Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4.0, 4.0-debian, 4.0-debian13, 4.0.4, 4.0.4-debian, 4.0.4-debian13

Index digest:

sha256:2811bebf59606c57edbc53ca304b17bc0f3a863452787ebf37f710b74bdbbfcb

Manifest digest:

sha256:b9dc124231def43bd24c56a6cf2d84a8e44d38a44e6ffdf44f6aca1fd288fde3

Size

460.40 MB

Last pushed

8 hours ago

Vulnerabilities

0
14
19
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:1764ee6dfc0707aa011715a8e27a7a0e3727f92c42de76b6b66573322a3e358d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:199b901c871e7935a028b9ac8b36b9345493a3a3c47145a479a9e48bd8a8300e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:b907a277b0ee571b642013df77627d21d6ac78cfcf92a1368b0b004aa4088964
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:dea893d0be0c77def4d572b14750d6476803644b4355bc1ec97ceab751c07082
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:c45149b659dd7b86f23c6018a6d6b6431419582c701917c6173b29f8add5a98c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:d0f3c7e16246b734cc623731cc03766f8e437614948500023fe49eea044c8c6a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:61fcdd7f4d8da238c63b9ceee3cc7d08131be1893e0f8ae10cd6e91d99623553
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:e1e345fcb4740dbd3e393944d16cdc597b29697394f13dce0185af5fd96f9e53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:ae3dcd65a912f9af652fcf815474a4b7f341da4f7b09198d3a4c042d021bf8e8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:b64a33451bcf6bc852e748efc651015af263d3bf94b4f63956f7cb4187b17281
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:70f413a8f913f75d210310115ce4901ce0d1edd5d7e47ebb4dc3bbea0ede6083
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:8bbd431fcc392e0279fdb93d723f4156c6c985cd1a8a36f657e7277701b845d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:b1daafd25c58ffe90f32a478ee13b6d3079005cd2963ac8e3524c3bc01760833
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:6915b5229070db32c47498b9733a745d44d8254ae4f868e422608af5706a03e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:0ab6e2244ace0dc7e24e3d96ae4236d3433c71478a4ad0a07381151d3513d765