Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x) (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.2-debian-fips, 4.2-debian13-fips, 4.2-fips, 4.2.0-debian-fips, 4.2.0-debian13-fips, 4.2.0-fips

Index digest:

sha256:37ddfb1fc2edae0b7cbc64ac16cf835d3c2d2d2f31ad7f28328a6b5046047609

Manifest digest:

sha256:84d43f5df5e5858b55c078e02677b0c007d1e45c855934a8fbf1e08e45eb9fd7

Size

482.87 MB

Last pushed

7 hours ago

Vulnerabilities

0
13
18
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:6b837099721feae1d9721fd61c261c2056156f9980c49ea817dfd09c182207e9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:ea05afab20d699ebad027af19c100f65a26f334811b95d7d5700a3724adc9746
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:2ba647f75d59e88628a7f407b497761e2790854d23a054884b5cee480a6e8b89
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:c97893f0777d83915c0b641d0caf986df027fbc484c68bc321b7489b0a0be1b3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:10d9c98666e7202275b1ec868a518ffacfee614166ad6f68c66bbc761c5ceee0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:ea927e610746bf620f5111d78982dcb9fe09fa1b5f646e128b201daadda4caa9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:b95400944be6e46e476b00707ce065c46a0d2bcb10bc0c82b327202d49772ddc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:ee4400e81724b4b7f18afa4f16a2bebf388125816f3ea2a598f2e12015f05b12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:9fe13d45c5f421933df93786c2b33c0adc3a575121a5c899a8d64fe5556cf593
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:f169b58874583d2af85c0473b726a55585ccc74bc9f2c2ba000792958f58910c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:c2864ecf9090219d2455fd50822c8d52fef72561a7f74c4860af4a1fa42359c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:1f00c0fd0bff3a517b7403c2ac6181137e53d7f715dc1cfed647c14718554e4f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:a61da5257f2f6164f7fbcab2e43b2cff1c94d266f85ac54acf8d3b3cc0e1c083
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:9123168895c359c12a29b03dc58d237c7919adf3897f8d3f7fd40cdd6002d7d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:3c19b59cf66a01eed42404defb807532c162a067cf1680beff2a710d6c7c1043
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:37060043f3972d9c35deec304885b3cc58cc4e52aaa8c0a5621e355b482a693b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:a8e7c862dc2fe13ba897b6c4972ef5c7878e82e90f37a4585d110581b871e927