Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.47, 4.47-debian, 4.47-debian13, 4.47.0, 4.47.0-debian, 4.47.0-debian13

Index digest:

sha256:75efcbd54b3ab7fe9aef29297245d7d9da96ee49d51f1a8e445840a849b31a5f

Manifest digest:

sha256:69c6ac68fbff05bf67888083fdfb603ff076dad3ba759d5c9dbcdaf2915d2579

Size

177.58 MB

Last pushed

2 hours ago

Vulnerabilities

1
3
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:4e559da1a5c2f839758efaaffd62543cfb6d36df452cfb5def489e6586657760
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:3b30ac7814b1b75036d1d43bb27f0d3476254dda3db685150550915d1f8d8746
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:d0af2c6125320b8180085cb90e1a71b55a938c78e0ca6c74aa7093757f6f7eb2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:7a322ba942c90fcd2c6fd469de6db3437ab5ebbebdd88002cf484ca6f4d3c8bb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:7b594ff43fd3d8d381b6804a1ab6c864f8ebbe65d7a6969ed66a4cbec269e0e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:e809d3084898ec227c16f84db135872bd5a8a174c38590539459125906ea721a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:956ade5c0ec81f7fed213457b62a091d8000135ec166b976be97a225d25606fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:78ac23b488641c9d4e43b587552d4b81c41672566d4793cc3eb80e7720e96131
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:a209c21366b22eefb2289365eb8b0abe785d5d4918465d02fd2e8112ebe1c266
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:e5f7c721e1301561d307af23d6abb3c531ec0b17e878268ba517200c269d9642
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:e015dda5b15b77204cbd9749fae6a8d05cd73bba419fedf38b8263e7bf1ec01c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:ef212a8d4e6bdf0026389fe33e81a972d4f64b1681a6a7ff6191aceb82117ef6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:55c382d5397b10692744dc40b95b4d74e5551dd4e48be84ab152c0d33a34229f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:1e32fde0b1911f166666392ee230b78d0b05e59ec81a112763aae79137868db2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:5d9fd08ae7377ed11e74123d985161988cdacea0c6f2c7505526b382ad7320cd