Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:9d4ddcaaffd69ab1a3a57201030101aaccb01d8b8e8e58617bb2c60a650b21d8

Manifest digest:

sha256:8dbfaa858503650416c2b565e17a2f54d0d8dbebd975ba273786fab03d0a6cb3

Size

3.03 GB

Last pushed

15 hours ago

Vulnerabilities

0
4
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:18770b8926a9954b1955cfd2131104dbcfdddc0f642e0902b99d711dd72b1bc9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:a4e93cf6d0a6a0973f094462ad3ce7e3d02dc142b4c6f2d483499e5a394ab99b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:896e95536b39e93c9eb5d45e012df7d7e514da55401c09e41124b258d1abb51e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:f7190009e29d21f82a95cf707abb2f719e340afc65d6daddcbae5a475c47ff9f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:a93f3deef424781c0f01af0f13c8526209696e34ee477af0c0b90c06dbf90b64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:7f3f9351b479818b30cb95885236fe0fb02f9094aa92883144212f9accc8e0b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:4ff6906de2aabf9968021f8cdf520ccbb9ca3f4a8f61904f29f54f8fab2153f3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:d0955d79ea4e29019376c342c4c55b3e1da81847af3e30bad2ffba9e7a396030
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:908a9a3fcc92c316239f4df271e99123ce128f050eca923aec36259d0d7c8395
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:69a2aef0c4ed9eb74f98deacd276ff4c209ddfb88157d2872a19d8b0d403329b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:ab6162d843d367a77a8a6a072ee88f46069c2b6e92decd373202255111877c73
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:78c91397a5285add6c8d54673da794f944e20b31f65ef1cd48b10bc33bb8d2a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:b724d54b6ec6f517d0e98f1433cf213fbe4dad8400099bb763eb610a2c39e109
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:f15f648930ff99536c78c2496e5a71cd3009089bdaf88c3a8ad3270b3a0e75fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:347e82e692731d5ca3971b8c3848757eae2dc5016f7670d1bac93a71bd2f3beb