Repository navigation
docs: Add SECURITY.md - #40
Conversation
TRI-1935
|
TRI-1935
|
|
||
| ## Security Architecture and Context | ||
|
|
||
| **Project:** Example Triton backend that demonstrates most of the Triton Backend API. | ||
|
|
There was a problem hiding this comment.
Backend boundary is unclear The new description calls this a generic API example, but this repository builds an identity-copy backend that Triton loads into its server process. Readers assessing a malformed-tensor or buffer-handling issue may miss that a failure can affect the hosting server. Describe the shared-library role and in-process boundary here.
Knowledge Base Used: Identity backend runtime
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
What does the PR do?
SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.NVIDIA/NeMo,cuda-pythonandMegatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording fromcuda-python.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)