Repository navigation
docs: Add SECURITY.md - #131
Conversation
TRI-1935
|
TRI-1935
| * The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting. | ||
| * Models, configuration and other inputs come from trusted sources. |
There was a problem hiding this comment.
Missing code execution guidance When an operator enables
plugins or version-compatible, the revised assumptions no longer explain that plugin libraries and model-supplied host code can run inside Triton with the server's privileges. An operator relying on this policy may leave plugin paths writable to untrusted users or omit process isolation, allowing a compromised library or model to run with those privileges. A network gateway does not protect this in-process boundary. How this was verified: The backend loads configured plugins with dlopen and permits engine host code when version compatibility is enabled, while the new assumptions omit those execution paths and their safeguards.
What does the PR do?
SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.NVIDIA/NeMo,cuda-pythonandMegatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording fromcuda-python.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)