Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.95-debian-fips-dev, 2.95-debian13-fips-dev, 2.95-fips-dev, 2.95.12-debian-fips-dev, 2.95.12-debian13-fips-dev, 2.95.12-fips-dev

Index digest:

sha256:f4092da7ef2fbcadbbae6dd9f11e4bdb097b6d7845bbfdf870577914b3c61fa3

Manifest digest:

sha256:f336776c16198484fd0be6624e2d95b9d8a9486b2d9570f3c338bb9437b52982

Size

111.21 MB

Last pushed

15 hours ago

Vulnerabilities

3
15
18
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:9c755e7a1a6690aaa805bfd3e732a2fb831e3b9156232fdfa962a40ffd91cb20
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:69017c3892596ff78bb57252ba1a57a61fbbe50e94db7fc0960250028640cf0b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:14e685414285ac21afbd70e4a4c9ccf9788129f1f7cb007c06c1e14f43b642d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:12e196ec4b069e03a4405c64be098f972af6083320b70db78e0f8d5fbfa0c456
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:e71418896a50b8fc533457d610bc526d1103bdbe4964f088490353c797384292
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:41f91536ffd9de1b5d99a6fa79f739001291ad8613c7ca99e305d214549e124d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:dc7dc004b598f9e966125f0195af459d490ba97a56c4b3cc33a64ca313175677
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:fe559de460bb63d22037c9687b46792174885cacdd61d311805cce47a3cd6eae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:bbf8a45969bb8c084191ed8419928d6e57fb18377fbc50cdcd7d96b42754ebc1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:fd3d7c31767764c98412d3ddb1e8d1839e5116f2c73150a0f7b43f88f4bb429f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:4df0ad5ee2a6f55881236bdfa9615bf93745fcc9cce1b693cfa943f5d34f73fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:cb0ce68d6b7d602986710c13ddb01347605a8d96816ea40e9e1faad361667086
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:c23689bac67986b72373a39510a0f10c3b0f5c423bb87098143c35151cfc3d16
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:5638a8ff216240d6b1cce1e15a8a2aaec0790937de929a5b591e14af4346d06b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:ebf062dd55bd2f6b38a165ac773315371bfdd562b4160cee0d242b1bb72c8a7d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:237b4807c7cf194de4608a59af5f5fd8e0b023fd9504a55365457e3d7d4e16b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:9ea1b8d2306c4b582dfed4673c707f1f3d4a21bb2eab33602c4b35f54faad99d