Repository navigation
docs: Add SECURITY.md - #26
Conversation
TRI-1935
|
| 1. **Untrusted input:** Requests, models, configuration or data supplied to this component may be malformed or malicious, and could cause crashes, memory errors or unintended behavior if not validated. | ||
| 2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned. | ||
| 3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption. | ||
| 4. **Resource exhaustion:** Oversized or numerous requests may consume memory, compute or other resources and degrade availability. |
There was a problem hiding this comment.
Response Count Risk Obscured The generic resource warning no longer tells operators that the client-supplied
IN value controls how many responses a detached thread generates. The backend does not bound that count; a large or negative value can keep the thread running and delay model unload. Without the specific warning, operators may miss the need to bound this input. How this was verified: The first input element becomes an unsigned loop limit without a bound, and model destruction waits for the response thread.
|
|
||
| * The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting. | ||
| * Models, configuration and other inputs come from trusted sources. | ||
| * Dependencies and the build environment are kept up to date and obtained from trusted sources. |
There was a problem hiding this comment.
Dependency Pinning Guidance Removed This assumption replaces the specific advice to pin and verify the Triton repositories with a general call to use trusted, current dependencies. The build fetches three repositories whose tags default to the moving
main branch, so someone following the default build can incorporate upstream changes they have not reviewed. Restoring the pin-and-verify guidance would give builders a concrete precaution.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
| # OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | ||
| --> | ||
|
|
||
| ## Security |
There was a problem hiding this comment.
Log-access warning removed The reporting-only policy removes the repository’s warning to restrict access to logs. This backend writes the full model configuration and a client-supplied
IN value to INFO logs. Operators relying on this repository’s guidance may therefore miss the need to protect logs containing configuration or request data. Please preserve that warning elsewhere if this file must follow the standard template.
How this was verified: The backend logs the serialized model configuration and the request-derived response count at INFO level.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
What does the PR do?
SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.NVIDIA/NeMo,cuda-pythonandMegatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording fromcuda-python.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)