Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:a111a228dddc857b36a06a04ce471118eac6ce7e2ec74768593b45131eeb30c3

Manifest digest:

sha256:46727d8d09776f7868c132b0b28805518accf4ee76c8ca750243ce8147b89188

Size

498.67 MB

Last pushed

17 hours ago

Vulnerabilities

0
14
17
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:adf34d4a5745c3891b68c33a22d813f779b390559aa664a67569af46a41cec96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:739c59b2f658d1f44f640a5398e1539aa9030991aa9bfa3e46e372effd515268
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:1c1ab389b544ab2e94f5df4801ae5b76295e3a87acd5c3cd71e0bd48fd5a1d51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:8f8833d68579c41d46bb484e8e3ea48f9b89813d83063d4762961a448789990d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:2cc8086b0bca8c317ba4491659a96192cebe57b6a2f0f7e76f5acae36ce209d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:a3cc624d79b001fdb77fabb341a0e1379400b10a9ddcf569d24ce9568b4ded91
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:dca60ac337647f338a515cad3dafd29dc1065caca7f63cd700b75eacaa1c06ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:64edab02721b3666b63d6fc6c758de58144f101e79a0a2f65595a3955f7dee9c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:cf58cd4802c80ebcc3627327cf872ea1e4bed050fde877d48b0856955da1acf3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:195fc7cf9daad8823e15f83ec50201810372147f18e490aa0c64d80f426b5d55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:baa6c8fc96f6751f08740661d52c85ff1262b9f0989057682ef4f37998b287bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:2bf2f94ff0cb692bc8efc96656f35f11decb9a004686a1638e4226b07b9234d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:280825cce08ba0c31ab4f0f3db43a05f2b0b6e0b5ed3fed7019e441a7b871ca6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:c789f54801e2a7469dded9c252526318d4f36b1f98b5e8337d3bff7d94d8e23b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:d8d7870ffd92cbe7dcf18076bcd215fa730a18b0086dbb334ee57a8b8ac3ccbf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:257f80e65c9cf18a266eaa4ca7550a77158b5da58dd14a32a542fc942e059eb7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:bf0d44eb80ce435a184c2321d5ac54cadff58c0678e9216be2fe28864f3a59e7