Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-dev, 3.7-alpine3.23-dev, 3.7.13-alpine3.23-dev

Index digest:

sha256:357b3a9da6320eedfab17f0985c3de8b4d31435aa481b81a481ca9729104f84b

Manifest digest:

sha256:6a551ce382902ec5104f1815e134a72db55f79cfdcfa87e91a955c0b7ac5c28e

Size

89.26 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:682598a9b07790225a961ddc874eeac6a576917dd6907076c4acd641d2196b3d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:364f9eb30ca50fcca2aac69508c38d0804b07c663751f02da9ab71e0c148c7b8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:8be2cf6c2006df361634137454b2e35487c5ef815bbf7d37cd3a760038f6dbbe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:4d826c6e386d0f8d3195539df8a2a4ac32202255dd304fbd4c61a348442d5bcc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:764ed9ca7d5b75290ca5fc5c8f07d733694baaa305f2ee8ccb3c1763eec35b43
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:f96b3da7cb061e283b9e706a5caed6eb25fe9dabb018eaf0ae3222f19013b431
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:483ad0865d2fbd0db95959ff528b660798f61357a7dffd34266b9030a95051fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:94c8c9058373486dffa549fb4c144d79b48d2030a1ae5e4a22013f18e9001fb2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:0a368cbec22796490ffebb3de961a961ec0922a513e4dfa8df8f62f526de3d99
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:5a717ce3cfd59e4b6d7d58b41c81edfa5feeee7f2e02a65ac24c37525d820c2f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:2041f70139887b6022260d05a316d1f219f45e39f8cccba564868d8904be8e17
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:1e5fadf8dec720ef70c8824c2440d13f7ef033e4b52e6cabe68f393f70f85883
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:c3fe5823e476db519005b1f5c5bc7c7a6b5107a8c5b2fac1bf95f702dc021c05
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:9e0e8cd4372fbfc8d7fab17b34336b710106fd3546e65fc28e66b139c49b31df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:6056a4ab76cb6802211c6887291954a7e44fd6cfe05dac2efd92e791ab49aecf