Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9, 2.11-cuda12.8-cudnn9-debian, 2.11-cuda12.8-cudnn9-debian13, 2.11.0-cuda12.8-cudnn9, 2.11.0-cuda12.8-cudnn9-debian, 2.11.0-cuda12.8-cudnn9-debian13

Index digest:

sha256:1861b95ec45667b5a27fc2e1628bec0198fe12a9dc9cc34fad64c5504a28cfc6

Manifest digest:

sha256:fd679875ef91c2b848627b69c1040a2ade203240b33ae14fc4dd8a7ff27fb7ef

Size

2.68 GB

Last pushed

19 hours ago

Vulnerabilities

0
3
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:658aa76d2ad7989d1c241db4138ed5fc3b96ed1c4ad5cbee3aeab01b179008e3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:a74c1e23ecba7ac13c42f8ed83f7a58d51c04618c9390babed4044e6a8afce16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:fc578bc75082fd5baabc03207fd70edef6f50045e9e59289b0d4d166bcca8daf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:34efea1232280819538fc81b522c1ce67cbed3d5bc2e60b09dbcc2c06c576000
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:6550ab8e2168974577a298da3f53a1f60409f6bfe7e538341509e095bb57b403
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:ad1ba750c76b604a2e8b2df51640af61f99ce7ab2ec8d5c44ff842826874c155
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:dd1a83ecccb3a871bc0099cd125afe4f492aaf6583e3877b621bfa24dc25b46b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:523c729ff10f077b5387b56088dc0a39b51009beb45f854e06b8418fb689d338
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:e91bfa7cc6eb46e7c12f9b07fa633869b29d5c3ed608a4a7f75c0f9ceab7b760
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:c02ad1f6a1cdbd4829ca589e4ad6d86958cbff301ecd7b7b9b147ddf6461f32a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:6d85dad0aa834484b0a320f1f9acb1cfc787e103da0095775f342fd2458db8d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:a7b0a2c486068055a5fa262e0a4c3c1044de6ebcf5bca9362b41f05d660ba53a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:6232ae0ffd04316397beee8790ec37a449ab14943589cf23bea396f11367f8f2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:18579e3dbe4dac69b7e4e71d872c63448e26d20f4b16291adc4ae08f59eabe80
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:4664d181040a3d59fbfd03abef91b9c46304982ad56c2263f3dd57453d577f39