Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian-dev, 2.11.0-cuda12.9-cudnn9-python3.12-debian13-dev

Index digest:

sha256:0c86d27889bad4198b05e2dd8e1bfee4d0670133137f46a164f96be2b028fec8

Manifest digest:

sha256:187e6b5ecf1dfa2e84ce146486c69ab9af0e38a327f4ec9a4f8828d5b84215cc

Size

6.09 GB

Last pushed

4 hours ago

Vulnerabilities

0
0
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:6008bc54f0290c653b96f9d39cb906b176d75a5777ea90785cb44748ee01e459
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:700526860e6904e359b57918802b2ea9b4187c319469865727293d3d31fb2554
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:0ea699db109b83bc335581ed4ae0d8d0fc5da53a4e0b1945aeebbc0fe7d86bfd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:69a8f3e4ce22bf8d0c73d1decd36e3de4b2d26a45d3bdb51bb37f38479217660
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:8449fd27105aed004b98573e5536c770bb383f26fd601ffc900e130ad6cf3e60
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:37ecbfb083f43b5f5ce604723fbb46d5500f0c49aa1a11cb2a5b31e40d5311f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:66a971a26a7686181604a228b66366338a7e51cada232495873cabe8452bc083
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:0f221b5d588f753ded35390bd3bbfc17e3dc4d1a70a0df693bcf9b7874990abb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:7e72d284f052c637652a1378c01dc9e744bceba5132d99afc247f15935789549
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:43ce04bc9657423abaa5e0e028d5a4b911313d47dd194b6aebc3f9951932c7d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:4cf9727df76b487d22b38dc8b8f548f73fd937ab784c636953c8fc519b4e9033
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:75ec4f6a7f10f603b7a3742114dc64feb2246cc66282683f3930415a4d04b3e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:62d8fbbd4fd3c181ef7db0703bfde732beeae9cfb484558cc30bb951b143ee5c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:6d2068b8a8b44e1abe2e94d569ae79349926711b47fafb1ff42315e62cee4374