Sign inSign up
LiteLLM

dhi.io/litellm

LiteLLM 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.103, 1.103-debian, 1.103-debian13, 1.103.3, 1.103.3-debian, 1.103.3-debian13

Index digest:

sha256:908d09bc01c395564b91675f5f85d01d1bab1e71c564b2f37124179337861253

Manifest digest:

sha256:33decd0f238a0016f54fc1f666f43461d3c51623f32389921901789b37dcb083

Size

270.98 MB

Last pushed

2 days ago

Vulnerabilities

0
6
7
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/litellm:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/litellm:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/litellm@sha256:d3b6728ea95cf891566b8eb332bf21bb61012aa515bf50cebc387b44d5907249
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/litellm@sha256:d21292704d2798e2b3b4a9ca306126359664fd2c0302fd2cce2333232c4b5950
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/litellm@sha256:8b6a51fd05b24c525a374d5cc1f603cbada0a4012ffe487ab3e0f819badc0cde
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/litellm@sha256:d9b604467aace577ccc2c106a4f3d4c5f0c30b6f6945097768fe9311d6af7189
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/litellm@sha256:2e37e694d9a3a8ba8d746ef1eb6f96dd12b265a8c13531b10727b5d5d483e278
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/litellm@sha256:1b4a440b87077cbc887fa87befe679f818d0499e0bd9b28f8205a34a91177ef7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/litellm@sha256:74b4f659efb632c7ad80e640688173b471309a39681dc5eef6bf0ca74c1287e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/litellm@sha256:db879b87044bed5ee6873910c9d6b263677daa1a06362decec24202532fc8059
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/litellm@sha256:ff45c0e47a7f0cb138e645ff30ec04da3c24ed3d235aa9e87d560436731a0a4d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/litellm@sha256:a9aa759ede68043f9c81e036733156b26728ee3af2421eb469c8ccd1017c43da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/litellm@sha256:5a2b07552959700dca7b63ae0f80383182bc8d4d8ea7e17767835fd9aa016c93
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/litellm@sha256:47a91ffb79656f827baf84999171be5c0e20c9f71c554d91e2defe7788990143
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/litellm@sha256:50c2064b89bf05ee0314ad166979e3d6310f820a933d2f3d0680fddb27425a21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/litellm@sha256:9dc10e53781d0d99168a8893c34cd1a945382247c88db202e7ce444ceedb5555
SPDX SBOMhttps://spdx.dev/Documentdhi.io/litellm@sha256:ae997e67606ddb65a4b081d526c50b6f0374f22fa6ead2ab07071924af3e35ac