Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.50, 4.50-debian, 4.50-debian13, 4.50.0, 4.50.0-debian, 4.50.0-debian13

Index digest:

sha256:aef3f8851978c893c927b394816a8b5f0818e5c7f5087a376b67007767311c0b

Manifest digest:

sha256:33076c78009900b8cd6154319dc88f4e8ffd5d911bde0366af8e69b0b4656cb5

Size

178.55 MB

Last pushed

13 hours ago

Vulnerabilities

0
5
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:0bd596effba254a4274213bb5afa991ad3affb2586e11212fcb06c0029747f72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:37d5ac3185584dc519dcf5153743741dc3b657a95f605a1083535e4bb805a54b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:d5709dd167f8f06c0808dd7103aaa1ba2ec9d0950fa3114da56b115c03e470da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:df09b76df856756cb8dd0d6a05850c7b591bd0af56a558fa05277af467147c4b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:685b52ac54c206e91a8db6cedeb6a2643b145aa33d1e5f23827dc212c37438c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:123898a34633e200dbe9862c21428741daafec88c34d82eb6ba82fcdd23015f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:7a225afc0dbd38e73e2e56bbc5d7636ec5c20d1ad231d8f99fdf9eaabe38d8a6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:acada6edfcbb4803e3896ca1e3d77a490e94204fd27074c319643e03e4e2551f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:ee063648e8e872cd2b5ede3498d69ada83d7748b04cdc4eb3082906c799f80cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:0ab3406544da1655ff7479b19b691ee5788a3aa530139691268f31039b14dac2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:2854fe85b967f5a80a6932b61aa25402ff8fb958fea7121c8951c5484656b4f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:7896324f237a9917fcf755af7fccce641aaea3ac03e7e25845e626f4df4083aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:c549192f0419acded9c331e02dab26b6726d7298c1e1141e1da4831f1477d814
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:671f4f6557c2529ac5d7c63695398087b3c41c420e61338f965b52c27feff8b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:79656edb21c18b99e7d7070ddeb51fd71ce269bc496d2bb1e57b395b1ba26e1a