Sign inSign up
PyTorch

dhi.io/pytorch

PyTorch 2.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.11-cuda13.0-cudnn9-debian-dev, 2.11-cuda13.0-cudnn9-debian13-dev, 2.11-cuda13.0-cudnn9-dev, 2.11.0-cuda13.0-cudnn9-debian-dev, 2.11.0-cuda13.0-cudnn9-debian13-dev, 2.11.0-cuda13.0-cudnn9-dev

Index digest:

sha256:268df2e8b192ada355810a9ed25839e3b58ffe3dddd0ddca363e6966117ec9c7

Manifest digest:

sha256:b63b1d2852895e67acaccaaa099f47525cd70f86f86ae488aa3217df093316df

Size

3.59 GB

Last pushed

59 minutes ago

Vulnerabilities

0
2
5
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pytorch:2.11-cuda13.0-cudnn9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pytorch:2.11-cuda13.0-cudnn9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pytorch@sha256:6b311a9009c1f87e3ffee1d08f9d2e51dd51ae589c551357605e934529813e61
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pytorch@sha256:d42b64c8a60b65be1d99d7b90415adbad0c861d2216ed4290d05f6e15cc1e712
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pytorch@sha256:ddb3cd703077e635e14a1725b46aa7f7bc1debb255c5c7fa93150b679dddaa75
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pytorch@sha256:e52f82dace423572c7f2f867061efc479d7fed7e7c11cb9fe05d556b8ccddb45
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pytorch@sha256:1538d1181c8eb0f8f3889ab8c2d58fb5adcd0a55f86fc0d3519f2f649f582e5c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pytorch@sha256:0911cb58481943af7d2c5728ce77e0f3f3468986639144b7e65bfa7286e48e6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pytorch@sha256:41f45a4666a5e0d6c2da5ac3a66fff861c7191d0ebf5c25ad3e61927b298fc76
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pytorch@sha256:3db28c75f8304d85e749bfb4dca65b1541956c91f02bfeef4e1ed8c5010757fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pytorch@sha256:afdb8aa9da230761fdb9b86340ca0c0a05ee24c209c719360df612186a408d39
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pytorch@sha256:0fd349eb6d5945bd01e79faaab3d6584dce0d82f7f3b940bf286fdd5adb3cc0d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pytorch@sha256:0469f026963d87f57afd987c4c128845e3ebae5383fe6dd0175ded31623f6e3f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pytorch@sha256:c07420bb30913e377b5b8a58d8486524902bbe6f1ea30dcf501a8377fbcdbe5f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pytorch@sha256:a5cdae120b97ddc3eb682c15d7915c8910e5b314f921e5bbfaec8d05f71d65b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pytorch@sha256:3200cbf54306a1bcce3bfbf671e1997bb35e5fc633316a7ab5ca7ac9e492af48
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pytorch@sha256:bdc26c8fd2a36e07d8dcbc48cf9ce7e6f1f82c51b12a46b6b0d99fbc79c3b541