Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9-debian-dev, 2.11-cuda12.8-cudnn9-debian13-dev, 2.11-cuda12.8-cudnn9-dev, 2.11.0-cuda12.8-cudnn9-debian-dev, 2.11.0-cuda12.8-cudnn9-debian13-dev, 2.11.0-cuda12.8-cudnn9-dev

Index digest:

sha256:981b5e2fbc62005cb607a0351ae341d47fdad6cda442ef497471d520f8fb81cb

Manifest digest:

sha256:0e8b923c8cd962bc40ed665d2d6f7a6e87eaef9cbf24b96fac6e350c3ae78d8b

Size

5.50 GB

Last pushed

20 hours ago

Vulnerabilities

0
2
5
12
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:d648f53ea90a9789d5df5264e233352474eecf41d495fee9f746ef53aeb66f8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:5e096ddc8ed06fd3e4de88ba811aa221c9d21601fa8a68a91fca84ca3d27557f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:c99eb2d90dee30fbef0401976399d00c2db7d12070a2b3835cb98a91d016df8b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:4b37cf6e6b92991dfdb3040bb2d877f198dd4c045ca3b9b6ead905d403364632
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:6b064865749288d695c4f94e3da1544f59871bd55a6cc087ad988997d2d634a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:5491a03345a402fa9b473ffd0093f586f495e43cffa985689b38682b6e1ec8fd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:76aee2aa834a8807d672188040c563c38892e58fc3a409591efa296d2ae79972
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:7e296d928eda9afef0c972c0a44f6ced124fa37a60dbfea90485019752e9a08b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:188dc9dbbd216c11ce77cadaed85e5d220695e63af1aca3aa6f949b3b0b2f8dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:e3df1bf3397e3975d3a61ac00d3a58b9b95e77b5bcf4ec5abb3984c43fa0809f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:f058384bde2ea918213d5d7c05df86fa52cf577dbad9c7d67b141013792ea2bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:57a5aaa69dcb718a10e20f1623922c7886643a94979254af8e114d749f757b8a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:77c15c77eae04a4a91736a69bbc23fde2036f50082e4cefa8ca72738baa7d5dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:536f0d36381ec83b4edaae4b808e48e776af6c18c856803aa5b96a1ffaef35b3