Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.225, 3.225-debian, 3.225-debian13, 3.225.11, 3.225.11-debian, 3.225.11-debian13

Index digest:

sha256:470a3924b15b8da7c355b8365e31ffa8b793dedf64f5d9576bc11aa7cc00b5a1

Manifest digest:

sha256:b33be2ca3b891d2424cc71407b63a9d4daa7bed624a774123528bdb5465707eb

Size

135.39 MB

Last pushed

11 hours ago

Vulnerabilities

3
5
7
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:94e55bda7e66eaf056a427c941e8ec7b5c8fde324144048396657eff25b74af0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:0f9bd60b30a5073f57a41a757f5ab242e8a450812de1b6584d15a249fc6f7c1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:815ef52821b4d29dbab7c89467ada725095036f16c5c37905184904a2c928994
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:53b2699154970080e54ab03697d499e2ad1fe4f965e7e16ca733afb9e763808b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:54cbed0eb8a3f3c356ff04fa4f59b65b580c3708d03bfe1d1e5207ddb0466c19
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:af984e41b0149d77a4d7e7a803e3d8b184091883d1aa68758d236561bd266fa9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:c624cee43445452bb19b9d6e622640b0ac2937963ea5c36ca64352a8401c5840
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:6469e1db7ece033f8029186894ba65e76595865cf74123c0d8035bebbb44a8e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:093404b667fd34207a6929a9e28027085cbbb762f4c5ddd269b0ede11ad16d34
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:c88dc7b5cf88bc69921c521c67f1fb24ca3403b7568f01d1a4d8c7b3a6b800cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:517dd1608b8d7b4d3a13f7e820032dfca1bc2f7a240534b0bbee9c56416751eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:6b9e1ff91b12ec3f2edfcb643350bba4c78917e7bbd2fde25dcc05686be2b9c5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:0e7c655a01e1e81ca848d1dd06dcad6f851d81ad1ba6bed2f173fc1d95e2ba03
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:0336433aa15f7ec15854fd077fbb26fadfc65a814a0a17e44640283329dc4d5f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:a0e8e0fec353bf3926e6a47f0140205972e4b6ac79d71c21869fd927156ed38c