Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:1d45ab68ee8054731c6e93d84225ea192d1080b4bdd1bc1fbd8ad8622ace7243

Manifest digest:

sha256:0a74edb91daf943a46b5d1144e7ed0e668b479e2aa0084aee746a9757dcdb73a

Size

499.32 MB

Last pushed

9 hours ago

Vulnerabilities

0
6
11
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:4039ab6786cb861a4d586c43858cd48655b5541fff4b064a2c4ebc4b44cbe1ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:0fa72d8e6544ada55f1c314cbb0c2bed2ebe99303fa9e53706c1822a3008e882
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:a791ee9cc9587bc76295668884e9cd10386d1949d6929ef9eb72f3c5daaacea0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:60b5f03409f8eee9b3d5ab06bbfaaed35fbee78a773035c742acd9cf33e15264
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:73f5c9303aeba4e867c840cd1e239f3bee709e335c5fcd415a8b0cc8ce8734ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:91565e1727250d240c9c4d478b36039a26e2b997ca06528bd89e94d8316d0b96
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:56d1f75b90d042932e8a34b71ded19a28d5519f41ff53f5f751413fd4467fe6c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:5be425d35731e5baafd569939c9e2eac8d74554dd489bf026faa64b31b6800b8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:4d92f1aa9f59113a826fc6fc2f970a46dbddf628b5233ff255893d3c177d2fe3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:8f4d0b19574a6efc17d60254325604eb7a38e3081f80898bc2ed99aa4c9000c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:73a6c202bece425bab08a8baf162c8a9e2c9b8314955ad704c15d7b4dcff8e52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:5f6906cd5b92f57c93ab81badcedbb8b6795ef404949b26d9c4ef20a18dc55c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:1060bf010105daf59fd0654e0a4d703c092bc615029112b962d5f87fcfad6ed7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:7ff174a1a39d812bd15c405c1c137c150ecb0005c6d52417c35a2945dc13906c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:007c272376f209dc58c828583281df04f886daf64f8aa5c580acab9e544370c6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:1acfef7a435e6ebf015492cd3ce54dad41e5a6fdd93dbca6affd38aabc3e16dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:48418d662a34185ab4e20393c3dc4937804f3c495c8815a41c059f41b94f384c