Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:c2d20575420464d0f76d1e989ebde65acd7e0601da6eae05c36b68022413cbb1

Manifest digest:

sha256:36eadd3f46162e3662f85b0104341ddd3731bb90e81e731e9fc07efe2361996d

Size

3.03 GB

Last pushed

12 hours ago

Vulnerabilities

0
2
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:0494ce4a1b54d63807307474bf73fd678eda3304611d19aa49c7ff32821a4082
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:8fe2479616ffeeea4ac794d300f01f6e11f13c7f5f1a9af5c2f730b2eaf3b2a8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:cd4ec8ee3cef99c518a452fae4120000f3d6a3bdea792989f18409b043e30d5a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:4a0ce17fb77254f740e91eee40f75e07832c5058935b9426b2a5ef99ecd79c86
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:806bfc115ec44e8480380170b8f78632a687ccee585eabf27b8cef5887539241
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:72e41eb9bb302dc8993b6f86dd2a5c1aa3e869c3295a27fe1d4a5f2c8b0e70d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:a7948bbad247c7037427b12b8e948949ad5d35a0c9c0ccb9521f205dac9ca8c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:db8b2e753b332fa6b6a7d0089081a528b6480df63ea356baa6ca08ba04cca3ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:369c60f5b601f29f1f5188e60a3a618a8f8e8f14f8d888522070e50d064ca5fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:4a294c6cac4681df07d09db51dc8376ce4baeee48244a97d64cc1a7cf987c0cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:fe20de0a4123285b2da8c77c299a36db1acca6722cabb1a39cb768ad05334c0c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:10820528eef632f52a7e28f1ef88dd2bbdd6a3aae89fac40902cc01181b2d452
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:9ee0bf7c68c9ec92bcc5f84ff8edca95e6525dcf693779494ccb6f2d79c46546
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:d09ee83d92c8fea9a731fda71e22b8aabfecd2f7665bd9e5b2e0bfcb8224746a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:0816e213ebd9e12ff4735e54fd5d76796cc57b2aeb13ee564b0a6d2fc840d786