Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4.0, 4.0-debian, 4.0-debian13, 4.0.4, 4.0.4-debian, 4.0.4-debian13

Index digest:

sha256:8f4daee35652524921eabd4fdcc897ec8f9faf4b11d5009b5de627536a5bc7f8

Manifest digest:

sha256:e1128411c2d1df5d551a685e907c96693e0987f7791e87275a7d4ffd079886e9

Size

460.31 MB

Last pushed

9 hours ago

Vulnerabilities

0
15
22
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:0fc9547d70b5c8126c9724e4fda1a9a38365014c7bead0c80ac12a475ff73f10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:4a8eb2869545953ba192fd4473682aaca99e16e7b71682b02e489d6b1a73ad70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:87af70f96aa1ff2be5f5db636c1dbc5848faa69141d1a23f42204d5e0ed957fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:42ee909a0fd412136a38ee9cad0322f7ca53ffea75aa38a33e4ddabe39eae46e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:d13be32d4fde2650b04709c048d80a0a3e74379ef971212aee583f0512381894
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:3e3fd9692d554b037e0a1587ce37d4172e82aa13e67264a8e51b63d3f1677cf7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:ed43efb966eb55d83e86842ecdc62e317a6fff65e3462670962504b82f3928b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:fd44edb5757016c2f877ea253ae328d92c99ece7239504ed6505082d957eeba8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:2521d3846bc2342f83af123c0b7570b4e3739aaf8acf23285d5f7566c8f32802
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:85720a22438cb1b7449b34293bcd7956554ccd26db9684360765623f5d36d265
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:3137c99dee007be832af7926d14782e123d4d8be02c966dd07dcca006e081bfa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:b73d6ab195a08cf3c75c46d85fc3b595b746b7ba3a2e9d16108a802b4f3ba8b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:2d9f400eefe1aab6c0000c64099529fc19ea729f5d2c44616fa30d2d382eb3c4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:139a27cfda461e46c36d27fea4e4e24594aafcd0e1891f712f8a155916af166f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:38b184f69a6b110e0aa1133b5331a60630c90b0a12eea1ab30146ac53f205110