Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.2, 4.2-debian, 4.2-debian13, 4.2.0, 4.2.0-debian, 4.2.0-debian13

Index digest:

sha256:04c21c7bc6399532c225bae1d76a21624c94164d1d70552e7ad16209e50548c5

Manifest digest:

sha256:ade3f6247c2ef099e7668aeeecbae61a625d49d83cf77e5c986a2ecdbdcc912a

Size

473.08 MB

Last pushed

9 hours ago

Vulnerabilities

0
13
15
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:1d6c8bf6a4b4bde186bbf348cd7fb81111f1c020333ba16ab919b1b7223939c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:b05b530f47b3ebfb0ca8f205608f2588a9b1773ad5589d26f03b13ce6db8a55a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:9d2fd9911c903bccf123100a6c59fc9c4cb3e98ff1fe48308b3ee42dc15a9de2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:0aceae981745a6a58ab90273d07e518a1a48f041e9d21d31b12fc9d90b358b8d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:43fc07ac7daa57aebca891bd111ee9453b202ad5c17dad57e1514c2f46a3e4dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:71a2d36c18a29687e5d81519e69be7d43f01adfbd302ba74da8042502394cbc8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:76ffb4bdd61a54787b80263729acd8280719fb0e7e9ef97fbfe6a156ca804941
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:3ae06eae2e4860170a335951cbaed6f2a3604a151bee91244ef74229bcc69dcf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:48b81ebda8a66158a3bd56955fe6cf93d36c348824576817c346836679147153
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:849350b3978bf4f0c71dbf6ad7340f3dddf883c6ddf041677954681400b91c84
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:562f2d09c659717d5b94c72eeea13f6482b2882cfe7041701366ed0fdf42fb3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:4b5f361579da115a386e48efa64f9593a7b10792fc8193fe257484350c33104f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:0f5f0b6cecfbdfe226f3e6377c3f8d7c5e2ba2d394fbdd0e5061d0cac83efb9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:90855077d3cb90aca5e494498da9f5f99316a0f012bd45657f2cc53d43281141
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:620b7cd799e34147bdaa667ac13be51cd992ef770b1a9bb9b476aee69d213bc1