Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:034de89cc00e3f8ea5ea707b07349535edb9b1319b914d8371d984bf7f6fd495

Manifest digest:

sha256:adcca59298f1f67c896912964be29be02178fadf37fbd5037215481abfdd612f

Size

3.03 GB

Last pushed

14 hours ago

Vulnerabilities

0
3
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:cd8a0f178ea1767e13a96ede4763980229e207ade60bd5054cb1e14969ef2aa4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:5d686ba45730f61ca1b3ee10f047945a706cf9677d41648eb2d7bc939c0627fc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:cf2a256482f85a4349c53dee0e269a8e9b2c190489646779cf14421afb8ce2ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:df22ab658f80342c5714096ee8be316fd896c5d469fa8e138fd5bcda88532e07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:1d9ed8be06a361064ffc30ff6d0637ea07b9a2cfa588834cfe2c146c765faaec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:0b4c4a165577dccf5019c8021b330b463f7bd8ea9d04037841bb9a02cbfa7a95
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:7dc1d34d9a06d2b3bf817b9611006a26f133abb3b20a278650bac6d01da1e006
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:345c776a7a3d285c502075617fc331993e1e04241e7f456eb04a288e2c8627d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:215927a3dcc4f8d8d40bf7d1b5f71cc2e9694050b7ab5f0ddef77ad5bf0cc3e0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:f32219252cd6970f0c830bfc402e7fa0c9a0ff947d4e6b148afcf9721b25900d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:59b562ac583cb3e9b27774217b8970471e96cb338ff2e232788c5e8e72e711f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:e1412cda4e665c89c3bada1de3d2a2bcbb468ec51f51d5e8eec551c0f842154c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:72c82316b7df13b89247a306c4891c6ed27c0f539b79fedea72751b35156c991
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:1fbd80073d3148f9c9814f305d54610d8b61fba6e806eae97efb8153e05e6e32
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:76792f11c33a1d4ed0387aac86f20593d5dc48b4aa2781b95d0e3387ded26012