Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9-debian-dev, 2.11-cuda12.8-cudnn9-debian13-dev, 2.11-cuda12.8-cudnn9-dev, 2.11.0-cuda12.8-cudnn9-debian-dev, 2.11.0-cuda12.8-cudnn9-debian13-dev, 2.11.0-cuda12.8-cudnn9-dev

Index digest:

sha256:7e26e893cdc3633918823ba07ac8140c2e51d37890962216010cd1f3c420a2ed

Manifest digest:

sha256:8964c29e5052b765af8efef2a9e0c945d76d4f6547f6bb75242d7c26927cee60

Size

5.50 GB

Last pushed

11 hours ago

Vulnerabilities

0
2
5
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:b4ecd22e0cc8cdf47ad3c2e4b108fa94eb61ed2cfa73830a7b63fb3837e92fb6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:8ba0747154aeff25cb6fc1bc35c8857e6baae24ff7b4006d0c54b2c55cee41ad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:8c8ae8e602b83e401881ea492843a9150d22821f700a8aa161d62d88d2ae288d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:2d672a009a1fd412c572fe04a734eb33a066689c7d14ea665f0d2ff166e7a401
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:13a057bd7716aaf919730c71b0db4be84dd4663246bba6ffe6718ccf42d12471
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:a8139d066813e6e10e5b395b73ccec29cdb4055bf4a9b3dc7a75f5ff0a085ec2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:7a11b44ee898cfa324248fead99f1e7cdcd46dca94198a429fb9432c4fcc4e98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:51a85df7c3c45b24881165a00057687f518f44b036a331287685fccb76254a73
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:fbe8b83c8f2923ac19f79f259ebce6568e939cb25321c6c4497a4ba6b1fb5158
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:9c3df86528b65d0687f70bda63f7714bea179dc98bfc60fcd09305d9ec97f8b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:4519cef326e902fca05d0d47066c45480e6a6a994c84197204a2334e2913f978
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:b289b7ce104c44bdcb3e643c490419a3a2c4c0b62031f1cc7e617daa26b8221f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:01033b6ee321f728754f42012476ef323e852acef1b5fbc7eb41381cf2ba1d9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:b47e682d92eb87089019bb12f6b8f0f727c1f40b2d35159cbd7d91be6d579d30