Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:7a2b0d48f4660602ecb9a476ae7b9620ebdca1018720e66ad758f7f98d60f7f3

Manifest digest:

sha256:9c3b740ad5f3a60a24318026a5e317b0699105ac3232fad4ccead279efa84504

Size

477.73 MB

Last pushed

8 hours ago

Vulnerabilities

0
13
21
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:abbe924393b079d70ca3ac460db8f1ed6d296c099704c90f4478bf2e5ec99bc9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:992ad27e0148af8417ee5bb6450a1f7a357e4a5abac120f0a1b21b576000e6fc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:bd77ac26d4a4c6509b4b36444c655bb7b7f38a432741d1478c3b6541c783dd08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:b181d77343b3e3126581e215a6b9239da896e3f5625c52795af3dc6ee9d7e347
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:82387ec00b0d27d1c6470b9eb3bcc0b9e8f6e4c71ae968c0fb5e4b66301520d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:676fd93d965fbf65eb6ac962ee140931323c20e3c6137473538bc3a02fa04e90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:fa8e6e7ff37975f445ce2ef6d632feb3a5fc4aa5ecd25e6e5f61c70b0170b484
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:269cb76dcd45c1f0417bcede6c1e729ba1ca033e564076209a9cee9248f7f126
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:fb0541c229b248464000a88bae19e573d19890343ebd90c84f0119615a5f7987
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:79be82fa829f87fbd7b1b9bf01182a0cec3577eea059e026a48db7e1cde10f57
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:f200924e2433b72918c5a99d8980ca454451c3926af2c3f4db54e561081b1bd0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:aaa9cf3a2a87758f27bfc33d60918726af66344ab57ebc54c9c651a4704fbfe9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:b28b47419560908e5c1dd756acb35a27f543417f612a32918cddad4658405e37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:dbdb451d4c7040cc030806ee5fd1984820d8f96bc7448dd7698f9f851f51fb2d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:641c9708163b34cd9bdc53614b8997690ce05c437e22d09924f6e2ed43f4d36f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:3a5434f86d7e499ab9cb06d612a6b3bb25b2de26cc796f5ed0fb369437d1c3b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:7be65ac5363eea5bd2e4d1599767f04560d2e27d76f19ccac951499bbe8d579a