Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.7, 3.7-debian, 3.7-debian13, 3.7.14, 3.7.14-debian, 3.7.14-debian13

Index digest:

sha256:8ffbaf2ba5d11dc859a08ddc7813c04b79ea3ce300876736c643805c7ac0a4dc

Manifest digest:

sha256:24af062b223f2a34035d771b7c64be9f38fb4e590ce472c85b6fbb1da8f1f2cc

Size

43.26 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:77c7d16440799c85bcac752179a598e796a7191bc17e155eae121f8642b4ef1a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:fbb95594108c961a968fa8c5553e169323a56bdd0887404949fb2d2757e175d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:d763156eb7996a08f2e72ca17d661257f65b514738cac47b66ff4a7213415cc9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:a9d4cf2eefb3c7419aa1e688e6b28606fb4f4a827536d73a078bd27f32bc0d8d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:a0e9d29c7157b5c3ac770488e0079c6ca76b04e7966910c2f35e6e497aa78fa9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:c1b3d3b555ce5aec4472e93a76466b7a9bfb5a47fa47333849b1baed4f41663a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:d2c99bc03f5382811f38a97d47133efcd689940b3301abc9a1599ac35ec415e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:7fb018ea0e92549c56572c8f8c1e2d27f282a23a9ba0c1d33e4bf3ce8d31dbd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:78d9eb738aa68fa76033833ca88178fbcef8c8f8e4fa27cc7e1c8f746d27c921
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:389e91a75c116bb5a4473d31582ebab3a0bdda8eb0500a9ebb5e9e16916db941
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:df4ffe7e7fb8086a9ccffa59657e5a12e63c5aced046f9a9ea792b338f4e1d52
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:bcf5f7efb7e5f3bc73f215309d589f72ae5ed1ad54eea37c73373f667dac4e53
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:34310fa5be3a2beac4f5bd5c3d69dc3c259519c8fc446e050f8119e099a9756c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:90cee86e630f705969fd58962936ffba5ee98caaa5046e3c728b96e00b71495b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:2d4bf73619be45d9ad6f037b61eb5d2a8984f34635222a721f3a6de7ffc185b0