Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips, 3.7-alpine3.23-fips, 3.7.13-alpine3.23-fips

Index digest:

sha256:d30f352d6f53ae03acf4080efbbdf919fed38877248161dec129b6b4ef0bb6e5

Manifest digest:

sha256:0bd72c321c7639d02a0fdc02e4b550764f2fbcf70f98d935d75972391eb30eb6

Size

46.12 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:94b72fcfa68fa1f7d50b6ed1ea775f068f97b55cfa5cee6761b407ebc1208d0a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:a4162dd7a8b5ea1faa71d00ce7929c33104e56655f9ec3fceb0b6e9984981ea7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/traefik@sha256:5684db4936c7038cf1421df50d04dc7b37f4eacccc05f013c43185cd3aac60e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:b53e402b3d343f9780f7a4732b730fee633d67e32f969b97ccf4a203d4ef030c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/traefik@sha256:ad1e3b32dae48d59262c8776b375d0745b972a63389819f86122fcad81f45345
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:c6a4f4c95a2f1d07e642a305e4f08272a826ddcd05e7870a26dab5ba8bb3468a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:bd3ac6be8466c7c13fb1152bb94e2df207ee02aacf3eb10af386775091e06acd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:306d98c9f8b760b9e165f2a3dad771ac18b9b505d2b22e2c520c73873d8d139c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:4097c610b00209ef9626e765263d04d7bbd319c64e7fe1bc6b238e1a05f4e254
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:680cc6e7db74a621033951fc12923782b2d0680f68084f6945a79a231ae76835
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:0802ee225dfe3766c74e639ca986656eee8fecabbfd7a1de3170febb7b644f43
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:4af748175811101aff027fce107c04d4f0099f7c278b2694e226cd3461ead245
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:03a240d7cd5c1d0a11aa5426f5157d5c4187234b3b5a7559aac5734bf5d8c78c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:145df03c0eaa58ffedcf615c69e2e3689d4baf88692519624e8bafb17912c71f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:ad7631c74d9fe98e67e5c8ba66a19ba83937fc1195800db790fdc51a6c0a5586
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:dc9377fa2be77c54e524a905fba0c4032c9d3e861cb6c0a1f95a0ab387c4d104
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:a8856121fdfed41fe1932167703c82f2aea00b0329ad36ed14b020eeeee1a753