Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.7-alpine-dev, 3.7-alpine3.24-dev, 3.7.13-alpine-dev, 3.7.13-alpine3.24-dev

Index digest:

sha256:df8f3625d16c9c88bc154c08301e4e326822ce445eee216867c9be5cedb0524b

Manifest digest:

sha256:87af356294928a7ce6b2c6cee198f94fdddf0709fd91acfc6df90dd0dd8eec26

Size

89.26 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:736047a606a89f63c76cd66ef44f4ef86107d2a12fa211f0cc4034a8f2b04fee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:cce1dde4e4d8aae9afa697252640169b71e5e3e6d6bb9857105648623c48c8d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:b1211af39c694546abe6baaf2552f4528132d7b58f1944f1f258ccc6bd03b219
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:44da90035cc23338bb11737d0250e5d2fb8d117709b0c23a64321474f78677f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:335797ff30f779689b2582d5518210034ac8abcdfb94c07ebbeb8f0723527969
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:914de5facbbe4c9fe825c3607e77a443aba9c4940429229b2018022c44916536
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:06a143584c8d2a3d7aa136c9e841178f02a068fa5bf1160f06c1f6ed00745d88
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:8f4823848c313e192f7b8b747cc6bfc6559d2e2e4265b03980b95e6715ccd773
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:dd51eebe532dac41b6880395b7e76c502213c28a61fb797347ec12127668660d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:7e8e0f6663ffc25c6d6cecd88fafe8d390519cce746e35eaf93665f5ad5d5c7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:8a839e0413a1e8bcf22fed286d6ce6c127ed138dd447bcb97a3dd5e8df746048
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:60634dd02d63ab415c534bff05b59acaf0120ce48d4c53f9df533a8678d02401
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:3b9cf849059b075f9027aea399c8095046a1067934f6c64771c63e29d752473e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:db1e5d8df8fbb0c7d2e09244fcf23dc9890bb00da025345aad632a8191ed2f01
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:e680f5a8826513c0a189ac8121fa1dda5a64b90921d5ab48e780959b42a79dc2