Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:5da5f23bed40d17db04c6d7fa3d2c727a5bd66f779ec0c16434fc0a99c6d90bc

Manifest digest:

sha256:de3cfeca45b535f8519169da6da11d9076a34eac993ad4fbd6160c688e30400c

Size

477.74 MB

Last pushed

2 hours ago

Vulnerabilities

0
11
22
10
1

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:2d4d85d2b3ca9012c485cb6de5ae1bf82eb4736976cb625401023c7170095db7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:4c285f9ddc135b8fdc19c6c6329b95812f9a4eaec96504909ad640ba54942a93
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:1b7436b9b9090c7314438b0dea51dd37d2e025b82ea4f5358f2c62d33354292c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:8f7fbd2200ed773317ff58c444d59afe2672f1711131c1b0ce05148193b105af
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:27ff097f8f19d0cd0a27bc0c25c28c404d68d69bea9a7d67bc9023cf2fe9cdc8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:0143210e39cfc40e347cbcb6243cd8488d12eaa7999d50ff9ec4dcc288231f0d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:f1f9fcc9dd7364a994585b11e4595e4f4c41bfd527a37a5659819810d55fa8fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:cb5e1d40548548e0525560ba10f8264c7e62dbab3493e16aa41ac0474fb175b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:3ddf9d2e3d64f778c4f930bdeedffa1e675f488e5d01dddd615a4fcd045736de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:1160cf0dfbbe04b4cefb7affaa24e30c793ebd6b23ff94e05a515cd58e9f90ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:c93596d3ea702f17a48c0fc24bc1458066211eaf62cb7007107c4b8428c39543
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:4454c99bc17541887ac53043294ff1b6797030eb0d009bf116fe70c879c7694b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:7a76fb88db177c2986bb11ff25ad4423c7642aa3bac3c468d0fe9921eefab485
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:83bc27124ed11a307e4279158f7e65e38d1f46d084f817a475891e75a3165548
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:856724539d3ad1294a4aa01fc5f0ddee5cc284ccf05e83abc4e5369141f545cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:a5ae5791fd058486d7dff6555d60d303fcd041ab50b2d1879c63ed350a72a4e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:907739900dda0c00a9c36088e190658043d3d217bdeb6dd730129eb6156e741a