Conversation
TRI-1935
|
|
|
||
| 1. **Not hardened:** Examples and modified third-party sources are for development and reference, and may omit production security controls. | ||
| 2. **Vulnerable or outdated dependencies:** Bundled or referenced third-party code may contain known vulnerabilities or lag behind upstream fixes. | ||
| 3. **Supply chain:** Sources and models fetched at build or run time may be tampered with or unpinned. |
There was a problem hiding this comment.
Checkpoint loading warning removed The revised threat model no longer explains that loading an untrusted model checkpoint can execute code. The Part 1 and Part 5 tutorials download a
.pth file from Dropbox and load it with torch.load, but their guides do not warn about this risk. The generic tampering warning may leave readers unaware that they should verify the checkpoint’s provenance before running the export step. How this was verified: The tutorial download commands feed an external checkpoint to torch.load, and the revised policy omits the prior load-time execution warning.
What does the PR do?
SECURITY.md: NVIDIA PSIRT reporting channels, architecture context, threat model and security assumptions for this repo.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md: threat model and assumptions sections.Test plan:
Docs only; pre-commit hooks (license header, codespell) passed.
CI Pipeline ID:
Caveats:
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)