Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.2, 4.2-debian, 4.2-debian13, 4.2.0, 4.2.0-debian, 4.2.0-debian13

Index digest:

sha256:a9fd5c29efa9d3fad3252200dd8f8fe66332ff0674c6eeb18368a666c4a382ac

Manifest digest:

sha256:207802dd1de6bc5c19ddc096b2c5351685e5e06b4bea4fe54b02071a25a56989

Size

473.08 MB

Last pushed

8 hours ago

Vulnerabilities

0
12
15
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:7ce69e89337d204232670e11cc014997ec2ee42f10d7207959c0e581df538656
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:7a05680436114811eeddf5eaf7d88608cc6f8f0cdb46bc860427b9b6571ccbe0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:2a8d60fb68f8a8cdc2ed4be0f9aa659cf53e9635b94715b1554d6ab605e7e598
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:07a4aeb29f6ae8e763e8f30609b73492c5614374fecf7e9892e298d2a35dd047
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:f093280c33b9a634793f4fc154f27c94b96fe8bbf428d9fd9c77825c58a42786
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:92426de01850d2586ed99264b39f27368db8da8465a865b08e11d8d683ab8923
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:521362e6bf8f40463da8aaa12a56ccc49596832aa6e3739c9aeadb185fff4880
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:3af3b3365a5a68ebc509c31213f01667caf2c464daaf96d431d9b56a353d97f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:dfb3f12dc3067fe150f80be245d67117ac7ecb3f50eb97572db2dba9a9692a36
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:23da8112033c20f2cc69137c545cb64608861ed10e800228f00cc9492782b204
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:fc9069727dc0ea96b540c823a056eb63027f46bee782c921b4db328dcd5475e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:a1e3fae322f75277212edc681852e1e480e406d4e41dd25fb903ad5da3b3242d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:64b9f82619fd2aa3554a95d6c33744bb26b0d593aa9e70b564362c85bb546916
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:de1af1d2f6725483f2354974a297183ae476e84a2f44fa4c0b618fb57062c59b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:940fb4ad4aa4133934a6486ed2a4ad54cf8cb22fc5592fb3fd6830aadb9fc6d8