Skip to content

docs: Adopt current NVIDIA SECURITY.md template - #473

Merged
mc-nv merged 4 commits into
mainfrom
mchornyi/TRI-1935/fix-reports
Oct 6, 2026
Merged

mc-nv merged 4 commits into
mainfrom
mchornyi/TRI-1935/fix-reports

Conversation

@mc-nv

@mc-nv mc-nv commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

What does the PR do?

  • Replaces the SECURITY.md body with NVIDIA's current standard template, already used in NVIDIA/NeMo, cuda-python and Megatron-LM.
  • Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording from cuda-python, since Triton repos are mirrored to internal GitLab.
  • Adds: do-not-report-publicly guidance, coordinated disclosure statement with PSIRT link, Product Security portal link. Reporting policy only.
  • Applied across all Triton repositories.

Checklist

  • PR title reflects the change and is of format <commit_type>: <Title>
  • Changes are described in the pull request.
  • Related issues are referenced.
  • Populated github labels field
  • Added test plan and verified test passes.
  • Verified that the PR passes existing CI.
  • Verified copyright is correct on all changed files.
  • Added succinct git squash message before merging ref.
  • All template sections are filled out.
  • Optional: Additional screenshots for behavior/output changes with before/after.

Commit Type:

Check the conventional commit type
box here and add the label to the github PR.

  • build
  • ci
  • docs
  • feat
  • fix
  • perf
  • refactor
  • revert
  • style
  • test

Related PRs:

Where should the reviewer start?

  • SECURITY.md — compare against NVIDIA/NeMo/SECURITY.md for the canonical wording.

Test plan:

  • Documentation only; no code paths affected.

  • CI Pipeline ID:

Caveats:

  • NVIDIA ships two variants of the warning sentence: NVIDIA/NeMo says "through GitHub", NVIDIA/cuda-python says "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.
  • The template's PGP wording is "we encourage you" rather than a hard requirement. Kept as-is for template fidelity; raised on docs: Adopt current NVIDIA SECURITY.md template server#8997.

Background

An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Resolves: TRI-1935

@mc-nv mc-nv added the documentation Improvements or additions to documentation (docs: PRs) label Oct 3, 2026
@mc-nv mc-nv self-assigned this Oct 3, 2026
@mc-nv
mc-nv marked this pull request as ready for review October 5, 2026 16:38
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Updates security reporting documentation to current template.

The PR appears safe to merge; the remaining concerns are previously raised, non-blocking documentation gaps.

Findings

  1. P2 Security Local library warning removed ▶
  2. P2 Security Network boundary points inward ▶
  3. P2 Security Profile export exposure omitted ▶
  4. P2 Security Shared memory precaution removed ▶
  5. P2 Security Elevated-Privilege Warning Removed ▶

Summary

The PR replaces repository-specific security guidance with NVIDIA’s standard vulnerability-reporting template.

  • It directs reporters away from public GitHub/GitLab discussions and toward NVIDIA’s web form or PSIRT email.
  • It adds coordinated-disclosure and Product Security policy links.

Reviews (5) · Last reviewed commit: "docs: Adopt current NVIDIA SECURITY.md t..."

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
* Models, configuration and other inputs come from trusted sources.
* Dependencies and the build environment are kept up to date and obtained from trusted sources.
* Operators protect secrets, certificates and credentials, and restrict access to logs and metrics.
* Host operating system, driver and hardware security are the operator's responsibility.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Local library warning removed The general host-security assumption no longer warns operators to keep library paths trusted. In Triton C API mode, --triton-server-directory selects a library loaded with dlopen; MPI and CUDA libraries are also loaded by name. If an untrusted user can influence one of those locations, the tool can load unintended code. How this was verified: The configured server-library path reaches dlopen, while MPI and CUDA libraries are loaded by name.

Comment thread SECURITY.md Outdated

1. **Untrusted input:** Requests, models, configuration or data supplied to this component may be malformed or malicious, and could cause crashes, memory errors or unintended behavior if not validated.
2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned.
3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Network boundary points inward This describes an inbound-facing component behind a gateway, but Perf Analyzer is a client that connects to inference services. Saying it does not provide encryption also obscures its outbound TLS and certificate options. Operators may focus on an inbound endpoint instead of configuring protection for the connection carrying their requests. How this was verified: The client backend configures outbound HTTPS verification and certificate options, whereas the documented gateway guidance addresses inbound access.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Comment thread SECURITY.md Outdated
2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned.
3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption.
4. **Resource exhaustion:** Oversized or numerous requests may consume memory, compute or other resources and degrade availability.
5. **Information disclosure:** Logs, metrics and error messages may reveal sensitive data such as paths, identifiers or request content.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Profile export exposure omitted This guidance names logs, metrics and errors but not profile exports. When --profile-export-file is used, the export contains request inputs and response outputs and is written with default file permissions. Operators who restrict logs may still share or leave that file accessible without realizing it contains payload data. How this was verified: The profile exporter serializes request and response data into JSON and opens the output file with fopen(..., "w").

Comment thread SECURITY.md Outdated
* Models, configuration and other inputs come from trusted sources.
* Dependencies and the build environment are kept up to date and obtained from trusted sources.
* Operators protect secrets, certificates and credentials, and restrict access to logs and metrics.
* Host operating system, driver and hardware security are the operator's responsibility.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Shared memory precaution removed The general host-security assumption no longer tells operators to isolate shared-memory regions from other local processes or account for regions left after an abnormal exit. Shared-memory mode places test tensors in regions shared with the target server and relies on normal cleanup to unregister and unlink them, so omitting that precaution makes local exposure easier to overlook. How this was verified: Shared-memory initialization creates input and output regions, and unregistration and unlinking occur in the cleanup path.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@mc-nv

mc-nv commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Closing: SECURITY.md already exists in this repository with NVIDIA's standard reporting text, so no change is needed here. Tracked in TRI-1935.

@mc-nv mc-nv closed this Oct 5, 2026
@mc-nv mc-nv reopened this Oct 6, 2026
@mc-nv mc-nv changed the title docs: Update SECURITY.md docs: Adopt current NVIDIA SECURITY.md template Oct 6, 2026
Comment thread SECURITY.md Outdated

## Critical Security Assumptions

* The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Elevated-Privilege Warning Removed The replacement assumptions drop the warning not to run Perf Analyzer with elevated privileges. If it runs as a privileged user, an --input-data JSON file containing message_generator can execute a shell command with those privileges. The general advice to use trusted inputs does not make that risk clear to operators. How this was verified: The input-data command reaches popen and runs with the Perf Analyzer process’s privileges.

@mc-nv
mc-nv merged commit 93ba37f into main Oct 6, 2026
4 of 6 checks passed
@mc-nv
mc-nv deleted the mchornyi/TRI-1935/fix-reports branch October 6, 2026 21:48

This branch is being deployed

1 queued deployment
GITLAB — 8ea67188 Deployed Oct 6, 2026 by mc-nv via mirror_repo #1460
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation (docs: PRs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants