Sign inSign up
RabbitMQ

dhi.io/rabbitmq

RabbitMQ 4.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.3-debian-fips, 4.3-debian13-fips, 4.3-fips, 4.3.6-debian-fips, 4.3.6-debian13-fips, 4.3.6-fips

Index digest:

sha256:53e61e065c017c87dce1368f5efaee025630de6e97802e1b79341ca6434a3edc

Manifest digest:

sha256:08393e5515508e7aa3bebb17401dcec2b651eddf39d988bdff1a0304f69fe64d

Size

90.02 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
9
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rabbitmq:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rabbitmq:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rabbitmq@sha256:1b04e184ff3483b0be4b30d23e2dd0e07621108cf02e4ec9f2801cfd1c6ef4ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rabbitmq@sha256:388d85d7e011c590e157a2094e1f8abf77bad2b3f44618b4af338a23755dda99
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rabbitmq@sha256:55a05cfc4b3ad9e5630e5c9218bfb9059480e294d93529777f16e8203f0719b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rabbitmq@sha256:84098c01b7a5b53ecb0c66de6b0051387b49a03ddb9a143373c8019e930cbd04
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rabbitmq@sha256:dd5cc1a52f818c199c579f098960df37f7aff0e545e8b856ab6a0aa5ee51d786
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rabbitmq@sha256:43224fd6dd567c243aff195f0c757a48745140628c54bab7f1f5ccdc908346ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rabbitmq@sha256:b2d3006ea71032363f4f89414ea5d953a4cef2f90bdf3963bca9c0f5fd7e6f3b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rabbitmq@sha256:a760100a48512eea7df8cb8eb6e37ce6e16a596f47454e7ba30283961a289da7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rabbitmq@sha256:a41442c82d6026c3aa4c1923ea7c898c019cdc2fe1ffbb3e9e9cc7842429e4d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rabbitmq@sha256:ae1112586c803ed83beaeb9d951a434a75f248b4fdf35e882bf415f8f6479673
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rabbitmq@sha256:017ef85f746fc327cc88361d907b35c830d6f6dd8b2f95cc5f31ff19d6130c9f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rabbitmq@sha256:1aa5f13f589945684512e7fd384d97d51deca2cbc6abace4f7c3c41036916e85
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rabbitmq@sha256:0ea742f84e61a56f03a730da6c84a42cea15563111fdc0a8534a78894b29e55a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rabbitmq@sha256:93dfaab197ed99926808ea10fbae30afb132abecaf3b6932e803edbe759278f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rabbitmq@sha256:d0c7673fcce3852148d3c034d87e255fd2caa591c493278bc25a638490709641
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rabbitmq@sha256:ef2b233d4eb9e04e58dc2fcee78f520e6e367ea367bdbd86e9fefb64b497a03b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rabbitmq@sha256:339fd818f6f3e58c6e0e4dfc24a1905eebeba3b2aa37a3e60fd73de4d50688ef