Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:c7ce7a579e1a4c469b71a3b3c209995964451aa3434a50a01b474c9f321ec9d9

Manifest digest:

sha256:1da296d5bfcb4c8a88610f1df9a76453dbf6ace0b539e21a683ff758cb033e0e

Size

498.67 MB

Last pushed

23 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:245bf7ed06a5c6b47c12baed602e4e9ac6c4d2ac3c28595a654e43dfc7bfda7b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:a205109bf08706a657725b3d860a9a37e075f0ee031e23a33349a196f6da4f79
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:e12f90d8a022aaa2371d92246c985bcc60f8d4887f7f9c8dd116af93cd4dd327
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:9a6a72e21b7da2f00497a60b4f378420c23630a41a62a9d6319e729f4ec05b37
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:efcff6c933252b0523565a8beeaa909bb6c70a62269f644e608a426da7dd073d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:8bf29945edfa2984cbe1524bee526d02a3e8242e3b425da510146de8227ab00c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:d145f5b848a7c43ef27accb3c1bac542c7b83747b09e246bd1d3eb985c12ccab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:8414f259ea45fb91c02e1392f0525fa3d4b2bc119690a28cb2e5f6fbf0ce3fac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:acad25e325ba8b18bc530dddf40f5aa181b7f1aa18e51348f10bb8b32ac7e5dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:bd0bcbfd8fcfb55bceec20817a04125ebb3e605b306e3b6ed4441121919dba8e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:0b817f12dcb63db39c7d97a44486d35ae53df3317575fe51f5ff7864e9ebb08b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:040643e3cf0481ef4006324a739828f319b4a6a7791537ab62ab7fae604d8dc6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:4cf6f01a397ae3b0aa582ff9d4d747c0e79769441ea886c78d84342057d60c33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:86b9e07768d827ae2174c636728b1d1c170b8b888d36f38f40a60b097219526b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:29f7835bab8e8ee4d649336cd77378b80d18f9beea8cead602997b2afd62307b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:75e87c4ddec7189d2c9071e362b87ebadb994abdadcb93aa94639e6b0fbbdfe2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:43f5e3e6fd8d02df45b94aed6dc384bba41576991df628e0e34821e153213f11