Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x

CIS
linux/amd64
debian 13
Tags:

2.11.0-cuda12.9-cudnn9-python3.12-debian, 2.11.0-cuda12.9-cudnn9-python3.12-debian13

Index digest:

sha256:44d5aef730d55507357f0c29b6aebb4ebe4b66329a4fdfae6aef0729f682dfb0

Manifest digest:

sha256:cb433d4940515f3b6f533063226df98dacc4c6bcbd0978e7abc59833107a2595

Size

3.03 GB

Last pushed

9 hours ago

Vulnerabilities

0
0
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11.0-cuda12.9-cudnn9-python3.12-debian --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:1a52eb36ed5d1bac5dc6966a80ededdf45fc8d65164e31723de49bcb946d22b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:f6efc12b2ac31268ec793d5f80aeced1a200519ca8608ee1b2776a8ee2e1211c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:ef0180115dd504f506c99e8fe684df6afa1457ccb6788975f77ee4b1f341a9f2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:f3a1d97cacc60c97f7a00c8b69aa421e5b2f4d3a666e84e529f942bc54d500a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:bf94699dc8ce612ffafc424ee0bb6d0d49fb4d3d77343cfb44bf1430b6803e26
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:0f4cc8453cebd32d3fc07f7c6867158fe133e9a3a171ee1c3c4c4768a6d3dcf1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:15cc36e1876d8251bafe7a69c0eb077fc39a8e403a8c0899d8ac521885595e89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:e34fa33fc577e142572060c17f0342fff280c3c5b61ac471b6afb678f471527c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:781148b0b19d7cfaac4d4bf187b737c47596f836945aa81223a543edcb55842b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:c33ba4acbc7c3a04b60eba1ab7dcf2cd14c7d2f5f3c38b1784a91b8bdc65e664
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:ec00667f5a160353b01886783c71d646834f915d148cd3ccbf141393cf90c105
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:40849f06394a43b63c6d37407ee54b5c662116c81638ed5460c67d23252633f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:b530a04e75f25c452aa2c729687c495f17a9145953eec59d4be8fe7c481c8e51
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:ff5112b0da5ba949af1cd0206d9bed839c385d899f9829658faf04322624e10a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:625ef0134afeb6d4ec9805520404abc672217fc5d05c15132b079965d721a0df