Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.16-debian-fips, 4.16-debian13-fips, 4.16-fips, 4.16.0-debian-fips, 4.16.0-debian13-fips, 4.16.0-fips

Index digest:

sha256:5511b2e80f5034008ec74c3d0669ddd7820b3ca38715e354570c41997a25eb63

Manifest digest:

sha256:ea78e4dc4bcf3620fc4e1a142baed4d409ed3d74dbf8d719f569818319b876f3

Size

169.26 MB

Last pushed

10 hours ago

Vulnerabilities

2
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:3120288f9c1a14c127ac76ca86cae426beaf701e243ced77f24af51a9666c823
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:62fbab4b498e26a18dc0f83556603ec7d8ecd4535d8ef6b3224f07acd810f549
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:b954008e95837c5750e3fa8e10ab90fb177ba1fa494f1f7c74b564dd4c3d34df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:9619a162453c344590beaf827ff14e5ee2c97e13d0d5dccdfe8416d983e74365
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:30ba54c64c5d4e4c101dc6280eeab4753dad028aaddbcb33be5c9ab18269b3b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:aa04e8442387b57c3a6583cc520f2be5849b44af587e7f9baa0bf6ba988bef9b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:1c03bea516192342854b8b1725ceed7f37751750a20b327007b7daf0c3edfa08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:056f9d7e439a42087052fdeed8ca9a522cd042560a06edcd23d9cb9f1f07a6d3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:e7b09abbe987f570534b0c1c01f1786d8b6c303b72e9f47ccf39d68bab78db96
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:4c26d6f4b02662928d5cd1f33d9750a484c849315a95cf1162f686b99816b0ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:88e2abeb62ead827b741b1882e7334d7ee959659d5aac82a20783e6c135f9433
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:70ff19a5b265d86dadb75d3ec30c3718872384eab1efe1472862e25ac88c4cb7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:47a3fccb7d4a237af33999d2ab1fd13b9fafe0c5199e6d81ea01adafdf3649e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:226a806828d7d015e4177c83c0f441bfe429b63b63d6168f86cf3513f99749e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:e3155b7e943d35109492787184779920d240182568c411c68511d847aaf4e8ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:f0be2dc006c96f400c477fb05de3d14d9ec13bb0b14d7bbb51a32b34a78622c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:2c2bd3d1da56602f6709c4d2d7e68059c3cfa47f1b7ac591df499ed2c3e6f955