Sign inSign up
RabbitMQ

dhi.io/rabbitmq

RabbitMQ 4.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.3-debian-fips-dev, 4.3-debian13-fips-dev, 4.3-fips-dev, 4.3.6-debian-fips-dev, 4.3.6-debian13-fips-dev, 4.3.6-fips-dev

Index digest:

sha256:685e7b83ab96cb7c36b91a928496b1adf84d61841a1f13adc7d207b2c0b66017

Manifest digest:

sha256:dd93f933a94864073208905fbf70f7e065426a29e435596106ac06a7ff9997b0

Size

100.53 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
13
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rabbitmq:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rabbitmq:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rabbitmq@sha256:c2afba98e2664b61fac9d89d1f478333435436793aba82ed24577e6a5acfb634
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rabbitmq@sha256:c2f425adbd53dc5ee597ece63d73cb5d025da43ea6c30cb260d1f372d4139195
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rabbitmq@sha256:c6bc6b1e09d4b795a7f8d574618667c7c68cd2d90aba181f9c3327a84930595e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rabbitmq@sha256:d9b0dd2c7d057340d58ccae5fc779955c30f84e44b0e4c771b900e734337d2bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rabbitmq@sha256:9b7e5c4057a8708d4960e4e3d4fa25bb4a395398ac9d4fa5d357e116f6f7a3b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rabbitmq@sha256:d0f9b8c556d48e26045b4c5e438e5a19dcd0ecc65529c4204fa334781e04e87a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rabbitmq@sha256:9fec735058ce913c14a95e39294100c45b4f61fa42c94e37cb86bcda20d63249
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rabbitmq@sha256:01fe98db487c946c636a6af6b09b70a155d96a00d1ca326f528368047de2ef90
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rabbitmq@sha256:abdecdc2027975bdc39ccd0b9d81567aba4e7c738751d7be74d6b559d36096e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rabbitmq@sha256:2d6975f1820d2b9c1335f939eb22bc6da5978be3efb84d7f67344c46d256c406
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rabbitmq@sha256:42604911f47eba30c6fed4dbb232b00bdd051163fa5be4edf9ab977c621e47c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rabbitmq@sha256:754e43c52cb8506438d1f203aaeb373ef8b34fbae83ac305c26fb0fcd3b71de0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rabbitmq@sha256:4c8c94a7a1b5fb2f074716bc8019ca1a69e19837d35fabbcd1c10d455b58ea1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rabbitmq@sha256:7c70f22b0e3b7edc23896fb38373f6ae5b0f52d0fd2c97525012fc3c0b252498
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rabbitmq@sha256:d7d57796ec238e017c43b0f15a846b3c12cb15e9f7091f5ba1e021797e3c04f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rabbitmq@sha256:b13792e89c3c221d9227f39459b13c5445a8457fadc9791d5c9802b856df4d7c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rabbitmq@sha256:29f571a286f0e5172032c9308da421dbfd342c07836ce4d964bf1f6b53a6ecc6