Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.95-debian-fips-dev, 2.95-debian13-fips-dev, 2.95-fips-dev, 2.95.12-debian-fips-dev, 2.95.12-debian13-fips-dev, 2.95.12-fips-dev

Index digest:

sha256:a074f2f6f2836509b7650b822c1624dd50e83c3d0762eb19080b6e80e16643af

Manifest digest:

sha256:6c44d5547eb66f9269d37a50fca57e1d2527403c7ea6fdefdf7b6eb41be5bbc7

Size

111.23 MB

Last pushed

18 hours ago

Vulnerabilities

2
7
15
11
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:028ed835a86b238c6f0c2afb34dc712d57cd3f5e5489c785e784117864f3505c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:0c94bf4923d72d93efd3da1f8264dfd5dc0d74b6fc61eba1861c8d05e9863847
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:bc557992d7552aab0f5dffaf81fd2bb457b7dbe0c4554ce33f66ca1b9fbaa534
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:f8ff100e728b7109d7f77d55cc1ab7deac6b55c1ac709c473ef31844aecc5f2e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:04c87199a16330e989e9350f026b58ad8dd0cf271a628684831ce3ce48f10624
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:d08b5170a45acf88fb779d9972f913bd7d6b4d363b44cc7f881f89cd773a9252
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:51906512b6018acf3d8fd1bc7237a105b4dcbbb6e44c84fb82221b6eba3d26f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:d7612859169d1cfb6115df823cb2218c3bb542edf664a1926ec88fb8ce03badf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:0f764f2061b914a93aa60eced376191e2bfb995070d97dead4be353a65175643
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:4c8c70467105d1a01a3a00d69626bef8e4166433be23b80d460e711f19ba90f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:c59ff6f76c075de7fc78459f358432f2a3333d3296a4568177c39e8c9a4352e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:304fa414d19d81b8f9315b3bc964bc2d0140c6f7a984532d1583ef5fdd84b1eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:f5438d56c760293fa28bb1ddcc606822e1ddc782d9db2302b65b9588f9f44d38
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:9b2996287222ed7983944b52dd24348ab7860d211bca96d037e70b176409e732
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:397dcfc4aba02f902c9636a6846f9b5c24c4bddd0e3cb94c69ed0174d308e293
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:8f2bccf2ce50af179699ab155b3115c8cbfef544fe0e54f57c1a65593536cddb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:bc960b5112c8b95192309bf9a207bcda363df8eb2c31f46216430c12d083e9bb