Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips-dev, 3.7-alpine3.23-fips-dev, 3.7.14-alpine3.23-fips-dev

Index digest:

sha256:8bce44cc046382361647ac402ebc9dd8693e56aacde7f01123590df93e7fa379

Manifest digest:

sha256:02c9155feb94432502e1220e7645fe3fa4d98d635354917ad33af8b85fd9d338

Size

90.05 MB

Last pushed

16 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:7e8cd11e54dc75ca052f12e78180646d7d18b1c8b0ffcf84b7ae40197043da74
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:f3839414860104a5ed4903c953641ab8480eee5dd07c96ad02f5c5e6ee9d532a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/traefik@sha256:6b8e4ee3f5a43df1975d52832a129631195c011ab9e78c529a99609276eb74b0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:40c0e93fc81908f86fdd05fb601f08f3fec9e7279e55788dc894a19aaa676adc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/traefik@sha256:988017e2aa10c1519e0f74d65db00dcae63f3c80afd41b9079733a3d03d1a723
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:5aa6bf6b0c36a2583d1cd3d917b2a97e43f23c13eb15e4b32505adcc7c5bb72c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:5c27844bf1dc0ccb9380a8e75bf7d46b0edd0ecdb3f748401574d4793f8accdf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:0a7f684649060a9312f5d2271f5727af271b6461d00932e6bb70165ad5f74ea0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:92f0411861ff9cb01058c9cddc4c280eb88ee0b946560e853ce584f63f49c52d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:74fc5470b609b055e8a495cb05a78c37d5bb516f5281cbc93b70b0e57fe59880
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:75959a854a38731a67c19e22c7a6d6abbe1c8f9caadff3e857c151c18bb706fa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:142dafb906ba41c1c57806a57d1151319cede7ee1f97eaa945c0a9f56334c7ed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:07d383daa47c2b6ecf36b13e6e1caaaea21c375bfa9b505c17741b9c7a8a51c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:f8d692b5e28de3d5457eea4f4a081746cd7d12a700864a9fd88b40fc621a6509
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:90879ca214c0c50b845295783b9170761d7e126051dc818f8c94c95418028d39
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:27b9ab83f639d89d8950f83c3f212b6e0079ebb157adf703e7320f19809173e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:8be992c483fed81f5f30e1cb67684dc15109a2cc7bd50f7ae7f5dc40be976a6b