Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:294f586a4aba58322827416c4914fca17c79c0ab9050ec0a1c10fc91f29d9c40

Manifest digest:

sha256:bae04c3e3dffdcefdba37944ac6082a1f722e59d43ea4e9aa6e41d39dc8f7856

Size

3.03 GB

Last pushed

11 hours ago

Vulnerabilities

0
0
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:754d316145d27c596175ba167df967c63899e3f895058d6a284cf6f311536ace
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:412aa3b30dd76f7323a8dbdee0e430f750339a6ea986738a38717118177d1efe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:8c6b16217649d5fe824fcd50e666e85f0a50ca7a18a7809df8e6bb6c00e04a3d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:ab851f858cdd8c6ccc019ea9a49a7eeb055e254b188b20e024880191a90bb547
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:cc08cb7f43fee8fa01edabc8e692c4c7aa03b1b4578c08582ffd6d9e6801bf0f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:5586f39f908d053aac939faad610ec9df31fcf7a0efd58fd3ae2dc833b504c20
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:8946518bd1f1a8d17a24786541a666ede1f1a11c08428b9a16656ad11f183033
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:6dfe5c161cbd7eb0401d20f7e3581f80306343390b4784531cf07ee8b8a71440
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:910fbea2173f80f46bb2643cb6538ce647d05e1fe4e3c3ba9b445e018412552f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:57b5fc13e2a7a397ce9b48b90b822bc69f337425a4b1d253d3465b3adc8b882d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:78c64d65dc8ea29da75863b3c608ab362b054a2da50f6a2d7b9fccccf9bd8116
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:b4e24878b36bf2bab1789e57464b9c1ac64df414c6153d2d64b9b39a93a6ef43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:45c6fe291057b4c9eb256724a44afcb9c296a1efc34b2dfdc5728738bfea3c71
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:1f1ed4a64af98d22e2edfd380772bb6a31f308fc22957a4f48d5b12b41b20192
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:8cfa98b8afe99c5d2f4e396d5cf3d9ad669dfe99565c6ebc524592152fb9221e