Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x)

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.2, 4.2-debian, 4.2-debian13, 4.2.0, 4.2.0-debian, 4.2.0-debian13

Index digest:

sha256:c34065bf5780f1e9834cdb2eeda11330937effba2abe0a36967c1c73db576250

Manifest digest:

sha256:dd47b29adc5f62cc2e6b0cd0099c25d2d0b1905d75d97f5397ad2ebde0450684

Size

473.08 MB

Last pushed

2 days ago

Vulnerabilities

0
12
15
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:8972bb4ccbada9cd03257950fd8d4352962d5fd248759731e0153021002aebe4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:ce175c7ef1ddaddec3b4633cede0c74317a97cce2d6f7b977d7e4eccf39fe41c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:77613d03b896ef28919cbd60087520548d307179484abe2c72bb2e407096d792
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:220fe1f9a78469c913670086aea169cca305039ebf681bb5e1fae167165461e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:a73637bee1271037132474e414430a49bebf7efc4f5b422cb702e4c39613e832
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:3c6947c7960501438fdc41d311e95bffdba4f8550c0031fae40934c7fc546439
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:c4205b3c73376fa61e05ceee95250f01891c51bbdb6b84c954eedfa166a543d4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:8899e18d1859771b83ff3527fdde84985798af3819adc4bfca260e066670c997
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:0e509b73dad7692f734d8f96a5c91a74fe98df2ef2543a68c5bf202db377da30
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:a20dc6b7789763d5a95c4d9e380617d81df9b9d32310bb507f853503fd8ca714
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:07a41a60b965033b5bd7b1579f0afe2bcd46defa2cc4428b1b349d09e09fdef5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:cc5b617b1ef3a2e4123bad7d28cfe0d60cff1e958f7614d578f00ebe856621d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:ff134095693fe461637a5f1b20d34c1696e28ede3cb22d99a007297c536b2a4c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:21253fe0b4730d87092ea4e8aea0b4f5933742924040a7106d263404eefa671e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:04df6be29a02ac7bcffc840d5289fda8e5466815a193892430f2298afa5f6e12