Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.225-debian-fips-dev, 3.225-debian13-fips-dev, 3.225-fips-dev, 3.225.9-debian-fips-dev, 3.225.9-debian13-fips-dev, 3.225.9-fips-dev

Index digest:

sha256:1c26146751cb78387a63aea6a30a7cab2429ca3116ee21abd1ce81f622344991

Manifest digest:

sha256:086e8ccccfbd78481b181d66631f0ac789880c1bcaa48a23b5c08cafd4a8ba92

Size

150.04 MB

Last pushed

5 hours ago

Vulnerabilities

2
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:0a5d56f16ebd4d98916fbff33237ac56cee99169e09a3574928830c5c48484f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:bfe7301b6daf09ad0e5e6736139a90fb6c7571275f5885ec48b9228f6d1b4acc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:1ee7b03d118765c935579e892f7f36c84ce1e666227760736ba3da3a343a9e8e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:e02e84407f594ae75ba8b9ff2c5ec02818f9c29d90457ba103e701c5977e077d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:e656411cda6f28ca5e1c31e505127b3e52fbc6b22b6472bf8fccb9e3a15d96fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:7b8a333f3844c0c9931cbac9f61e62ee9087142d339e272309fae3448d8c6f3d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:e75cca8b07c041a73e1bba1256be31f34aebd5c022a48b5a61c9c5cb7f2adfcc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:fff44ce22dcfeaf7f0bfd8ba5c4bd2795d72f253b56721929aab4a037b0bfefe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:aeeaa64fc7f31fb74a24930a9367b99da6bc3824a91da382c246ae060fbaed42
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:5c00eacea9758e7c6bd01c0a874c5cf5d674c759fefdc6304ef5c669d4adc1d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:b35baa969b14a1c84f6136c54a4b634e9443fc7f08528eb2b5db422c5b6da1cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:2ae99a9acc1d2b855e9995b8327326c0ecd92413892f333745eb53dc40f3bc12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:5dd89ff4255f6fc707500011b681c3a8268a253696c6ac4ed9ae22b1499cd3a2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:dc3b53c1c5ab10642ec1159cec6d63f856a5816ed8e43b6d0c754d6bb46da1c1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:638428b0d81657c1f3f4f46b2b0026d38ee02a1a2671ee824cf46a27e9f85a69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:9880fc859b26ebad531951e09f8f7562a34f7d814850df37cbc98f6ccba0d92b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:7d145f4291ae3e92f93899385199a37220dba837c20dc3d223f2cc19eba7342d