Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.7-alpine-dev, 3.7-alpine3.24-dev, 3.7.13-alpine-dev, 3.7.13-alpine3.24-dev

Index digest:

sha256:b73c4783be5d638632eaf60a7f9b50de7bebee5abfce3961e0f5ae6e866052b5

Manifest digest:

sha256:eb1124e5b116e1c2b1cd5186ba8210a546a509333f73c5f4960329967d22c9c0

Size

89.21 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:454edb7e5ba848349f7d66b94378f7df16c9bbbf5c5fddb6394eac4478750bea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:872d8ab06063dbfbc132151e0f865249d30e66a3fe79b4caac12b81f897aa501
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:289e5285ff5e4d12d4094d3db92da880ac4fae71bc8cddf9abb37e71e4b1abcf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:4ed9e1351b82f51b3a9c287129602d3a3501cfc796a3ad631849950a2ffa0ea2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:3fb4e25d887ed38597203f7b1fe5183535b8e60f19102b358c70bef95c1f3284
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:255b42c7fb30b006bfe7f98ca0b359e875df81bc98a70150b9cbd4d1a6a201b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:71fe1ef4400f46f927b6332d29217d19238588ced7d301eff06931563876a513
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:a666db3cddf27fbee54325b8443ca257c19ed415d8ca717634da0370ffbbe603
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:b60eb2d88f99247f942f9fe1fe39c59f767f5e9f4db248d653aeffffcbb8bd27
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:14fb7b6d200d4aaa993e001635be64e024c8d4df30ccee980ec9af37394b773a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:9247aa5b36f05715676f64f420c6c1fcf1d1fa8013c2c82acd17b13d0965b41a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:23bf3d3317c4c73088884f50fc5de8b1499882f4b76cc29957c9f5ab40db5d52
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:657930a46afa5a8f6bce79ef59ac017fa28a17072da1a4caa2a0578ce218dc4d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:5f1528402de9574e356a9c31dd841d1fc0290df05d2da439ec02d1d33ebe4abc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:3a6d065debaf1728e69172d79e3f4fec3af895a1fc442e03b57623d89bb59632