Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.1.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4.1, 4.1-debian, 4.1-debian13, 4.1.3, 4.1.3-debian, 4.1.3-debian13

Index digest:

sha256:52d5d7293b342c7ab668d2bc75977f2a0ffed984a24027bb506547b7c070646b

Manifest digest:

sha256:0e7f5ea64628eb5ccfaaae0182a36e452bc127996b3f37609b7f48c6ba613d92

Size

477.57 MB

Last pushed

14 hours ago

Vulnerabilities

0
15
20
2
0

Support

Active until Jun 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:c8669142ec94eb8e52a1686146540500e175b0647f83f13ba6a41646c0b9a435
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:612dafd8573b7819133323cd144c1edad673038ed42852f93b164c87432490f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:6fa8a6c43ac09fc8236bce54563b4c7351da94593f4fd177aa089a45152d7053
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:10de67ab6839b8efc82f7787cd934ff33ef3a4ae1739e60586c387314876da46
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:ab7489e8038113050c1fa3e1c68fc002ac40fa70cfa792e23405ca3060d30228
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:7e71d17c97907811d5136e29f6a2a3ae9197ea45c7b377ca5bd21b14bf011e32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:b69d50592836c0d3b6e89d11e49280df2126573c6dcab8d57f2c9eaeeea8d2ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:462cb1dea0e2a9aac65782682b7624dd01893b068421bc2a36d33cd51d48b804
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:7b2ac5880654b46c54c796f4b02135471aff459284ac0cf1470d6dc7eefb8d6a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:01119615e2a4f043fbaca2fb635a6431783d7769ac5c930bb934e72ec4c830bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:8f7012efab11d0f540b0304183c200eee51c909ea60e8bfa6e8566b8cc606e58
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:d6e8596423cfd117af3de57b768881562fa34b4a85195a0cd8d2f698f81e0ff9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:b2ac57eb7c8cb360464e1296a0ace02c31e649d089efeb70fef2a5cd34f228f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:88e1b588d0c362af40817a87aa917bba4cd25e8b8526eef15735b4117888ec5b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:6ab672e7bb8db32ee65e2ae95901af526c61d5a4f88ef0d178abd7f5e56b889b