Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian-dev, 2.11.0-cuda12.9-cudnn9-python3.12-debian13-dev

Index digest:

sha256:76e9b70254463df9a0018f86be0e905b98762f6fb3df26b4d798b4f687072854

Manifest digest:

sha256:8a2257fe00f9e544c0c1bed7a1fefbf7e092d661f2f3e823b9f59a4fc0a67bfb

Size

6.09 GB

Last pushed

9 hours ago

Vulnerabilities

0
2
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:6f2a3c9789deae75b2a91dd0086d1a44979f6a60d93cab016de7ecf8f14c0873
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:d48c9509e9178c002d084e724c38b13f8f051e7847122ddd4ca7076fcc76cd3e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:f672686ae00197b69d3788d1068cac8e4214aed617a390c1d54bed2b11166ed2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:b4ca7d057fe2836de174431451919d8457e5fbe7733cd2081794cfe7124a46f7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:226843decb2b929acf32624a3c11d913fba37482ab48408fd38662ccd78a8bca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:bcb6f450b21d8bf88f5f47adcf7d7078430873bd8fcbf443783e5c6a2e110ae5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:041317ff200ddf66600986a6ce4096d7194631bf6581daf5a18f32018c6b1ebc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:e95627f6bab8aa2e8fbcc985a7b4aeddec350035ae78c005c7b5bdb3f7670652
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:09686efc333a6b1299ebe3e0a6608797a9b29807a9e8f46edb35192831b2c553
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:6659dec69d4ccffea48e50f53f3dc16b69af1a2d302cab20e5e692d20e7f2daf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:0b210515d3cc5cb6bc5a4fb63d316c72a948ddb651879e683b01c3a67308f982
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:668e6ce6b1f2b3794356accf73bb9a0edfa10127cbbf71dc5d79e7b890d51c04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:fa8d2b09cb21ebc782ff2aba377fe9e1bd93173f6c727055185ee96b1a549940
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:b6e85268ec6043957965b9b4a1b63fe1de63375f564909bd0b770849cf6b9e28