Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:1b2915b8bb61c0c975a4b6b313c2fb4865f1fb5bddbf591051faa98ec94fcc6d

Manifest digest:

sha256:8e9cc6103bfc02b92d5d7f5ed970c4b17f7d7ec44123a8858d0721c217ff3bc0

Size

3.03 GB

Last pushed

11 hours ago

Vulnerabilities

0
3
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:32f3e0e1f898462817416fb772702da655d19508bc39f817c00f089544c0b540
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:5871a5222f2b7a78ad4a2478b52464aa3a837318c83a65919ce7a66c940d8f50
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:93741c4d2eac554fcb36d6551ca4760fb77cc6a4089366e8ef3b64037c809f25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:01b674d96efe1112cf0d29970718bdcf0fbf18819deead1702ebdd99ef99357b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:c3c79dadd5ff575a89ff54ef8fb50c3070498ab5acde461091599c33e167f075
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:e9d0d8e3eacdcd2d48db256b3ff028b86a0d972cb8d676afee836a363b356815
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:dec258f059fd0d42fed4278182d9cec0ddc7926597751b2509c45eadc37ec387
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:e87a4b2b60ddd659d6ab64400a908c9cfb673f36f80103ea6b346108ea82a532
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:0f8f6db844126cbfc148643b39301183a90fbeae7c42423a98f565021063db22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:6a41d46e3b2fc2077ebf7f0e7f49699d7b9c3eb18202d4197e84f54230fff9ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:b8bd0a15bd5c61214b2e798f9a0760c474feb00a51a063b4ca7ef52ed9705357
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:12645c58c42e2c4a411c9bf0ac0dac8633a691361a1a3e7dd0c4b1d8b9290657
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:257623332e08ffae2d9550d7a379e57ad4bcdf13e7b9afb8c0bf254f9f0db23e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:84737855887ce20ebdfab9d038592179d6de5228bdcb542a2338ebe6858b9725
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:8ed717516820b6dd20c44502de189f81383db998021b0c8be31f2c7de881f0b0