Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.0.x (Scala 2.13.x, Java 21.x, Python 3.13.x) (python, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-python-fips, 4.0-debian13-python-fips, 4.0-python-fips, 4.0.4-debian-python-fips, 4.0.4-debian13-python-fips, 4.0.4-python-fips

Index digest:

sha256:06feca946d3cde55074bbb8e82e63a45ce266119ba5fd23ebcde26f3cd0ae919

Manifest digest:

sha256:a49826c7da630dd13626899e2c37d71407af56dc9f6a1a31ba9fc4933876c86a

Size

478.40 MB

Last pushed

4 hours ago

Vulnerabilities

1
11
16
2
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4.0-debian-python-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4.0-debian-python-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:16c837440de1bdaec64dd9c8a86d6d622774f86df700fc0f456a7b821995c3e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:a73457b537d5f7d5276cad5639e4e0d47c0ff2e7e64dacda6f810a2f25e6a70d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:d082e80704b7a434eed0910a926aa1e8912926febfd2708036b25dcff892bbbb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:9df32a12d43bb48cb8290f04c0d311c841f26c1aa61f9213d409c1f4c9d59d98
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:1fc6fc8eaf3c1ed0d46604097ee4f1939e2e9dcf61316b0c5364992eeb1f82d2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:c374ab89b7725108c24baf4fbde931de8432a55427318d2d2260e5532ed36527
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:bfd9073f121592a50a38c88cd50c6a29edb10faacc1f8605fba6b6f80c6f7954
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:c177ab6dac327d7b04a726dffa9b4d7e2f4e692624f78e076ef7b8ca6c1a6dcc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:ddbc30c396be60bafe456ca880004b991b2037460105f0b7e5df3c03db9db15d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:30da4a2a38e1b55c29cfbcc5b7ecc88d3f5fd511902ff9622428590f2b368206
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:b8307cc47cbad01507dc5c61eb1cbf6f229825fa87f48c05632ab13dfb4653a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:54471ed58884296bfbcb14f8d3695400178850a7c16fee67267e6c4767cc7062
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:033f57a57e878d733196dfdf66948290b7db8db9ba8986c7f75430999c16b08a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:c166ce7362e2b8468c3578e47de16214580cea3720be9b6738a584190e3451ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:079796e0da6f0535566997e0d08e64bb43a547ab3d80b1dba6e65d2ad888a64e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:143b997705fa35b2716e3fb6899334abeb3c3e07680f0fe33bc618cf5c265e64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:4200d8b6130b74a1561c13334ec7ee4218ce24e2f992874bba8af6926484981c