Sign inSign up
Traefik

dhi.io/traefik

Traefik 3.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips, 3.7-alpine3.23-fips, 3.7.13-alpine3.23-fips

Index digest:

sha256:c645655f2d1136914786bb80c43e7b57355e3d00b311213b696eec3ab247830a

Manifest digest:

sha256:45b0bbbabac8222b3ca535c933dfbbbea3ed830447df1b7f86d41cf17a1816cd

Size

46.08 MB

Last pushed

11 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/traefik:3-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/traefik:3-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/traefik@sha256:c090e16c7ddabf14e0037dd3525db057f155ce6f7282a2b473cdfa2473c577f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/traefik@sha256:06c103989e650c278a4c04f531dd1a9d2049a5e9dd467d4ba6c5b40038f7fc85
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/traefik@sha256:faba6e36bd4d3b5bfda66e6710cc022ceba24b243f3cc7e0f1f37cea97d945f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/traefik@sha256:cf45d475a23b3ce4db9c2455417cc8608392fe21a1db74c9aaaf58830ab1379a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/traefik@sha256:5d9e3649e68d40a1b4aeeff4a9d17e38896cc3dd7f123b5350058523121593b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/traefik@sha256:1fa422e0d939b9ce545c3cf5ef0bb2d58534dd8ae8b385e6fc28eeade632a67e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/traefik@sha256:993d9be51103b2e20ca4241cc188ece64b16832bf2045bf7f5141450aa7eeb0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/traefik@sha256:0648731422abb01b740296a6044f58ea372ae29e0d9743a62d5bab48caf18fd8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/traefik@sha256:a34cc5c9dcabdb9a43c29f13c43574f5be6e7352d0fced88c0d982c11980cb1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/traefik@sha256:93ec0582b21d8fc9fd2cb75d671b2e30ecdffe2fdf586709c17eb4d12f1b7d0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/traefik@sha256:d8e47ecb7d86f836805c2c7b3680ac10abb7c94aff85a114ae948a8fbb35b0df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/traefik@sha256:4aeddfc42e72815f04418650a335563580f4d5dd5e408dcb19a982358e2b9fe0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/traefik@sha256:580ca18833d6d38ddd9fc00e48e1c51f6e3b71a6882572edb7fb200193e6f524
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/traefik@sha256:bd6402ab3f336618996a4fa93572f0ab41fa77ab4337df607e1ba1684cd349a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/traefik@sha256:51cd89d7337712c004fffe5bdcaec3ae04097fe12e265a53112ea87fc1ffe0f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/traefik@sha256:dd7b02563be9f20344f3f299897aaebd459287e025927d66255ff705490289d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/traefik@sha256:22f3c342f3dc9531b911dfbd5cc992f598c7fbb1dc5542872f9ed548b95afdba