Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.41-debian-fips-dev, 4.41-debian13-fips-dev, 4.41-fips-dev, 4.41.0-debian-fips-dev, 4.41.0-debian13-fips-dev, 4.41.0-fips-dev

Index digest:

sha256:6ae4a0e8bc13ee08a48de9411aec500fc91b533228d4154a429f900ceaeb91cf

Manifest digest:

sha256:c7f842f6236beba866d5ac0840d6d0db4286a7cc5235b4a16ac3f4a873914ba0

Size

191.78 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:2e24352e6fcc3ea54be222d4d8706b7ce449a144b66600cb3e9afaa6e3487154
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:79fa1a4ce71e2c9ef002ceaedf04d8c36ad499d56111a69f7af1890db5dadb98
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:65dc429cba04d0d2ab37751b207b72a61959061f613dfb72d78787c2a686b86f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:27b119b58f47277d015f949f2e0fa10dffb511c9f0f87c7d683487aeeb501ea4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:102ad2e2861cb2d20cbac8708e50442bb73e537d4e8893b531368ab2301129ab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:5790ce5e445ea5dd560492a9255888edc7f95ecf83a25e49a06e200aaf38a869
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:511cd5c39f3cc429fd635eb2cce1d631adcf0f3d3d82f2bd334cbce0d107d1bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:f23f3e0330c8e90131b2f765cb4a96ca51da8ace9e4cded569eb337298fdadc7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:3631f2a8690276a3d30bf0238da1e538a5dbf09eccf9abadd129b70bc933f24d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:15bb699166ff4fb094718a3daa12e4e2f49b46245ebc4b262f6e76817141b778
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:564e514bf00d4b0ca21c38dc058b50dab41d57be8ddd2b0a89f7333c0846a353
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:e15171729fc39e50fbfe6ba637a1c485e655aee58deb3b2389ce62d964e678c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:d4a9b48395db7d177cc2ff4c355d81d1e6179831fe49ca7dae72fee0c6ffaaef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:49b149549d013280193d3df1b1d33bce81ddcaa3f8008014f352839f3968c645
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:7449740f7f909e56393e8df2c45f3f5aed754c7aa1e6f2f711fdfd65cbbbfbc5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:f49949491f42443df4a35c1502700acfcc287a5f7cadb0741b8029aa383aae3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:39477ccef7ef6fba2662d258fb0853e79521ed5a0324714b6ac0696b72d1c5f7