Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.95, 2.95-debian, 2.95-debian13, 2.95.12, 2.95.12-debian, 2.95.12-debian13

Index digest:

sha256:c3eea22ca31ab7840c85fadc82fe0417483e70a6c0de4508b75b2b18952d2052

Manifest digest:

sha256:28b811959e80df73280b4d24f4b1655476fee5ffcba1993cf284977bcb6fe009

Size

96.41 MB

Last pushed

1 day ago

Vulnerabilities

2
5
7
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:d9f2e9be4ccccf60c47cf4de9799f23ab01066fa45ddaf6510ddb6ed19dd42bf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:45919155948dbf0aeee2bcac004ede119792f8a46e65b1b45936fc2648bed6bb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:68ef3526c75af2b458ac27ec58158d1689867a507decf62ed066a617677c1a35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:1f810443d8f9fb77343442b87892ba2d172f72eff305bcb19440b497c5490bb3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:7471172cea6c00e986464aa0feec85e236d8e5c7413fa7bd71af2f35601799f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:09790690ac706b44ee34bdaaccf98e6c13dfd2008ed530488be06cf2d4fd5da0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:bcca6617903b1aa4f0aff5ddab310fb8fc6200a6a5202879c82ffbdcf4adb4b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:aaf82f065dadb14931b791a95d0c0e541e870d926fc1bf5e4fd4eaba629a1e17
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:ca228bd652c903e3117dac58c379fb3c6f9720af6d03e6377b4c9402954d9c63
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:cd14566b298c8f250f9f45085c7d5d423a0907bc3ab94a77e51d14606983ed78
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:fff59b24bd0d58741032d65e3c776e9235906d1593f2425f0dcdcc343429c512
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:c7a33a8311bdf77eac9cb23a410b53842e74c6b557616a6c7af830caa30a9f5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:6489962f34066076f0318e4aa84028157a35172d226d53d8927f175396eaeb45
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:271aea463509199d4284b73f91b67570f9ed285ce7698881f2921278fece07b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:ce12c7abba55bf91c22011e0979d3e29ee7e1cef814977c4d4c03e07bc43fdb4