Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine, 3-alpine3.24, 3.7-alpine, 3.7-alpine3.24, 3.7.13-alpine, 3.7.13-alpine3.24

Index digest:

sha256:9969e9f14ec81db1b83ece542219aabd1d85aa2dd39a44f8bec942171c5efd89

Manifest digest:

sha256:545e026b07c720415c14b14e18afce7a66217891559e01aa83f7c6594758be43

Size

42.67 MB

Last pushed

11 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:7deffd6289839a2a36fb83fe4d6950d61f6f225125758629561c48f1a755ce0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:cab2b84acba7642c826c69b2116fa6cdcda329dc1fdcd261f8a8554e5883531b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:bf8bdfa4fb2f0a00644e18abc07f1662ee1bbed99b51c4cd842f83021fc4fe85
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:969dc8f808a2a5ebf38f82d1228c3ff2558c4dd97310a9f65c35c57748760ea1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:e26182597dc45a518948f219cdd3261f11d0ed593dd5be7d1bc15b551375a5c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:8661e110b28122202d86223b83c38e221bd6eb32b11bcdf9dbe94d5304924b23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:d471b424a281c5b30106729ecd103cdffb96fe81d5a3dd331c34151a84dcbf85
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:a6abfb94edd83e249f97ff00efdcd3aae75552cfd59fb37001dbdf2c49d05c1a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:7b3903b41ff65593b54ecf89f34073b28764ce0a987c0cd424c101d0c4f58191
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:20b23ba9510eaf7cf31c288b682fd7589581ea8d699d2e7aaace07998653dcee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:e89c9e5212eefdd01fa07e060717256f409bd99b6f324abe333c2b1a4de24dc7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:b858cbb2c6d7024fea8da4321457b6d3acbe88a9666bcd9a0fbbf8c63246aae1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:bf4a7e7c1a254a7e35b42f298cbf726e68d4d60e8a63326a6e1a4b507d038a29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:4df0d401302ebc9b8bcc6128fe8dc1946c97fa704ebdb802e62e2d404cdcbf4e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:6646493bb98aed233547cdcec5c2c76f7ea2c4a72ae13607cdc0bf10b0ffe91b