Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:ad73841716330391416681aa478f3953badbef8a940e4108a6b31e8b8e28033d

Manifest digest:

sha256:95e6ff004de269e06dbbee8ce0b8ac7a1957d05b21c638be83bff9c6a0aad6ca

Size

3.03 GB

Last pushed

6 hours ago

Vulnerabilities

0
1
5
11
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:8ccc842fa0e8a7bebb16c753ebe72862e4c057ee5e384aab38c7d0855a536392
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:b1097a155bd1f5d02c312f2a9b660cecef7231c88e788702c8ae28ac56f0a0e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:05644256344f01abaf472e854137d8790d0d245e219819cf7e092b61d92153fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:87dd70e34e00e39e9e25a74d38ee08ba7a9901017a205831de36fd9cf4330f14
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:572013401ba2b030d5807b70f4debaf638c519662da058ee537c446e7e036bc3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:424029a92ae47fdd1c74a2b61f67f5412fd69c074737b776e0e8bf5c30da05ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:5bad8684b62fcc2565272be659a66eee20abf2190e9a08f3f14c926917552d66
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:4c83cf30ad039242e046eda1bb79cc8d1c6f1d25f751a8d08b8c022396e8a4f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:8d8766e11a4f9b84e3f8e6a793853ff29c6a0f68d4840b4429c6279d5fb3e32c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:244d70645e943b75b07a9123233b7867e873173aa05c2330b0e330f0bf12c71c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:2c96da0a19b63a0150121c3552ce48df4324ba493228633f34496418f69f3c3d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:07b22732c852030f94356a118f0a3afa518d94278daf100aa5a17ef863722167
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:41ff2ce04759743222493fe8fbf4e9743a294eca021a410df9059aaa038a1c37
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:fc223839f50b49a97d066f434cf8a1498a1d159abbddbf08c3f2c0f2f46702bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:14a250078fd964e1cca5305dbe2e1562a49971f3033f15ea045a7efc5c7f1993