Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips, 3.7-alpine3.23-fips, 3.7.14-alpine3.23-fips

Index digest:

sha256:8b5e944ee1daf79c1d879ca85a484f983b39c72d097a0c62b803d14c2eade0cb

Manifest digest:

sha256:6e13eae512dcdc26c9b268d2161000640db6caaee40c5c7e39ca2df8e2283a22

Size

46.27 MB

Last pushed

12 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:95a95599d008742b3f92d8a8341ee6c75996789f9cd30cb06e4c665d55b085ed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:b866983dc1f1c2ab7826b2da57c5bcfc4c2393f2db34b2aec0f111a66aeef62b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/traefik@sha256:c0cebd09a6f8d6c02ef83702a2217e1dc6ec86185c2f0adcf78d5bb18afdef0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:15e3cfdb263c9b8034f7675e3ecea2804314f5ab35116510b92adc3376809832
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/traefik@sha256:2c432ca6ce0b8fbc750a5c5024edb5d70ae0e4db9afc261331ff1487a820ad6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:6fdf7785d7d5796c02722fdcc95e02e9f67376b5856d9ed9e5bb5d47ff1e7c9b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:7baa2466749b3f970e18bc611c788d61339ee35e314b056c7e76c405cb7166c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:6fe4087e89dd1cbba7295b3a28ddadd66392ea692ece57927f1e765ddbf06915
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:122c95de87ff235b2a52cbc111051b13fbd14e7e32bac4088606290bd597d30c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:518ade810ebe19c086f9e428f80d7b7cf3cf916b5782736ce44e5c1553297399
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:c655a2c8694ed612e1e372a8935ee0f1cd1dc50d6d3e8f800a75df08d392fa3d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:91efb25a1da48a2efdbada767572e4666079418878bed234f919393ce045a77f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:0ea3c4167227aedb26f5a275f515c95a8f1bbe9475b1277d92c4b567fb468257
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:387a67045e6b174c069621d753db75afd4f2861d0400eab86a7de184561a305f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:ac3faf62527e1081b43388f86b71f07269147b45931d1e99d0a0d8af79830d4c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:bd24aadfb5ed6176fc91ca26dbe03aa6162f16da7dfa242bba5165e95ddcf27c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:6071792abfd75296ece1441da8a5c9de70654c9150c7d3dd415a1001b2ba2b62