Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.7-alpine-dev, 3.7-alpine3.24-dev, 3.7.13-alpine-dev, 3.7.13-alpine3.24-dev

Index digest:

sha256:b7d5ffd4f89295f747316986ab60ea1afeb895c74ca6f31f3e2c2b3fcdcb3fb5

Manifest digest:

sha256:c64fb65e5b331d0fe323723f51ad9e71fb8e4617f7854ccb98d98c32fa574213

Size

89.20 MB

Last pushed

7 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:0340be9b42071bb33f865c31642bb1b2949205a6916700a897cda2d158a1d2a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:89c4c2ddce8abaab3be955e0e46ce9678e25b28da85952419f8d4fe698d6ab2e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:c87d5f59ef70d68934ceab0d8f381c3813760ae041539c8776ab5765cbe54f1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:7ebab8c94cf964d24f2297ffa2d7bcf6c2f1868420464b7f7cd1851905f40a6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:cf30ff4782f22b29c47a0facf11c46019313601f73f5738b30a8aeb1c3a93f30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:15c1f25724f69b8f64dc6ecc4dda8a12fdd6c0f3a4bbec042f86372812bf80fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:6a68f9211534a2239419fa02404e85ae8f9416d4224e7f8293548489fb35dfbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:74747600b27c21e3ad5227b05a5fcb784c3039abfe413e27d763132413c129c0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:ef3b12e02f643cdc3a9f6ecc7aa0eb3f449e1944bb46d362035b2d7a8a091054
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:62e25b6e69230f4d71fbf24105789b63bc113e34d9166a76a4a0ef26f508c05a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:41cb8953698f7f922b31d3e7bd59e2361b74b9f768bbe20581f9835c1b7c5a1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:3e3f0dd6f5f98d21fca48d621e331c6e87367427e68b21c838a605fe8b81137d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:f29695be5da9cb3f0cad8580c172555664fcf616b7ec439181fb1600bb66dee8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:6b0aa001169f25817c9af4254bd8eed58833af8af528fdc8837c00356d7f0a21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:b2046bfbd7b931bced31f4fb372d41b36cb3decc9061172e3fc2c3ba1fb1e607