Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11-cuda12.8-cudnn9, 2.11-cuda12.8-cudnn9-debian, 2.11-cuda12.8-cudnn9-debian13, 2.11.0-cuda12.8-cudnn9, 2.11.0-cuda12.8-cudnn9-debian, 2.11.0-cuda12.8-cudnn9-debian13

Index digest:

sha256:5e5e17a2e16578d327e62d32753c9689aa1b3072989714c2a9eac4876c9f140d

Manifest digest:

sha256:7529b8c1e560362fbce7ab29476a00dcf60d9a6f4554f82076cdf3cdcfeb8c0a

Size

2.68 GB

Last pushed

3 hours ago

Vulnerabilities

0
3
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda12.8-cudnn9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda12.8-cudnn9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:c1ef477fb08c8be2beb39da810ea63908834b8f670685f10839152777cb07419
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:39f02046d14f67f6ef97727e185c44a51d46955d345e33f57f01308d63487ad7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:499ef7e8fa1f094b3274ea250178bedded69f87186939816cb6a7f9687de11ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:134e271a9cb16ffc8ffa076f2d519524a7616113e473ef82cb3ea96441ba5a5d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:5722411b6613f26a89ce6d5f7a968db2e3cbb9d7c589480a140fd897de58d7d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:7498cea0af23c4f960c7e383a7a754048ad4846f453d573002aa38a77872fe34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:2dfdee7dbfc7bf854d699382a3704ee60865b58394a882b54bce98224e498c01
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:e97e15d613f2e57c3386dd73af4932cd1c96c20acf452fb38176819dc0cb9888
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:6a2b8beb2a2f1405c5e3cba3ac26312728a0b5e55b520056cdf5ad40c93ab581
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:241ba677cb2e0f33a76a5a10fffdcff4280db905b6753ba0d68f9a0b19c02b47
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:26e7b9cabedc222bce1e39e74eaf3f46fe4188e768b50600511dfbbb04c96aba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:c5b04da7d9f65500c2b8f688910b9168062cd559bdde41f982067fb3c7c2c1a5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:bcf3860e7f589f5cacc024f87b270e1c2efe99eea75f5f2d29d5826d1469b0ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:44ccc98a8ef486a437a49d890f123c299f3f5f8bb1ab4132623e55e4f421e116
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:a8fec4089cf4654ca8b6bf71fe86e776eba35ab6a9ca2c2a415a2b67e3fc1fbd