Sign inSign up
Apache Spark

dhi.io/spark

Spark 4.2.x (Scala 2.13.x, Java 21.x) (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.2-debian-fips, 4.2-debian13-fips, 4.2-fips, 4.2.0-debian-fips, 4.2.0-debian13-fips, 4.2.0-fips

Index digest:

sha256:e3d8e2752e9157febfbd9c9cab94e296ed73d793a2cb31770734ce5ed70f8e36

Manifest digest:

sha256:e74694ce07127168a2e7e7eca92add613ca5495524897de65cebd9252fcd9daf

Size

483.52 MB

Last pushed

7 hours ago

Vulnerabilities

1
9
10
0
0

Support

Active until Jan 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spark:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spark:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spark@sha256:7e6ad6464e84f80b51b8f03e4c0c0fd36878de4b214d948de716fc773489d974
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spark@sha256:3cce0f84de01699093e130897b350a977fbf8ea816fffd2342088495b7c93249
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spark@sha256:ceb8aa6a3948a7ddccaa18252b3fc7ad0d5ed37ab7247a9b94201021dd90eab7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spark@sha256:2714b2360ad16fc9e68d6cef920f8d46dace57651309d7e2becfc1ea1b194c98
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spark@sha256:b7708c2b2c868a2dd9890be6436dcf307ef9f4e16d8c151a3d0c9532e832cbd6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spark@sha256:89bda7782ef224ef9ec6cfd5f623ccdd66c2172c93b76a68fe0aa6c7ff4857d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spark@sha256:0cc6a0f607749715fc2415824fa03874561959730216b6ed7adce99bce35d632
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spark@sha256:0e0f118f031c1d84222ff10850395a5f5ee64c3030cbc2f06c5cab74f28a3cbd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spark@sha256:ea3ff9ea55bddae245180dfa339aa30640382926254f4436dfdc8255d01b5cc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spark@sha256:33bcf4e94915de506f86b4df85f89cf61f7e668da1a30fdfd2ce4ac7e6c6a374
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spark@sha256:15f516f011437cbf401d4ca92076891a825019b8be05f96a5e54210c9b52a0b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spark@sha256:2cdc23d7cce80bfbe024e8c8aa064801230e130c568ebe1f41f1830774b0b480
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spark@sha256:f005cbfb87cc622d519bb91744339232d0091a69a8ed3ac100688c98d46d5d67
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spark@sha256:8243632c97d2b4a64c10c9f9a1e596fc5b860a2a8ffbf62627474e15bdf5a443
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spark@sha256:c8a3aee589bb601184ceee92891b11edc808d3c7190eba48ac13425c7d40cd07
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spark@sha256:cffd7f0d98d40896de876d86aed43d0e45cbffdad76ab4ac771c5a6e60d615a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spark@sha256:467e2bd8445eb8f23f2bc104fcf37060a0daa7db77e06b68957c1352fb5dd0f9