Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9-debian-dev, 2.11-cuda12.8-cudnn9-debian13-dev, 2.11-cuda12.8-cudnn9-dev, 2.11.0-cuda12.8-cudnn9-debian-dev, 2.11.0-cuda12.8-cudnn9-debian13-dev, 2.11.0-cuda12.8-cudnn9-dev

Index digest:

sha256:1a4728e2b7bf8207a74df5221bfb4a80dc0415cd89b2eb6adf5c5062f5233afb

Manifest digest:

sha256:3fef193cb0808d1dbcd590770ede02d50050203451f9719bd02e5d1ced7341a2

Size

5.50 GB

Last pushed

1 day ago

Vulnerabilities

0
2
5
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:567f6953961bea5125baf0c23ed645cfc22a92b97a0bea214e44856e697b6b52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:eb5db76e6f7abdfad594c168f6d6d0ec2b6841f711e8d5fd7063dff1d1378a5f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:c4b8bf286717c9a8bdf00c35b25538a6308afbfc7dce54795cb341a64e005200
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:58ac069c3bfacccc8ec9944e66736266a9b9a28fe73631bf7b12d7d9a0493a95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:bdd8ea3057bbb4dd67ac57508e607528257cbb5c5617f2799cfd9952f441f3bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:0c5fb9da6877fdfd310cc6a3181220d5ee026d338b723f14b3ed37e47ce0237c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:9c355ea6960cab7548faebd4c29a400cdff3116b4c4cb9eff1ad72e1759fe085
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:b5654308b9a38eeef127d9e17a452ac191058491a9bce86c532d9a2dfaa5c72a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:adbe59ffcf7e8db64aec27437593a2183b6508b2675caa508e3b0e5c0426cf58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:d6f4f4e06092a02105c9e0c023c64541b4877741a39abd578317c548811205df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:c33d7def432b189b245f5af1f4a2acd647af18b90801e3c711c3f1d14f55cf5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:c377b8caa38029cbe994d7e8d0cbcaa9c5719863f3b204e456d2aaf866f99927
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:c0fa1c6443c5867e77ed8f98c5bec8a3bdd583db3c21213b5ef80a5902bb8a9c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:f62354e41c5aa1678e23cc0b1a26636f49cdd215121be035b25711816561ec6d