Sign inSign up
Langfuse Worker

dhi.io/langfuse-worker

Langfuse Worker 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.95-debian-fips, 2.95-debian13-fips, 2.95-fips, 2.95.12-debian-fips, 2.95.12-debian13-fips, 2.95.12-fips

Index digest:

sha256:fce650cb7a799d10635f93ca9a326fba181dc6c3aeea7328f28fca70df605090

Manifest digest:

sha256:636c06938ec570e04b4e4a1feb297cc1e09f656ad6251b6ebcfde7e26cb6a082

Size

192.37 MB

Last pushed

1 hour ago

Vulnerabilities

4
7
8
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse-worker:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse-worker:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse-worker@sha256:ae5683429a75851ea4818e102d7d78a70274d2fc981a84c7bcccbb526d963f41
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse-worker@sha256:12ad3f919893a79f7e1dd6cb97b9a39a3a22102524541f57515553f9a83a1695
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/langfuse-worker@sha256:0f67911a16d59c5f1185806e0466d51a111bdd8b01af54d776c4633a1b49d436
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse-worker@sha256:9ebcca142f2536d05d8bc608da028dc629184c233985c489c49ec9cc6babbf28
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/langfuse-worker@sha256:531019681a18bbc311668f37546c4d4eb485626a58b79d0f7fa6f0dd9c1f649f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse-worker@sha256:8c0f100e4a6725b3f6df44e6f6046166d191466254a7105e6db7512323e16022
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse-worker@sha256:51f653ff998d38ec62850e337552608f9085d6d64fd5958e1b624575ece3f4f8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse-worker@sha256:aff2840c32e2efab6b9ccdf14094123afe469f9462eb366ec2fa35b99d71c3e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse-worker@sha256:3fe1428ef3972c489b412f464d9ab7bcef17f33051d7fb1a735c10db717ee52c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse-worker@sha256:7127ea747711325bbcf1082dceb9f055aa3ff8371b27c59e388e5718c1630eed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse-worker@sha256:7c4a81dd76f852db7efc59a8aaa14d715c76866e63f1fd2000e973b8dd4e7858
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse-worker@sha256:54419708ba66673c26b37f2f88da854c835c6523d20211bc89c235769bb6c3f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse-worker@sha256:2fe171902053c45a73333deb36ea0a08e55e776821792854bd3474d5ef5259d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse-worker@sha256:e7d6a8bf06e5b2f296de9e8f9735b3dd99d7e21f70ec927ebddf8139ce3b3c74
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse-worker@sha256:2a904a88793672f79905fd038331119c76f205ed05bbb628e5fae5677e87820b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse-worker@sha256:c3144e9223f3830686d9375d06829221295e3db402de10b308e04bdbe676304f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse-worker@sha256:1e13363b1c8f1addd7cccee622036ec6fe87099172f811b92970e1dfe43a0ca3