb367ac19ce785198a574f722b86cb0aad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:cf5b9bc191f64701cbf1c5d32d92d802bd79aa6c76ec6427270d4e264443c6ee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:8c9ba7202546875cafcdaa9023d1525ebf77d70acd6473bdbb959ac7fce47029
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:8f78f8131e783bd6d850c3ecb5608655a00ca731725f69ac33d6c7b60d136999
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:c0246056194fe23cb64fb8709927d5eefcd0fabe31bae9dcb9cd9df2b4739a35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:887ad87b499ac35ca08f5bdb272373a1cc5a6313018e1975733fa8d96e1fc6c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:3ecde52bd0fb12d23dd948443106b775c4a6d6264e36877c4699c4f065378d1d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:f628d60f71a2b86f2b75baa5dae9cb5822635afb94995a1bfd7452fb6bc2f16c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:f455421a91f190697f03bbde7be63ec02b371d7538f7dcf445e74bd2dbbebacf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:d70c716a70d37ed3f1931a12d2f699090a783fa3b5a6060694f35fe387d7ca5f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:9a3f5d2a2e3d653e5b9a7ea05de59fee64e04bbb45cae4dd1fecd5ba7adc4f66
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:ed06c076e05c0f3c6afb71b76aa7788dd4d77f0e6f116514e75b3d53b1a0981c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:4db4b8736e40554515c756ca7bcfa0b9c5be4de5bcf47af765dc12289a93a92f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:150f288a8b5324740c65ba5ac709fcc25bd0717e6d3c86b4263bfbbe16112a9f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:ce613dea358b72e56569e4f599f96fe00fe4247f744861373dee6e51119ed5c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:700e3ab7ebaeaf5b7814d22203863a06366d43910df029f7febe304d179b2e8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:91ec64e44f53c8d51b08b0b5f86017c40b7d05a052e745280da14a9853b6a29d