Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.50-debian-fips-dev, 4.50-debian13-fips-dev, 4.50-fips-dev, 4.50.0-debian-fips-dev, 4.50.0-debian13-fips-dev, 4.50.0-fips-dev

Index digest:

sha256:b7bb3952f79ab4d6a46620311101c75a2d8baca8895dbcf87a22532517be71fc

Manifest digest:

sha256:3b3a9125a0e654e1ffd30cc06cbf7a935177deba4b598c5ecfca6ff2c13eccc0

Size

193.37 MB

Last pushed

1 day ago

Vulnerabilities

0
5
3
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:bc46b5f6478a76a3de4cf6556ae580c8fbf8da60d11bb7a083dc07258c02c8cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:458fceb714aa269aaa0e701ec20704ec487ebf73ab4da66830d272ed8aa4f97b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:fda6618d379aac9cdb82605273031ef9dc0a0f6ad60d23a5949879ec08d0f477
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:93e06f8dd1f79b1fcd5fbbd9a450ef3eb89c9a576351316b165bd3ac21f203d7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:ac3d0f6c43003f4843dc9df4548cbd7b923805d9e4fc8dc8157d502fd53f6481
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:d829e3e5d2ae9ef78854e53ccb9389df711e280b5b161c9dd968fee2bb401f18
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:fa30a14b59b34a05b2e90d13023cc6145e7e8bbd37aa82dbc44750af9bda414d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:4de086aea69fab2131d53f733b57f26d82fd50fec1060eae43210fc5046b86d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:d1634a8d5d17c4f86d6b9a0e46d6bb16c18f20466fc62d6efb4e01d86d183978
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:f8ec3dcc4bf56898c2452b3a8decdb9f6b904fe4fb3ba8b09be997e3ccf29dd8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:1e0b6dc60c3628e68d84b7d86401ad328a59fd1ff77c4ba318dcda2e70fa0fb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:f30a430d3f078da912e249cc5525dae943e8267ca12b5cb92b2d4277ef7c6202
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:aa8c7d97f8782afbfa25cdfff83e83a8914615d2b68f722227a3082525d98375
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:9d848112653ab04d913fb4df344798f5b6ff419ad241c2c4431ba6a6fdcebd74
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:c937d66ac8cb6d3d78b727e894cc0ca2de35841472a2bf93dffba570e663ffd0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:0c72cb4fdbab5522ee5d171557948426283d3ddcfcbf7c885efb31122bd3aecc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:b172b5115538079b1501491284756ec86c50ebfda763a5c6d38da09993e6fd4e