Repository navigation
docs: Add SECURITY.md - #174
Conversation
TRI-1935
|
|
|
||
| 1. **Not hardened:** Examples and modified third-party sources are for development and reference, and may omit production security controls. | ||
| 2. **Vulnerable or outdated dependencies:** Bundled or referenced third-party code may contain known vulnerabilities or lag behind upstream fixes. | ||
| 3. **Supply chain:** Sources and models fetched at build or run time may be tampered with or unpinned. |
There was a problem hiding this comment.
Checkpoint loading warning removed The revised threat model no longer explains that loading an untrusted model checkpoint can execute code. The Part 1 and Part 5 tutorials download a
.pth file from Dropbox and load it with torch.load, but their guides do not warn about this risk. The generic tampering warning may leave readers unaware that they should verify the checkpoint’s provenance before running the export step. How this was verified: The tutorial download commands feed an external checkpoint to torch.load, and the revised policy omits the prior load-time execution warning.
What does the PR do?
SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.NVIDIA/NeMo,cuda-pythonandMegatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording fromcuda-python.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)