Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9-debian-dev, 2.11-cuda12.8-cudnn9-debian13-dev, 2.11-cuda12.8-cudnn9-dev, 2.11.0-cuda12.8-cudnn9-debian-dev, 2.11.0-cuda12.8-cudnn9-debian13-dev, 2.11.0-cuda12.8-cudnn9-dev

Index digest:

sha256:8c1db3ad6f017f82a804667d8ffbf8f55a47291ed8d9fde1fc4fc16633ecd5ce

Manifest digest:

sha256:6f4e06eed5019cd8c0275c70c7392a440d7c55ee917ba0631b2bdc2b18e5caee

Size

5.50 GB

Last pushed

17 hours ago

Vulnerabilities

0
1
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:689fe995b77e2cb6c368edf313cda0acd5993029b07b83343bdfa51c780d24cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:5c0de96cf06587f587502096ae8477263ac9e75e0e48f578cf64cb94c3f16b09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:5a49279ede300823d6ac904f58dccb1efe8f4974265356a248e71246e95089ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:5d673d9b8ddff44c6b7fccade4915a9e1137e9fa932cdc1db9338df40f89be0d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:7693b48521dd4006c643b407884b3d8987609c0b50e0fb58157ef58f3a51182f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:c667547b1e380b83f6f34b6b7b36549591812820dddc9c05c214bed3181e68bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:b53d79bce72e34b0f7b313b3737430f5747cf0c0dda3451c8c70852d33110730
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:3b1c98535f0f5e4737eeb7a9164a1a12d969cf212344b9f7043f48ce48839e23
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:d5b6fea8eaa0ea6a2810da0a772206d13110d5601701b8aa7ea06a475b572185
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:5d19da45b28fd81e03f73298dafc4a295fb1f26a3c5bbc76c719259061365b57
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:34f32aa01abdde1857caed2d5ea89e5d6f964b5b91c1245a87e3084580051b83
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:c680fb27dc4644b0a4f3273e8c744488c90d750c889862841544bcb72b518c8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:3d930589f4ba5a1a6220fd2d088366a1313bf14c29164da49f5fe0e63fa2ead6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:f5ec914f2cc4eb2bded284ae1f88306c68d5f313fabd9ceb77f0682fcbae9777