Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.50-debian-fips-dev, 4.50-debian13-fips-dev, 4.50-fips-dev, 4.50.0-debian-fips-dev, 4.50.0-debian13-fips-dev, 4.50.0-fips-dev

Index digest:

sha256:c51be20bfa391ae8df539f199c53b404656c3c0cd416bc8e54ab83428313dd55

Manifest digest:

sha256:53db5673decba7afe5ccbf7cfe8b83ee8fa33247b1de40c492879dcb11934916

Size

193.37 MB

Last pushed

11 hours ago

Vulnerabilities

0
5
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:a824956a153a9bac5f32199ad170121b9c1bfe76d4eb3169c2d574ae8d0c1979
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:36bdd26441c8054b04c507f34d4cd6b8e0fbfe03c55f6f0d6627cd83f2dc8225
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse@sha256:e957c77d95d14ac7ecfa6db7bbcba06599b33fcf8c05a3b144a6385db107b9fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:f072febc98ff6f878fc00ff2b98e81424f3a64bd72b120ab18fd471cffacab7f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse@sha256:7944412dfc7ee80e071dc63efb0368e0e8568cafb0b0ad5f77a0d29b8a9d5ec5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:17345757c35a824ba88ad5d9fcb8b3e533f2500d746aedb3fb6ad789adb8beaa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:4aa85280397a51753e8ae3201b15a085a872d50fb3e7d76aeed56ae6c916213a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:0ea3949759d41725bebae5e0703eac6865471f551556011a66dae561e42cb555
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:e46219a449e4132f461bc85c2515494bdb5f39bf58ab88dea592fc0c959640dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:de85d4d1391d5769f1c7807c2e14aa0bf1fda16c0d1120be6ff806c7e7b356c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:6599f14db4bffe690915afeef285385f9128e748947f7eecb565b135617016fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:e26a0b1d0253f43efe28a658aca4b246459d2b2372702aa6f4212f6b2b30e80e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:81fb9946d8f406f6fd1fcf1ddea4406e2fdbaf8168a8f3c460e9f720ffc94562
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:4afc573403a5d41f566278d731ca02be67eb4fa4703c5632ca12bce8e525caff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:d84c14224e4f62df722aac168b90aa0b8da7c2a332744766a26df97b6fd97bf0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:5f7da308480b7bb23584eeeaa562cbb9924cc858c537b4baf4f652f6c0bf2290
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:514d4311a4b3dbb12194c852bde93dacdb0a4619519c19ea225a4208da54b104