Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.225-debian-fips-dev, 3.225-debian13-fips-dev, 3.225-fips-dev, 3.225.11-debian-fips-dev, 3.225.11-debian13-fips-dev, 3.225.11-fips-dev

Index digest:

sha256:38ac7fee61c079feafdbee521a64a87dbb533b06c0d1813ae44c4117636f8875

Manifest digest:

sha256:e857e2d7c4ce1e82dbb1abf3af33f725d60d59a4653e1ab6e246eb2591a84d93

Size

150.04 MB

Last pushed

8 hours ago

Vulnerabilities

2
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:b8e679016ea5c0318c004577d26a87c3393aefa86065cd471a6e5c93888faf27
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:75e094cba74fc04bff6975f4b4e7ce635f48d2d6a412ed3456a7fb1a780bc34e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:d95b0c45b38411ad306088f43600e2364eb4f50ca57f5908d663af11ecc72bec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:725dc86071a7802398607ba0686ebfbbfee1892130e3684e266a0f2fb072a406
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:5b30b06934d0223ccd60f6ae2faa1157074693a4698b536b3ea6e57a692c0099
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:4386c3025198aa30d2c1451dc7fbd3c4c0d9f43e2b4b94e2c9674a505b94f611
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:d7a0f5cc2dbd48c5a5b62fd9c3a92161eb4927b78c5f8a752d290ab12b93097f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:a77505fb45c08585afa23992cd253a1cfd5f940416f0106a4a3cb0e74e522ab7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:f48416063cf45be171c1326ce636d1a835f1af0addf9886043a34cae64ba185a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:e68e459c0121c1a760ca08ae393396e6f3221139ac57c67ee9362c32c8a88e97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:a1fc6742f417252faa77997218c230f499b7a10248d0706a45cb13bd5f020d6b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:fc679348a8d9367b10b4e8264128eabccacbd054af79de29ad4f92c9bcd2cd2d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:d1153b4cb659dd9d1e2c3b501c788135009be28b7a21311cd02e3f2d5c16edf1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:de8f103f7cc4611a5c063da2b0544751cb715ec7976bc54bdc0ac4d1db374c69
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:a824f7659c475d2471711f1f77e4acddc8c1637012acd18bc9f2b1e4748ab4cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:254207a3e2366a6ddf50b6050ed30dcad322983b89993ebcc90bc93a646c4056
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:58e7a2e16a263667adeb10b71486afdb838928757452c9fa2b8dd53850877d49