dhi.io/rabbitmq
4, 4-debian, 4-debian13, 4.3, 4.3-debian, 4.3-debian13, 4.3.6, 4.3.6-debian, 4.3.6-debian13
sha256:fb408ce5ba175846643956066e9a6e9aa6fa95645f3dedf6320a7efd145218b0
Manifest digest:sha256:b28a38ad4c199e41bcc0ec6359ef61ed0db1aec35bb9bfa97489a6bc414ecb6e
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/rabbitmq:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/rabbitmq:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/rabbitmq@sha256:f595ac776cddf958955c82dcdc4b13b836892161e87386423e994ed0c093c072 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/rabbitmq@sha256:5800eb42e69ee6dedc1eccedc96e377d1ef3c3f849fbf3d2111963d8137bc5ff |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/rabbitmq@sha256:3fd754ff81ea8eb131582505077e6a34034651a69093ad69e5a376eac0b15e46 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/rabbitmq@sha256:6be98d4b4758f50097397822620adb6b23c3dbfd692f86e4c0ff020c8309c85e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/rabbitmq@sha256:28b17e0f66a8dde52cbd74dbf7743d1f6e4b59ca57f243b203f70e191a6a447b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/rabbitmq@sha256:c341d233ce6e583e70a6b5735fdead6a4459efc11ee4626e05d16d1c225fc17c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/rabbitmq@sha256:65c99bb5318eb1664ca0646a646ee40da261008a5cce1c6bc66c55bb1d33de74 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/rabbitmq@sha256:dd2eae0e6dccf5a3a24c1bab02de7f961b2e29d75f21d61d7207f5a4f5593113 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/rabbitmq@sha256:2c90f5260f516895606e8645aab845db8e3d7d58d7dc02f33019e5cdc4bde191 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/rabbitmq@sha256:3f85b45fd8fa43264c91dc1031aa4280ab32d10be0aa605314a3fe18751656b6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/rabbitmq@sha256:8463438bf72e4a9a664c4f95b9d8f96e50c55d73615e6d2f27cc046a9959477b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/rabbitmq@sha256:4378146206b81a41ab21b10389e8c7d4b6d3b0fe43c6d8f774615ec2a1263527 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/rabbitmq@sha256:f5ed78425f640aa891c26e48d1114fda64408452562e9179a34b919227c3ab0b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/rabbitmq@sha256:2004ac296bcc9acfd6fe2fb717511c62d06e4cbc9670740c66557de28684efb7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/rabbitmq@sha256:aa6f4b69e3231f928cde99ecd90448727a53ce9eee7b6663f098374724f1c2ba |