Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9-debian-dev, 2.11-cuda12.8-cudnn9-debian13-dev, 2.11-cuda12.8-cudnn9-dev, 2.11.0-cuda12.8-cudnn9-debian-dev, 2.11.0-cuda12.8-cudnn9-debian13-dev, 2.11.0-cuda12.8-cudnn9-dev

Index digest:

sha256:06a3d10cd2776ed202c69f6bc35ea90d5b94c9da7bfbcf0665b8c3255369e8e4

Manifest digest:

sha256:939b2561f03e231ad720c466fe2cf4d398f66abed262ba623e1d5665d1a1c43d

Size

5.50 GB

Last pushed

17 hours ago

Vulnerabilities

0
2
5
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:d50c5882c59d1b64b34700bc3a6d3dc0d8db4d4b42359eba923888dcb13fcdef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:575faf6a8e1ecf4cf4070978b47249faacbd781366d6ecf1bb6479ee5125d1fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:7f36fcd4190892c018e7ae74559aa87bdc893b1ae7c1a594fa4c31acb7f6ea33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:0e65b21c010af1f2ff1325283df109080841325e427fea56cf10336da1e55c58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:8a867e26be3b6a5da60cb7f762cf3ab2b42f1ba9265cc14108afc9cc3a9590c5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:4fd9c147a8588d98ed032cea70658dec924fda826eff2e293165bada68068c52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:196327cf9dc80800cba9ea6a826851ee40f499729ccfce22ab9a0f9ad8294c78
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:7194f89c8f9387c7c66be7ef0d4fdb3df0e82714adf3a3372ead3fd95ae57916
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:e722f616751dfeae648d223f874572acf33a429bb6edbcf70d1f939164f8604d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:a790f04b1091d38a12e6c80f188f32890cb20d5d1f99a84ad748f49b3a586d00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:4e1d5dbf6686a2ac4859c7e486c1267eae8f8e10db19a228c2eeebfec12137a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:f8f892a8c89b1aca878a68a0b64d1681dc3852b89eb67ea99ba2a183b10e0278
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:a257ca962a0c4cfdd767400066e98a9c8da56228f965dce6eef3bfed47d8a475
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:8898b29dc8d85fc8712addbaabcdf9b1ff53b0839e8e2647f43af61846e4497b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:6c51e1af365f1b9f0f69ad3da65724da417639b1443d8f12e1358ab57edc2ec6