Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.49-debian-fips, 4.49-debian13-fips, 4.49-fips, 4.49.0-debian-fips, 4.49.0-debian13-fips, 4.49.0-fips

Index digest:

sha256:61c3639cd250ef05499948461d791ec0842c86195853c6a3109746349da8bf9a

Manifest digest:

sha256:b8c6c071375868441854750d77b8d5e9cedf7b7d694a58c88bcf2073a9da86b4

Size

178.55 MB

Last pushed

10 hours ago

Vulnerabilities

1
3
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:fb2755a9f61b64484058df493fd3524b6b9931f69feb9543296beb1cfae9e641
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:3996f09aed55fe5dceb19d66d1cf608b19730f3121d35c83807b80b8b4e70c9c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:34f93d2c3d2a9baf2cae66c633fb8f08edb882bd70db1a09e04be66ff1d480aa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:3b11864a23207a904d1ff0eb21f6d8459094a2756cbbd603af508124d396b0f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:b7cc5243a94ff736f8eb369755a2b7152f70e505a12bf0a7942e10888eb16851
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:9c2466407b3ed4a730e9ae1e8fd03282fb0bec6c29c086d6f3e5420d758cdb60
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:cd276daa55527505e90a00404e1e163e88b4ba43823e95ed131f33626e75cf63
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:b735f1dfbe7d0d65c90eec3eb4dc8b4dddc10f2f895023568ecfd0ba64c33f42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:fd3dcd03cf198e2216356fd593fcb9feaa17760e4262b60137081a2907bf3171
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:27caa130829fb5cbd35c7e0b9bcd1c6d0acc743f3effa5dea2d7772357fda643
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:b48174159cdcfeefcf76a81f1cd4fb143c03c0dbdae73b315d34d26f0bcaacef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:bdd4d7125371f2c5c92c8404a39bdb6c9728006281db3c62dec1d4b6b21150ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:24c31ad8d3822b9d52f1bf43de9901746e239cc181a33ea414f319184634fd11
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:27ca0342fbd3f82aca1155b8b46e0f638d7030b7a8570c21ec95702d3afc53d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:eee2dae7739be8339866d7f99fa3c7d90310dc67c2c2590e5c33bb627f81cb01
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:6a4ffde976ab2f641a470fb867a3b6c5d41980911303392a83945eed564c2f80
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:6f2e3357802eebf64abe2500952a8a3de28616267c73619e7807bfc5a96c2dcf