dhi.io/rabbitmq
4, 4-debian, 4-debian13, 4.3, 4.3-debian, 4.3-debian13, 4.3.6, 4.3.6-debian, 4.3.6-debian13
sha256:ecbb989b72be05d4d8b9a389e1f9ef6da0e834b755095a6edc62306c4487e59b
Manifest digest:sha256:0461895966be54644a1b3b6ed1332b2ce6650c08c0b00ca077602a5cb18ad64e
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/rabbitmq:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/rabbitmq:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/rabbitmq@sha256:92be12790932db953780002f2c596ec1fb481a7c535c09fa7082499f588ece96 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/rabbitmq@sha256:d0265e354fe582811d00bdf17dcb3f904860fa7639aa24c4897054bd7aa56611 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/rabbitmq@sha256:d75a9734400877b64be460ef05e6460a7fe211953c5f1e7c27d6634128bf7c9e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/rabbitmq@sha256:5fe505bc369d743a09eb8fa78bc78aef475fb20905b76a102eff6e80a466913e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/rabbitmq@sha256:57250e20270ff89bea9e90d7ce0755fd06375be1a26f57c5650a14abd2a1eaf5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/rabbitmq@sha256:45173cc3e13fe97ee8307c6ecc01409422c7c66f258524d4a99c1c3114b0ebf3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/rabbitmq@sha256:12e7b47986a94e94f41333f433fc95e77f4d27a8e6ca85032c78164539eda371 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/rabbitmq@sha256:f257d2f491bd8cf1ce4dc1d43f1560671c691adcca914b4cf48ec3ddde765555 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/rabbitmq@sha256:6084d8958f0047c16c3aee06ad67c1b6ab4f3e70604262c150ac18383445cf3d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/rabbitmq@sha256:710cc78ea97cb8c86bba6dec118a03dc6285d8b2ce3361424b38b32b65da0e5f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/rabbitmq@sha256:5abf56aba4b7557b02eec18486054df035d659428640142df49a2da4919949c8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/rabbitmq@sha256:e9b4af2f6f9c8e1312b52c6231a33ccc976d33fb21ef1f010a9b85a9af7ebfe5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/rabbitmq@sha256:94bdbbce8ee5453d69b6db845dbae081e0cd9b60c30e2efec846ee59d9ce4463 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/rabbitmq@sha256:20c7901b1faf9aa5a1afcd466367347d939da480834dad0bf00f0e0ba341caf6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/rabbitmq@sha256:c1e6790cfa4948b341998d488e7c8a3035b18d135b5bdbb500a83553a8c46113 |