dhi.io/traefik
3-alpine3.23-fips-dev, 3.7-alpine3.23-fips-dev, 3.7.13-alpine3.23-fips-dev
sha256:f819aa0601997c414abf871ca4fd8512024e0524d968f69930841996cc54d443
Manifest digest:sha256:69ca91790aa506048cd6a121909a3be681ccbbcf0428d926f49fa0be45b2ff3d
Size
90.02 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/traefik:3-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/traefik:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/traefik@sha256:ade72c7d4fb1effb6b344256a6318eed8401f749b85b1c72a416c63ef2b3d10e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/traefik@sha256:f66db62687652a87bbe21cab63a8e2fbdd08c6e94ac13ad9a7400f1379a84c7e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/traefik@sha256:9798cfd5c7afff87eaf52cf750f235697c7b675c51325928f75ecb90e6d04ed5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/traefik@sha256:4806fb600ccf9b52d22c018a29de22443d0301162f344f24a8f7f915b0616bed |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/traefik@sha256:214b8ac35c61818d9f367a1edc6209f12941bd8a51eeb0c2fa494215c7560725 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/traefik@sha256:b1ca31c95891404b6faa15051b0ebdbdb0a2d6a3dfe55f38fdda480f71804ac8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/traefik@sha256:08d035688436284495b036359b18e642196d05ba208b17d585d7c8051c86e20c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/traefik@sha256:b89985580456d6e3606c6375d71e7f301233c772bf13a5b587d0b06b95fb2340 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/traefik@sha256:17f2c2e9bca327c960c5ce6135266806721ea361d2703280ce0d2055f4f5e377 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/traefik@sha256:f65cbc879008866cb1b6c125e5db01e7ec8ea617d58984de45381ec1f12b12de |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/traefik@sha256:c6f58a212e5a7d9e1cda2d9b4e7b0f5d5170152e7a68c242ebeaa5287916156d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/traefik@sha256:935df8b623040cc909e17c73774c17c6ef5c403a84fee64b3495840ba9030c6e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/traefik@sha256:ea18149c67c02ab055ba79a2e7852680c972877706fb88e6b40ea44b01e132dd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/traefik@sha256:c0722a6a7cb3157312dfc03e5f0ed62732984540c6b54366e51fadd3ff2e9e90 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/traefik@sha256:70b0cfbb0b2daa3ec95918bb44b5703568192d28f016c1cd10a0224e01635039 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/traefik@sha256:3d3a4b65d14c6fc590ed955f6206f8e14bdc6afbacc2dcd0e34141735e7599f5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/traefik@sha256:ba31562d5e4f092fd3fddab7aeda7ada34275bcce9311d0f595cd7322d19f189 |