Repository navigation
docs: Add SECURITY.md - #864
Conversation
TRI-1935
|
| 2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned. | ||
| 3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption. | ||
| 4. **Resource exhaustion:** Oversized or numerous requests may consume memory, compute or other resources and degrade availability. | ||
| 5. **Information disclosure:** Logs, metrics and error messages may reveal sensitive data such as paths, identifiers or request content. |
There was a problem hiding this comment.
Tenant isolation warning removed If a deployment serves multiple authorized tenants, gateway authentication alone does not isolate inference state. The previous warning about shared state is gone, while the documented LoRA cache lets subsequent requests use a cached adapter by supplying only its
lora_task_id. Restoring the single-tenant or tenant-isolation assumption would help operators avoid treating an authenticated shared deployment as sufficient protection.
How this was verified: The LoRA documentation says subsequent requests can use a cached adapter by supplying only its task ID.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
|
|
||
| 1. **Untrusted input:** Requests, models, configuration or data supplied to this component may be malformed or malicious, and could cause crashes, memory errors or unintended behavior if not validated. | ||
| 2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned. | ||
| 3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption. |
There was a problem hiding this comment.
Private MPI requirement removed The new network guidance discusses client-facing endpoints but drops the requirement to keep the MPI coordination fabric private. Supported orchestrator deployments can span nodes, and an HTTP-facing gateway does not protect traffic between those nodes. Operators could secure inference endpoints while leaving that communication reachable by untrusted peers; please retain the private-fabric assumption.
How this was verified: The deployment documentation supports MPI-based orchestrator operation across nodes, while the new assumption names only a trusted environment or gateway.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
| ## Critical Security Assumptions | ||
|
|
||
| * The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting. | ||
| * Models, configuration and other inputs come from trusted sources. |
There was a problem hiding this comment.
Artifact integrity guidance removed The new trusted-source assumption no longer tells operators to check model artifacts before loading them. The documented workflow downloads models and tokenizers from external sources, and preprocessing loads tokenizers when the server initializes a model. A trusted source alone does not establish that the downloaded artifact is the intended one; please restore the operator's integrity-check responsibility.
How this was verified: Repository documentation shows external model downloads and tokenizer loading during Triton model initialization.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
What does the PR do?
SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.NVIDIA/NeMo,cuda-pythonandMegatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording fromcuda-python.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)