Skip to content

docs: Add SECURITY.md - #18

Merged
mc-nv merged 6 commits into
mainfrom
mchornyi/TRI-1935/fix-reports
Oct 6, 2026
Merged

mc-nv merged 6 commits into
mainfrom
mchornyi/TRI-1935/fix-reports

Conversation

@mc-nv

@mc-nv mc-nv commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

What does the PR do?

  • Adds SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.
  • Uses NVIDIA's current standard template, as in NVIDIA/NeMo, cuda-python and Megatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording from cuda-python.
  • Reporting policy only: no threat model or architecture section.
  • Applied across all Triton repositories.

Checklist

  • PR title reflects the change and is of format <commit_type>: <Title>
  • Changes are described in the pull request.
  • Related issues are referenced.
  • Populated github labels field
  • Added test plan and verified test passes.
  • Verified that the PR passes existing CI.
  • Verified copyright is correct on all changed files.
  • Added succinct git squash message before merging ref.
  • All template sections are filled out.
  • Optional: Additional screenshots for behavior/output changes with before/after.

Commit Type:

Check the conventional commit type
box here and add the label to the github PR.

  • build
  • ci
  • docs
  • feat
  • fix
  • perf
  • refactor
  • revert
  • style
  • test

Related PRs:

Where should the reviewer start?

  • SECURITY.md — compare against NVIDIA/NeMo/SECURITY.md for the canonical wording.

Test plan:

  • Documentation only; no code paths affected.

  • CI Pipeline ID:

Caveats:

  • NVIDIA ships two variants of the warning sentence: NVIDIA/NeMo says "through GitHub", NVIDIA/cuda-python says "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.
  • The template's PGP wording is "we encourage you" rather than a hard requirement. Kept as-is for template fidelity; raised on docs: Adopt current NVIDIA SECURITY.md template server#8997.

Background

An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Resolves: TRI-1935

@mc-nv mc-nv added the documentation Improvements or additions to documentation (docs: PRs) label Oct 3, 2026
@mc-nv mc-nv self-assigned this Oct 3, 2026
@mc-nv
mc-nv marked this pull request as ready for review October 5, 2026 16:38
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Adds security reporting guidance document.

The PR appears safe to merge under the author’s stated reporting-only scope.

Findings

  1. P2 Security Path traversal warning removed ▶
  2. P2 Security Tamper protection limits omitted ▶
  3. P2 Security Resource risk points elsewhere ▶
  4. P2 Security Repository immutability assumption omitted ▶

Summary

The PR replaces repository-specific security guidance with NVIDIA’s standard vulnerability-reporting policy.

  • Directs reporters to NVIDIA PSIRT’s web form or email and discourages GitHub/GitLab vulnerability reports.
  • Removes the threat model and deployment assumptions. No new actionable issue was established.

Reviews (4) · Last reviewed commit: "docs: Adopt current NVIDIA SECURITY.md t..."

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated

## Threat Model

1. **Untrusted input:** Requests, models, configuration or data supplied to this component may be malformed or malicious, and could cause crashes, memory errors or unintended behavior if not validated.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Path traversal warning removed The new threat model replaces the specific warning about unchecked configuration paths with a general warning about untrusted input. If a deployment accepts model configuration from an authenticated but untrusted party, a key containing ../ can make the agent read outside the model directory and return that file’s digest in a mismatch error. Gateway authentication does not confine file access, so operators need the specific warning to identify which inputs must be trusted.

How this was verified: The configuration key supplies an unchecked path to ReadFile(), and a mismatch error includes the computed digest.

Knowledge Base Used: Native checksum agent implementation

Comment thread SECURITY.md Outdated

## Security Architecture and Context

**Project:** The Triton repository agent that verifies model checksums.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Tamper protection limits omitted Describing the agent simply as verifying model checksums drops the previous warning that it is not a defense against deliberate tampering. It checks only files named in configuration parameters, accepts a model with no such parameters, and reads its MD5 expectations from the model configuration. An operator relying on it for tamper protection could therefore load unverified files or files changed together with their expected digests. Restore the limits on what this check protects.

How this was verified: The load callback compares MD5 digests only for configured parameters and succeeds when that list is empty.

Knowledge Base Used: Checksum repository agent

Comment thread SECURITY.md Outdated
1. **Untrusted input:** Requests, models, configuration or data supplied to this component may be malformed or malicious, and could cause crashes, memory errors or unintended behavior if not validated.
2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned.
3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption.
4. **Resource exhaustion:** Oversized or numerous requests may consume memory, compute or other resources and degrade availability.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Resource risk points elsewhere The replacement guidance points to oversized or numerous requests, but this agent reads an entire configured model file during an in-process load action; it does not serve inference requests. An operator could rate-limit a gateway while leaving large model files able to exhaust server memory. Identify model files and load-time verification as the resource risk.

How this was verified: The load callback passes configured file paths to ReadFile(), which allocates space for the whole file before hashing.

Knowledge Base Used: Checksum repository agent

Comment thread SECURITY.md Outdated
## Critical Security Assumptions

* The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting.
* Models, configuration and other inputs come from trusted sources.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Repository immutability assumption omitted The revised assumptions say model inputs must come from trusted sources but omit the earlier requirement that the repository remain unchanged between verification and use. Even a file from a trusted source can be replaced after its load-time checksum and before the backend reads it, leaving the bytes actually loaded unverified. Restore the immutability assumption so operators do not mistake trusted provenance for continued integrity.

How this was verified: The agent hashes configured files during its load callback, before the backend uses them, and performs no later integrity check.

Knowledge Base Used: Checksum repository agent

@mc-nv
mc-nv merged commit b376e2b into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation (docs: PRs)

Development

Successfully merging this pull request may close these issues.

2 participants