Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:6cad92a3217cb54c8c6b75e1087376b19fc2ca207ece60a89c89308c4e9fd171

Manifest digest:

sha256:9425d5249c6c0b812c752d89d50173c4eeff6a16687efb87c65720da7eb954c0

Size

498.65 MB

Last pushed

5 hours ago

Vulnerabilities

0
10
17
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:dbc95c6c9110f1462147fd089b3897b8b3487f01c4a3f333fe8ca9f3e7b1c03a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:c706b9e0788c5755527700078f1abaeffba2e22df1984009f07c28cf2ca31707
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:7765c68437a686105defb5e227b207b3afbd0c6dbb4e618bc04ab6c4ab8ac1c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:1d340b9a5e8f45643b2eff1f38a06e250dfb0640d21700b68ac7df8c7df54df4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:6a12921e924454aeb9fb7a641e4e12a89324d8faba7307dbee948bfc1d32d832
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:c55ef8d929b50ba328086666f96a4839728717b7eeb60134623aa26f46c840bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:90bca6fb00ccdae48f0ee859e5a0d4ce2a9b4ae8ea4127ab8228af9c7778cffc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:922da9d72538579aee413b8e86c6bc94a0f48163a177c172b3f97a47ff3a4653
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:fc0b98679fab14f34746986d97af1abfe6c3ccf7a3bffd3c567bd2f3994c2884
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:d753d30321a26661089ea9071b87899c7ee83b6f77ade5486848c12a54f0155d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:a2c7bafff7a63b06491d1b6a3cc385d6f7385f7a59fbe66e4f658baccb9f271a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:f18927874342bc906d5f750c05297e96452dc5c46ea385d53776821d3737e302
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:1c6dcd73228baf666001ea757a97ab56dd431f472796c1b85f1e9f3fa73e778e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:c03cdc338adf43d26b610690929ec0200cf2cb94adee361d34386f898698ccad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:d2607e3fffb795121ebbc2cf50aed9a9cb1ee5d3875aeeec279ae8d18cf566fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:71fff4e78ae9263b8a2dea25ed17705d1813d4b92a9547be2ea7b20733b8fbb0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:b1fa7948fb3f607e9f21164de8f19ea00c2ed53f08ff16233c13d873c2083374