Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine, 3-alpine3.24, 3.7-alpine, 3.7-alpine3.24, 3.7.14-alpine, 3.7.14-alpine3.24

Index digest:

sha256:096b7d2e285caf62bd862fd7dac0ea2f37d1fd4767a00744bf64b980a630c0e7

Manifest digest:

sha256:d56e541133db4a0daf750b3602cb2789d6aa6ed90cda196298c238a616f1c34e

Size

42.86 MB

Last pushed

15 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:66a0c8cd3137d672ada1fa8d58c7aa075bde353b16f63a4b7d19587ab47513b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:2717aacd89876358b29a0514c57505b715776c9c2cf6d81b91ca539862e3aab9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:c1f7c8b27e83b8df9f9c7972581fbf821c297e3bf7bc2eb1ebb0704370aee4b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:e9fba5638b11d0408e9739870371b8b48a0f827155a413cb315aee8fe29b6e63
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:9df0539d97df3c672b4aec0cdf2ff8d8218f4413a2195aaed7952ea9085a37bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:d757e5b5dff7ea5f90ce82eda07d4104f83da26acd9b355a84a100897d981fe7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:b5b9854ab4474476bcf228bb2da8115a8c7b40403679caeab2af1839e17b37d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:2b35f87376eeb4deca6ac1d0e18f326af3daaafaa4d176e59e0176be994acba4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:8f811800298a46cd960144d6e988aa08a5cdf43f224fc97fbd52daf197d98847
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:385b9a2dc6996a7fc9329131deacc6c82c8ca012a28ecc34c475973ae9de6d3a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:d30e2f939a95e97d309c7aa9a565d40205eb3ffa1e8ba7a95e9309b097d22592
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:f00b8569441275c54c8643f9b9a412e22e55e64a80dce9ad715d5dfaaa37e5f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:ed0814e95bd0681ce698bec9d4ae5e1b54086212b56aca6e6b46e894e13a45ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:bb5e0c803723834b2d20dbf87ff9faae32acb052ea74cd63b901dcfb8ed126c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:c32068c7f35cd48bd6cc9f5f57babad31a21a445edffb42a4c4e5b445734b34f