RabbitMQ

dhi.io/rabbitmq

RabbitMQ 4.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.3-debian-fips-dev, 4.3-debian13-fips-dev, 4.3-fips-dev, 4.3.4-debian-fips-dev, 4.3.4-debian13-fips-dev, 4.3.4-fips-dev

Index digest:

sha256:2d49b08069995f1c91415f1bdceba2d3af0246fd09f8ddbb68f4574eb66a8a2e

Manifest digest:

sha256:b43bca96408aa7aaaaa5d5d37adb4b6012c2b9f21468c3eba38059a7cf83684b

Size

103.14 MB

Last pushed

7 days ago

Vulnerabilities

2
2
3
5
3

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rabbitmq:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rabbitmq:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rabbitmq@sha256:c038d914fabdfff502ac4578dc79e2b6745f6f92b8c2efcf4ddc81ca0625b7af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rabbitmq@sha256:a1733b2c8bf892355672cd79ccd229e770d8291230638802c23c8339dccb7009
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rabbitmq@sha256:70311fed742d48d0b935d2b3870f15c168db5da4964c95294327e17274ed2e03
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rabbitmq@sha256:c8d2b8e60efa8e0ad37ed5b928f5879ab298116481d8b9c0e746821117422204
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rabbitmq@sha256:cbb927f5a1c9cef57a0e7f8001ba59ebd47dcb863c99bc03dc101edc81f2beaf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rabbitmq@sha256:c403a8bf6ffd916bb868dccfe62c0fc2609d4022bf6e016cd08b17dc4f317ec7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rabbitmq@sha256:734842c2c25b063a4359d0184f255fce0c11b347b01e4a7c4200ed6c24628432
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rabbitmq@sha256:0e02b6c1a0c8acf6270da166981cce62bbbb7791b6f80a0d042e9f9ab50d0fd7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rabbitmq@sha256:c27a7d6d2253ddeb45d69da2fc50c2a41035119e44f3ba1ab6e9164a77b4dab3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rabbitmq@sha256:c2032f1473dc240408ccc89817d3686d9247a7dc83cf4d9cf48614a912000aa1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rabbitmq@sha256:79048af07a9ef95903f9bfc083650ef5b898fdb9c152d41c8c16178df8c609e2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rabbitmq@sha256:b31433c6ea4d1a79a0448c2fb70127c728f9c0d529ba112a983aad6e72e89a8d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rabbitmq@sha256:0b4c9e5da262aab1afb0802f0fd536c735730b830bd633c8ebceb9c70153e3df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rabbitmq@sha256:58081e9f94fb17363d1e9587f0dc964150de5860115814b8dd5fd8bba6c25171
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rabbitmq@sha256:3131764d89591f08f9ee0ad761ca8b5709ee743aa9625f581e7c9470052281a7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rabbitmq@sha256:586298e8b637886133bce464269ed4ab84a5c14e5874b4454b50ef57a3c943c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rabbitmq@sha256:13120a3251b6feacbc9a3cfe20f190164ca5895808ed1b4863b87f1a192e2c59