Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian-dev, 2.11.0-cuda12.9-cudnn9-python3.12-debian13-dev

Index digest:

sha256:a3a39bf766702569b969ae955d37103b027440c5f3fd2998d9e620d68af65d1b

Manifest digest:

sha256:c74985cc0b9296e95bd573abc461f8a03bea4b68d5fb75c79833d60d3e702194

Size

6.09 GB

Last pushed

9 hours ago

Vulnerabilities

0
4
7
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:7a2679b0073a9449ecd91e78e56f3475e9f9857cda7f850143765a21c7376f31
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:3a9ff645002fce6c2422753977cd3b65612910a26ca3cb55a225daf7b5ecff5b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:02b18f3b5acf17f6d028c49877d44ebc9fce68217bb0729234c1ae435ecfd05c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:2be3cb3633c6a28b20a3705b9d3c3439a36d24bb0a3a5ff502945d104e089fab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:797e1470d1552659404649228cc8f1bc0c38b2f475f7d43986d27ee2be8c491f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:58ccd76a382905fc3542274f355c101df3af693a682f9721c5a8464c562783e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:7bb03110ac705b38d6f0424e6dc9d2c7da00626baaafa23e6a0fc80044b03598
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:1c38d9a976f89c0395a44f6432ac84112ad1f560505cf0fb434e5c870e97d4f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:76257b8f129796ebe346e3587bde2cb337546815f9e380da37161541e6a78e4b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:206e12ae6a4b79a10fefd771a1dcf8f14197962340a66336b77f7573d5fdc793
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:4a1a3c0413c5ba24d2e7084c262664e86e97bfbdfaea5a3f63d86ebd8b7e086b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:53ab00a992d72f5654f9758954c36a7d14b0fe212450fcff3e5b6d2ed5722003
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:530d417f6e88abc38237ec675b3a14f79a2b46ba10e6e106bda6b0421a53183e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:4bdbcf835a7a9f0009cc642ddcabee571f2d5ec22b433ca5bf862d7dd5847f57