Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:27a095eb3de80014b64f539968fac8a146b975e9190df41ce13b806a3f1ef64f

Manifest digest:

sha256:6e8814c8679e769384469044b94d395f55f826de95ae768b55994c07482d10f8

Size

498.66 MB

Last pushed

4 hours ago

Vulnerabilities

0
15
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:8814003f09be87a2ebd0f4b53394b295a9604cad10dc1bde6c8fc09dd253039b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:23e2a5978893229e80f1c14ec27e5e4cc3eff678027b0d7e0035ccca79a5f5e8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:fe7f741e7f2e4aa1db10b799a9d415b92f0446d1f901dc5ce425560071ac1bf2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:7effde103e4ae6545f7d285ab929a381d2219212384fa9864c94a9eb60ba9a60
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:7c7bd82f03310e82a7bb4ece19ed60f020a8473dc46ffb5be063a02dd3406618
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:6284723bbda9d72d03207ab12171898a575fc191b6159216d99255e786e999ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:399ae929b584e77f24d7c89396d1f3ecb1023a23e255d318c67b42c962381579
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:83eaf642b6a938c8c6472281c4dfbe511b8e04c223df254eccf20549a5ea748c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:99e93d850d524c834014be27551cf103a946f35e5b68d04ce1b18cd9df6889dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:3ebb90130c7e6053023f61c4dd07780a8fcda76c0a62dcd377dbcf8eb5484e9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:9b3b17beaaeb291e7cd8d991eb5bf19f921928582b76b28e7a70d61dc42d8172
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:f022b9fb4ec1514da7df1059aeed432bf7add94a3472e49db603f54400005c21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:1541ad3ad1939a3c20cabda8add83e3e43e3210d803bf43765a8fb074216df3f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:ed28331efcdf1b5eb08fedb5c772b598919ffe632897b995ab585142992b8394
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:4b7f2f1b42927cb824946761747269bc32991cfea23e5b7154072114e15dde2b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:f98a07a68646e9ee5270fc8693e47994d55b5105eed621305602e9054fc7db30
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:d149960e32f42cd1183d3e3fd06825499b2272f6b26f1725e406823a00b89edb