Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian-dev, 2.11.0-cuda12.9-cudnn9-python3.12-debian13-dev

Index digest:

sha256:88378221aef4198c88871333b7a1b2eb53a31c7f435a666c1e06be61a8054dc9

Manifest digest:

sha256:afa67ed346299e50bd705d2d9fe853768f3ff866384fdc640aedb7c376dc24d4

Size

6.09 GB

Last pushed

8 hours ago

Vulnerabilities

0
3
7
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:f2c6d74ca708bc95a008d376a7f92ca17bf304125fe19b73e623368fbc5c4584
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:6cd864d8e215926d12ade1e49f30a1606f2368cce592e9208791620aa032ee6a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:eabf4da983958bbb469a3af31d43ae1515f81281608a9764728d3d41cb3b436b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:65101bd1801c34f09587657acbc11ab303fa26389dc9cf04eb3ea230aae7cb58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:27d9bc50310f5e8f6bf9adae3f27f2cfb72db872014987ad3cad53e86dfa7f78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:94fe7bc1924040561961d2b5da3f508713d46ae436e84483d937db18fb208961
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:5a62790b650d4dbfb55a889d2bdd939fcc5c4a91e29f29ba44d2dda3068f1d74
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:d8935dd0bcc632fbd94aa1a8b7ae279f11e91cbcbb50ac9119f74f6c76a431fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:8e6d4a157054554d075a7c29bae8acb11793e8572604edead6019c2c0ed95e6b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:ed68d1f34b49079e6d461cfaa771c647fdee0cb5a3327b4019282e038b1e25c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:8d2fc524d6727453a39283c7995595715eb0a73035b38450069e6b9932d34623
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:a73b2ee3d8e9379c3dbbda4c2657788670f88c5da7d80065d0d105a6275d6e02
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:5366946d1c61bfa72eaa8cdfa666e5747f92b2fd496f0228231ad6527cfbfebe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:9fc58d4acad33f6f687eb117f06b689727e5094d8e980ad3f9479c9dee097cdb