Skip to content

docs: Adopt current NVIDIA SECURITY.md template - #8997

Merged
mc-nv merged 7 commits into
mainfrom
mchornyi/TRI-1935/fix-reports
Oct 6, 2026
Merged

mc-nv merged 7 commits into
mainfrom
mchornyi/TRI-1935/fix-reports

Conversation

@mc-nv

@mc-nv mc-nv commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What does the PR do?

  • Replaces the SECURITY.md body with NVIDIA's current standard template, already used in NVIDIA/NeMo, cuda-python, Megatron-LM and nvidia-container-toolkit. This repo was still on the older block.
  • Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording from cuda-python, since Triton repos are mirrored to internal GitLab.
  • Adds: do-not-report-publicly guidance, the coordinated disclosure statement with PSIRT policies link, and the Product Security portal link.
  • Applied across all Triton repositories.

Checklist

  • PR title reflects the change and is of format <commit_type>: <Title>
  • Changes are described in the pull request.
  • Related issues are referenced.
  • Populated github labels field
  • Added test plan and verified test passes.
  • Verified that the PR passes existing CI.
  • Verified copyright is correct on all changed files.
  • Added succinct git squash message before merging ref.
  • All template sections are filled out.
  • Optional: Additional screenshots for behavior/output changes with before/after.

Commit Type:

Check the conventional commit type
box here and add the label to the github PR.

  • build
  • ci
  • docs
  • feat
  • fix
  • perf
  • refactor
  • revert
  • style
  • test

Related PRs:

  • The same template is applied across the other Triton repositories; tracked on TRI-1935.

Where should the reviewer start?

  • SECURITY.md — compare against NVIDIA/NeMo/SECURITY.md for the canonical wording.

Test plan:

  • Documentation only. Pre-commit, CodeQL and Greptile checks pass.

  • CI Pipeline ID:

Caveats:

  • NVIDIA ships two variants of the warning sentence: NVIDIA/NeMo says "through GitHub", NVIDIA/cuda-python says "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both hosts.
  • The previous block's line **OEM Partners should contact their NVIDIA Customer Program Manager** is not present in NVIDIA's current template and is therefore dropped. Flagging in case it should be retained for NVIDIA AI Enterprise customers.
  • The template's PGP wording is "we encourage you" rather than the previous "please encrypt it". Kept as-is for template fidelity; see the review thread on that line.

Background

Raised by an AIVO asset review (securityportal.nvidia.com/aivo/assets) that flagged repositories without a SECURITY.md. This repository already had one, so the change here is to bring it onto NVIDIA's current template rather than to add a missing file.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Resolves: TRI-1935

@mc-nv mc-nv added the Documentation Improvements or additions to documentation (docs: PRs) label Oct 5, 2026
@mc-nv mc-nv self-assigned this Oct 5, 2026
@mc-nv mc-nv added the Documentation Improvements or additions to documentation (docs: PRs) label Oct 5, 2026
@mc-nv
mc-nv marked this pull request as ready for review October 5, 2026 16:38
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Updates security reporting documentation to current template.

The PR appears safe to merge, though the optional encryption wording leaves a confidentiality concern for emailed reports.

Findings

  1. P2 Security Email encryption is optional ▶

Summary

The PR replaces the repository’s security-reporting instructions with NVIDIA’s current template.

  • It directs vulnerability reports away from public GitHub/GitLab discussions and adds PSIRT policy and Product Security links.
  • The revised email instructions make PGP encryption optional despite requesting sensitive vulnerability details.

Reviews (4) · Last reviewed commit: "docs: Adopt current NVIDIA SECURITY.md t..."

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@mc-nv

mc-nv commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Closing: SECURITY.md already exists in this repository with NVIDIA's standard reporting text, so no change is needed here. Tracked in TRI-1935.

@mc-nv mc-nv closed this Oct 5, 2026
@mc-nv mc-nv reopened this Oct 5, 2026
@mc-nv mc-nv changed the title docs: Update SECURITY.md docs: Adopt current NVIDIA SECURITY.md template Oct 5, 2026
Comment thread SECURITY.md
@mc-nv
mc-nv merged commit 920fc89 into main Oct 6, 2026
4 checks passed
@mc-nv
mc-nv deleted the mchornyi/TRI-1935/fix-reports branch October 6, 2026 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Documentation Improvements or additions to documentation (docs: PRs)

Development

Successfully merging this pull request may close these issues.

2 participants