Sign inSign up
Langfuse Worker

dhi.io/langfuse-worker

Langfuse Worker 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.225, 3.225-debian, 3.225-debian13, 3.225.11, 3.225.11-debian, 3.225.11-debian13

Index digest:

sha256:6a98de148ebb071cf87f587f484baaf46a31fd5df4932d5fbea51d393bd975b3

Manifest digest:

sha256:bdfec0b94884649bec9a6a16dd5d030ef898c09612425aa5704d622ee55b491a

Size

196.32 MB

Last pushed

5 days ago

Vulnerabilities

4
23
25
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse-worker:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse-worker:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse-worker@sha256:dbd8a79fb3ef3a68fca4cf9f877227b2921be9e4172f9aa6b5deb248ef6e36a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse-worker@sha256:2626cfc7083940e54c57af613da7a17d42898fd71d06badce6d76f8586e75f30
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse-worker@sha256:34fbfe3b5464610ba34e161873c5150ab26fa2406f47d623b33b32741953e4d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse-worker@sha256:249c3d823775c289ec6be120428ab1ecc6b0120e4024349a0ea4e80add040ce0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse-worker@sha256:01412f8a8b562b68ebef9891f400fca5f771762f3f783caf4cda54a03c23880e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse-worker@sha256:d6ee6b9d5778e0b9ced038964e229a95abcd031159ad779eb631765f43f34d1d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse-worker@sha256:9aa2ada76542a5abbb66ec52735edce4f580dbcc6fe170bae30f17408882ba8b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse-worker@sha256:d66bab8435bfd4d09c06f3082d3908047b9c2c31baef694de8a87376275a4bee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse-worker@sha256:18a0c0c26193ff5b2d51af77816f7f2fe738454194e561bfc8c429b6b1dfe260
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse-worker@sha256:f3cd531ad15260d743ca6dbaf88213482c3a829dfc25bd2391a4b6a3f34b9fd3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse-worker@sha256:23b97cea7887813e988dd2817906e9434f15c848d852f9df5d9e2d36329714f7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse-worker@sha256:2000f06c58662eaa9a08b5c1152954797ead9f90b9b385584d4aa9987e18ad76
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse-worker@sha256:e69bbc073ef2a23533dd160e36f70bb842d0001225d03b08ad05777ddad62b0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse-worker@sha256:2b821a0daecf41e3d8875f9baa27129a5f87ec966165809a316af56f74d73c18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse-worker@sha256:050c8077a9a631a6cfc6f485bc54d1535adb830f98f6dd5a422c1514ffd87b36