Skip to content

docs: Add SECURITY.md - #174

Open
mc-nv wants to merge 4 commits into
mainfrom
mchornyi/TRI-1935/fix-reports
Open

mc-nv wants to merge 4 commits into
mainfrom
mchornyi/TRI-1935/fix-reports

Conversation

@mc-nv

@mc-nv mc-nv commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

What does the PR do?

  • Adds SECURITY.md: NVIDIA PSIRT reporting channels, architecture context, threat model and security assumptions for this repo.

Checklist

  • PR title reflects the change and is of format <commit_type>: <Title>
  • Changes are described in the pull request.
  • Related issues are referenced.
  • Populated github labels field
  • Added test plan and verified test passes.
  • Verified that the PR passes existing CI.
  • Verified copyright is correct on all changed files.
  • Added succinct git squash message before merging ref.
  • All template sections are filled out.
  • Optional: Additional screenshots for behavior/output changes with before/after.

Commit Type:

Check the conventional commit type
box here and add the label to the github PR.

  • build
  • ci
  • docs
  • feat
  • fix
  • perf
  • refactor
  • revert
  • style
  • test

Related PRs:

  • Same change in other repos; tracked on TRI-1935.

Where should the reviewer start?

  • SECURITY.md: threat model and assumptions sections.

Test plan:

  • Docs only; pre-commit hooks (license header, codespell) passed.

  • CI Pipeline ID:

Caveats:

  • Threat model is drawn from the code; treat as a draft for review.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Resolves: TRI-1935

@mc-nv mc-nv added the documentation Improvements or additions to documentation (docs: PRs) label Oct 5, 2026
@mc-nv mc-nv self-assigned this Oct 5, 2026
@mc-nv mc-nv added the documentation Improvements or additions to documentation (docs: PRs) label Oct 5, 2026
@mc-nv
mc-nv marked this pull request as ready for review October 5, 2026 16:38
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Adds security policy documentation.

The PR appears safe to merge, though restoring the checkpoint-loading warning would make the security guidance more useful.

Findings

  1. P2 Security Checkpoint loading warning removed ▶

Summary

The PR adds a security policy with NVIDIA vulnerability-reporting channels and a condensed threat model for the tutorials.

  • The condensed model retains general supply-chain guidance but drops the specific warning about loading externally downloaded checkpoints.

Reviews (3) · Last reviewed commit: "docs: Simplify SECURITY.md"

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md

1. **Not hardened:** Examples and modified third-party sources are for development and reference, and may omit production security controls.
2. **Vulnerable or outdated dependencies:** Bundled or referenced third-party code may contain known vulnerabilities or lag behind upstream fixes.
3. **Supply chain:** Sources and models fetched at build or run time may be tampered with or unpinned.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Checkpoint loading warning removed The revised threat model no longer explains that loading an untrusted model checkpoint can execute code. The Part 1 and Part 5 tutorials download a .pth file from Dropbox and load it with torch.load, but their guides do not warn about this risk. The generic tampering warning may leave readers unaware that they should verify the checkpoint’s provenance before running the export step. How this was verified: The tutorial download commands feed an external checkpoint to torch.load, and the revised policy omits the prior load-time execution warning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation (docs: PRs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant