Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.7-alpine-fips-dev, 3.7-alpine3.24-fips-dev, 3.7.13-alpine-fips-dev, 3.7.13-alpine3.24-fips-dev

Index digest:

sha256:9f2b47e855c373a4c54b89bf3d7bfd6c6419db07a952a78e96ce0d79246a941d

Manifest digest:

sha256:76cb8a277e0a914ea555766ee686cc7c5cbb01ad2c3e1dfe9d1f6a8e87dcea15

Size

89.95 MB

Last pushed

16 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:692135b51ad6ebbe5fbfb37005c9b5174eedc0d65f4a2a9f09476cfee736e50e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:016cb5e5f77cb76119b111059b54c116f865c1f9d425feca864574a2ea83c991
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/traefik@sha256:cfa96a9358b119d21274ca9dd77b9decfb598ce34b5e0c57277f23b0403d455c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:96721783b54cae039ee5c14e04f5dccd95b18b21f70a3e6cd6f8ced334b4cde6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/traefik@sha256:e5745a4f9c6460d213389383db9bfced9af4c0860ac4162f8b5c77a5a839a644
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:6c399199540e9226857d5ebc341d97aba50f2120bd886151f25ef1da93e5975d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:8daa3f1d4b125364dd613547eee0f1827f3c50ece03cd72dbf12db0a10959bb2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:9e7fd35d7881a5042d72f4ff7217f6b5e80a69663368f4414dc9778f31cbc202
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:336276c0fe5f7b5314b24c820f139c3f31314e2d423f4449aa63653490087ff6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:45c0a8b226d0ac448355474a49181fc046a2042b905bee111dcd48e673a5ad22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:9aaefdee3562741249a0d3968b09084295f639a5701f7b97f15474812784bc9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:d814973983f09ed67183bb9f1b968039675bacc8122479345bfefeedc9b27bbd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:777ebbf703939f22839b52c55a7a77ab7e79787e183f2738a1f5e70e62a30107
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:80d893e4ce61da09ac47db4ec0eeafcf7738ab532a8097c1e8aa839806722f85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:8ed70a1c1111f8163a88674fe02e985881411a8a4506f4af89a7621909986705
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:b2ee35166574cc02365a724dbc01d79c114d68e98dfe5b8e9cfeed0cd1657618
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:dd4ae2dfcd8ef93d040388efdb178c834cc865cdc5074eb36289ac3be9ab7e94