Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-dev, 3.7-alpine3.23-dev, 3.7.14-alpine3.23-dev

Index digest:

sha256:aed3cc5356f19f07987c6efeee950e982c9dae55b7592026cb88b35224ed30cf

Manifest digest:

sha256:08c277e7b32e709929eefeb31052c986e100d8de127326fa5f7d7cc647296138

Size

89.22 MB

Last pushed

1 day ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:7f9e3b164687fdf9ab91996965aaf0f39414ecbbbccc2a64c45450a7e36946cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:a70b1aeec5a032963ae6ac177feb616a7c4fd6f5ed4499c95463405c27e8a68b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:13e66df8674adbc5274c77f764f2699e0e6fcc07a11061fbc84f8b7e1061e107
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:deacc0f01efffd3d53a2ae250cba56a02595ecb7aab5c286b5700ddcdcb36050
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:ad5936741064dfe43e45f66ed07e5214c4e43691dbeb47ea80892cbcf25ead59
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:a2b4574efa86e6306a12a7c622b48639948fd6239b85baf275ee08b10eb89862
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:99dad23a2dcd7037da4eec4e5cd8427cab7d36ba310670aa25f8adb3b2c54f95
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:c55161a98723fc672765a349f8a3c949c60e0a128d79a464c2135655dce03bc0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:bd2adb0ef16c497de2988246d75beabb90f3c4d90289182a3b2c1650f2952037
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:7ea9a8ff6e70cea31fef16ead394000e256e00acbc06c47d394928a37a09dda6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:41d12d6f087852733f31aabcd4c9285cfba16390bf293ba9a275aea442d6811c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:760d3681a4528df27798344adbc12175fce6264a112ddc56fdf77f6a02ad8d5b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:12d73846f0bdcab0e66aca6ce5f84bddfdba2191cad7c2ca163482e3466be9e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:33e4ec9ac545d919e10fc51ff9943438c91ff7cf688c183792d99c445856f149
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:575dd47fd294e4046f657e1ea97b613509374a2a0e3d8f396192290eadc47d4b