Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.7-alpine-fips-dev, 3.7-alpine3.24-fips-dev, 3.7.13-alpine-fips-dev, 3.7.13-alpine3.24-fips-dev

Index digest:

sha256:f50a9d3abf7f1d97c7dabbede1638f6b4535a9f494c470f4ae4117c02d39228d

Manifest digest:

sha256:c281bacc91536c944dff46edc8f6edc741e5ae0dbd459a954866fde2dc5a0a07

Size

90.15 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:23cc8879696fe8a8c0463fe17cd3ffb85d283eda34b36c52508497679ed0e433
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:348fe6e3f3828c8518b970bd8b2cfb54ce616db6918f836160d4c8dc91b35f7d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/traefik@sha256:5d6e9252b3b3f702392c3555466ab97937ea865dc2ef338bb2c2f0c93453c27d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:63cef2d1866ccea7c068084d7f8aa8238be5977ebf21c1845ff4504360fc1878
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/traefik@sha256:395d8f3b79965d9f871f1b1e1ddd9c433dd340c9f8ccbced22ff4c4b58761f24
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:3fd15835f4430a9e9ae614d50869e660cd26d35b52f0ba90005d9d0c93703737
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:b07204d561c4b32306bb8480634b8db5cfd01e6d939c056d6cae92ca680e62c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:4c94aa39b1d6898c0520e19c1683ce0a3e391228198cf6cc7ae58229f9b2dde8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:b5acddf94199f47616f913788235bf1b3a140e152f2965650f90b31134a17677
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:7f8abed2fc3b722570c8bc9db4f24e870ff3bab6eb09b045299951a1a93219f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:12c1a66ca9d13fa019620c5dbf3bdb44993a90dbe16019dab1bc5564f3b66aa8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:ca35be25262fcd9fb19a234e809168b1cee5f735e84ad5153adbeb9031350319
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:a03f730d3227a63f599fee8750580b6f76e0cf652364b41cf6ea43fba50659be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:8d458764b4d4c4c41eab5190a68db02a30391f1828c4b63a32e92372af705f05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:39027b67d5e70455f40d49c300ceabbf5526a31723185d6b54b30174b074b2ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:7478754922a3f0513de1d3866c3523c1bbd2a945d2fdeb286f5f677f39b28a26
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:5950e851f9b1782467ee9a55599766245810746363a8e39d2b27b928f2d52052