Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4.0, 4.0-debian, 4.0-debian13, 4.0.4, 4.0.4-debian, 4.0.4-debian13

Index digest:

sha256:bc36d604d8685195a7013b2e9426ce59384bfbda3ff37fb8d7114bbd9ec2d2e4

Manifest digest:

sha256:27031dcb6cdc5e10a21e2ed140bbc5d78f284807a350248fa3cc8f9b0d21357a

Size

460.40 MB

Last pushed

11 hours ago

Vulnerabilities

0
14
19
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:5f34758794013a852ca8520454a217e2258b2fb59dd18be14b387677836933c4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:d4637e8b80554ead8e0b2e1108f6fc6366584b91ed07039204e89c154e5da51d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:56a67e7926979e037c1299393c0946c1cf962ff02cd655d915cdfdbcbdee83d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:6805044d29d6b35c0378e931cdad05ba46bf0c3d3cb38200dbd7d52cd63c0394
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:ae10f8f874c2f03c54027b0be757a80011f139a78edce51dc8bbdd59cca2cf80
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:7e07514cd58e8e936e53be39b198df67a01977528bcbc8fd501aaacc44832faa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:71611773a9706d126f25293cea500cd614466282326c5a0bdd28827ba0ba5df9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:3e5cec457dedcf6ef5b55b3327f7754f3d929edc752bb2a9b4a1fab6b528aa9f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:3575c1da0131a41f5ec43755a584ab82af7de3abaee387e8058fd8450d565aeb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:418a2009f2298e653b717a27bc1876ef7f1499e7b5520d095253d6b5dbe201ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:5a319c66d74cf28abf76c957a5b93e703a9c50eb1937c12a8829cc8cec3fe600
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:40eedbc0bbac8f321055bc65dac4981ba17bb999a64f8d664c76f41f70204884
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:e0cbf8f595025dc8d9237d859c3ebabd5635605a35d80cb2260aa2c6a0c7d94c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:0e3a5fddaf0218b00169e18cc3609d0bdfba14cfd793d370dd71ac1a4bc591b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:f3bf7c21e593b3ce62e502d6a9bdae22649d5a53d32b6b7b4655869b8ec90539