Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-python-fips, 4-debian13-python-fips, 4-python-fips, 4.2-debian-python-fips, 4.2-debian13-python-fips, 4.2-python-fips, 4.2.0-debian-python-fips, 4.2.0-debian13-python-fips, 4.2.0-python-fips

Index digest:

sha256:631889253988d986e5593629c84cab81590ebd897ee6e0c74211e2da16c9d062

Manifest digest:

sha256:aab2bd6474fd8d57959bb35d015d48e981753e0b4848adee7d9d5fa1e144a057

Size

498.67 MB

Last pushed

14 hours ago

Vulnerabilities

0
16
20
1
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:366f876067c836ea396ab624cccf03fa7bb8a760d8a21485d16773c5bb0295dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:bd97a3bb130981a16cabaaa635502648b7e5a8978c3291c92d7b1b5a95f974cd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:b2aabf765b00bd202478519afbe84bbfe361118abfa642db6ee58e42d88e6131
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:c5d3b149a6fed2831dc6e494632c89a812c29c4928b32de9ce1003e72bfb4d40
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:83cfed755f04402cd7bf31779543b157fa8f93fcad463743bfb65b3feae6feca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:a9aef414617e7755fbaf3db7f77e4ffb468041fcd4bbfd02315725d3c018c369
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:db4d241685a3f1b46486104062afe832b161b9266b48f4d29a9ba90b5102f004
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:2d54582cb78d1c943602e42e199faeb5778384782b4b9d10eabfc8d21d712980
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:7cd7edd32828b0e541951d319a0da90e6899f35b912b9bbce9d3c71b1b0139d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:5b67f2338ea87261a8ebf8fd978e1043fedbb8ff72ffa2147a6a37481fc01022
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:1bd0b3ed4b100fc479288d31a2178bec8816732c25bf398c9c821a26436a898f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:70d7dace5e21621da037571bdbb2abcace3b600db41424fb08facb750e80b828
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:dc91187ce249e21ab5e0205406e82923cebe7201f17b634fe62bcea1a5f1063e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:5894c5049b4bb823eac879a4bae4e961f847b1c394549375c4dc209587710bbe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:d5ec965b5c50b1e5f6e68df6bb75b0ff622680c7b4e0ebcebe337d19481fae34
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:fcecd233385ae09c8c6c734cef79c667660e72cc007cdb760cca625ec4388e75
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:a9110f364c6c33abb9d42feb60fe6064db9b14bf00b55e525cd30c40d49d3b13