Repository navigation
docs: Add SECURITY.md - #63
Conversation
TRI-1935
|
TRI-1935
|
|
||
| ## Critical Security Assumptions | ||
|
|
||
| * The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting. |
There was a problem hiding this comment.
Missing tensor validation assumption The revised assumptions no longer tell callers to validate tensor buffer sizes, shapes, data types, and memory types.
Tensor stores these values without checking them, and the wrapper passes them to Triton unchanged. An embedding application that relies on the gateway assumption could miss the validation needed to avoid invalid memory access.
|
|
||
| ## Critical Security Assumptions | ||
|
|
||
| * The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting. |
There was a problem hiding this comment.
Missing trace path assumption The revised assumptions no longer say that trace output paths must remain under operator control. Trace settings accept a supplied path, and trace output opens that path directly. A gateway cannot restrict where an embedding application writes traces, so operators lose a warning against allowing request-controlled paths to overwrite files or consume disk space.
|
|
||
| **Software type:** Software component (library, backend, client or tool) used as part of a Triton Inference Server deployment. | ||
|
|
||
| **Security boundaries:** The main security boundary is between this component and the data, models and configuration it is given, and between it and the server or application that hosts it. |
There was a problem hiding this comment.
Local hook boundary omitted The new security-boundary description leaves out this repository’s
add-license hook. It runs locally, accepts file paths, and rewrites them in place, following symlinks; a network gateway does not protect that filesystem boundary. Without the trusted-working-tree assumption, hook consumers lose the warning that supplied paths can lead to changes outside the intended repository.
What does the PR do?
SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.NVIDIA/NeMo,cuda-pythonandMegatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording fromcuda-python.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)