Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.95, 2.95-debian, 2.95-debian13, 2.95.12, 2.95.12-debian, 2.95.12-debian13

Index digest:

sha256:d41daf9b72ee569f59633250efc7c4c10c321c60298914ecebe0b70976606c32

Manifest digest:

sha256:019056f9f6e681c7d324e14623e87d6969f3fca27a6ac1784e6fbbe99f7934a8

Size

96.42 MB

Last pushed

2 days ago

Vulnerabilities

3
15
18
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:a537ac4a0dbc75131810207f1161cc5fe3e80fdd269d6dc8d33c851a5495acc4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:f0c1cde5c708ca4e27689dd81bbd786410d973903e8dc8d89cc5f134af03cfb0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:82fad74270a96ca83c8fe39b6be0a88f1045f53fd0f3d45965d2f37b53de8721
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:8ee24ecda6b5e942388c931ba880db55d9c10025c89ec090c325f450e377b116
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:ea18c0ec1f4fc771a5a14a20eaf0423c906326a4a0c53f3ebf5089d3056fc327
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:2bf3f05470bf16fe502ad55f5c0ba50b540723dc66de5a11dd9064519507a73c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:c911b01274a6d00642b27a10b94051b4721170f0b6a0bacfca01dd80e22f2cde
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:a7e1efda2959d864e77cd57af571e35c52cae5f485d5b90fa8c1bdeab2b7460b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:34f4a78d4704f7c885906e85b934a9e696b138c6270ad79a6d45aae87678862a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:7a3af9c00fcf56322bd976124cc5634216e7a4b0acb43ee02f89ce1e7894576f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:f7aa5e4f6123c004291f143d1972c480478188a4c13a276c467194e812cb2263
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:c95736c9fc991d2e7a275771805019716d24677474b855e3f0fa51e5380a3c93
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:9fb9a29e45876fe0ae14fda4fc4b80a430b4b056a149732e3e2203bd6b1d3727
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:ee5369f0bd3ebc9b6c564effad864eb544f69843bd09a71259f890e26b1cda28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:7541205cac075fc581dc2083be7dd6872a615087d76a46c390a12d728c25ba8a