diff --git a/.release-please-manifest.json b/.release-please-manifest.json index 9d58c97e1..78e1adfd6 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,4 +1,4 @@ { - ".": "0.2.52", - "packages/modelaudit-picklescan": "0.1.10" + ".": "0.2.53", + "packages/modelaudit-picklescan": "0.1.11" } diff --git a/AGENTS.md b/AGENTS.md index 9922106e7..dd8099d21 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -18,7 +18,7 @@ This repo publishes **two PyPI packages with independent versions**: | `modelaudit` | `./` (root) | `pyproject.toml` + `uv.lock` | `CHANGELOG.md` | | `modelaudit-picklescan` | `packages/modelaudit-picklescan/` | `pyproject.toml` + `Cargo.toml` | `packages/modelaudit-picklescan/CHANGELOG.md` | -Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.10,<0.2.0` — when the sibling crosses `0.2.0`, bump the constraint in the same PR or the next `modelaudit` release is uninstallable. Both packages are driven by a single `release-please` workflow (`.github/workflows/release-please.yml`) with components defined in `release-please-config.json` and current versions in `.release-please-manifest.json`. Full publishing details — trusted publishing, manual `workflow_dispatch` recovery (`root_version` / `picklescan_version`), and yank procedure — are in [`docs/agents/release-process.md`](docs/agents/release-process.md). For work inside the picklescan package, start from [`packages/modelaudit-picklescan/AGENTS.md`](packages/modelaudit-picklescan/AGENTS.md). +Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.11,<0.2.0` — when the sibling crosses `0.2.0`, bump the constraint in the same PR or the next `modelaudit` release is uninstallable. Both packages are driven by a single `release-please` workflow (`.github/workflows/release-please.yml`) with components defined in `release-please-config.json` and current versions in `.release-please-manifest.json`. Full publishing details — trusted publishing, manual `workflow_dispatch` recovery (`root_version` / `picklescan_version`), and yank procedure — are in [`docs/agents/release-process.md`](docs/agents/release-process.md). For work inside the picklescan package, start from [`packages/modelaudit-picklescan/AGENTS.md`](packages/modelaudit-picklescan/AGENTS.md). ## Mission & Principles diff --git a/CHANGELOG.md b/CHANGELOG.md index 33027145b..e7f427a95 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,11 +7,12 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [0.2.53](https://github.com/promptfoo/modelaudit/compare/v0.2.52...v0.2.53) (2026-10-03) + ### Security - Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes. -- Upgrade locked GitPython to 3.1.59 to address four dependency audit advisories. -- Upgrade locked GitPython to 3.1.60 to address newly disclosed dependency audit advisories. +- Upgrade locked AnyIO to 4.15.1 and GitPython to 3.1.62 to address dependency audit advisories. - Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants. - Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature. - Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615. @@ -19,6 +20,50 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Bug Fixes +- avoid C&C signal for check_input_dim identifiers ([#1847](https://github.com/promptfoo/modelaudit/issues/1847)) ([f906f9a](https://github.com/promptfoo/modelaudit/commit/f906f9a90a0dc692a4d1dd5af69bf267aa47b04c)) +- **cache:** ignore macOS file access-time events ([#1821](https://github.com/promptfoo/modelaudit/issues/1821)) ([b5341b5](https://github.com/promptfoo/modelaudit/commit/b5341b5a35c86edba3b315af92ea2a431700156b)) +- **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) +- **cache:** keep Windows probes out of concurrently scanned trees ([#1795](https://github.com/promptfoo/modelaudit/issues/1795)) ([c29586b](https://github.com/promptfoo/modelaudit/commit/c29586b09a29f7cf8bbba6e9e4a0a74e006cc27f)) +- **cache:** preserve locked probes under directory aliases ([#1787](https://github.com/promptfoo/modelaudit/issues/1787)) ([caa2afe](https://github.com/promptfoo/modelaudit/commit/caa2afea1c2d961aef19d1b149f0c9b8fe20c72f)) +- **cache:** preserve macOS entries during ancestor churn ([#1800](https://github.com/promptfoo/modelaudit/issues/1800)) ([2c3512b](https://github.com/promptfoo/modelaudit/commit/2c3512b97cf01ecbce632873cf6e1e17a64b75c3)) +- **cache:** preserve Windows source fingerprint cache hits ([#1793](https://github.com/promptfoo/modelaudit/issues/1793)) ([f27ebac](https://github.com/promptfoo/modelaudit/commit/f27ebacdd4008eedf902f6ab87d9d5420a5fa66b)) +- **cache:** update scan-result entries atomically on hits ([#1809](https://github.com/promptfoo/modelaudit/issues/1809)) ([a9720c0](https://github.com/promptfoo/modelaudit/commit/a9720c0af126fd2bc3f3c2f76228320336103202)) +- **ci:** accept rotated pinned checkout digests ([#1799](https://github.com/promptfoo/modelaudit/issues/1799)) ([704e070](https://github.com/promptfoo/modelaudit/commit/704e07022f814953ebbf1cadb583cda29b58e6eb)) +- **ci:** increase nightly correctness shard capacity ([#1866](https://github.com/promptfoo/modelaudit/issues/1866)) ([7bb0378](https://github.com/promptfoo/modelaudit/commit/7bb03789e0d821709a1d994d778617a715c2251b)) +- **ci:** route hash timing test to performance lane ([#1824](https://github.com/promptfoo/modelaudit/issues/1824)) ([b4c10f2](https://github.com/promptfoo/modelaudit/commit/b4c10f2fe39a253c9d10f60fea3b8803c850db8d)) +- compact ONNX runtime lineage fanout ([#1845](https://github.com/promptfoo/modelaudit/issues/1845)) ([4b7ebbc](https://github.com/promptfoo/modelaudit/commit/4b7ebbc4e179d20b1a864c6eb9b7ab2ffdee6010)) +- **deps:** bump anyio from 4.13.0 to 4.14.2 ([#1855](https://github.com/promptfoo/modelaudit/issues/1855)) ([e635b8a](https://github.com/promptfoo/modelaudit/commit/e635b8ac950964d473742fe70f1bc45995d200cc)) +- **deps:** bump gitpython from 3.1.51 to 3.1.54 ([#1786](https://github.com/promptfoo/modelaudit/issues/1786)) ([32de965](https://github.com/promptfoo/modelaudit/commit/32de965e4345b9749e6cd8bb88f5a7e01a08933b)) +- **deps:** bump oauthlib from 3.3.1 to 4.0.0 ([#1860](https://github.com/promptfoo/modelaudit/issues/1860)) ([72d3777](https://github.com/promptfoo/modelaudit/commit/72d3777374f23165d63b6c28bb510cc2de07cd23)) +- **deps:** harden audit coverage and vulnerable packages ([#1808](https://github.com/promptfoo/modelaudit/issues/1808)) ([995767e](https://github.com/promptfoo/modelaudit/commit/995767ed16bda0f6019d27b02239ed308dd669b6)) +- **deps:** prevent incompatible XGBoost Renovate upgrades ([#1810](https://github.com/promptfoo/modelaudit/issues/1810)) ([ee2025e](https://github.com/promptfoo/modelaudit/commit/ee2025e3a65273b8ae3aa4f7dbb313dffac3dd89)) +- **deps:** update dependency xgboost to >=3.4,<3.5 ([#1805](https://github.com/promptfoo/modelaudit/issues/1805)) ([e84cf95](https://github.com/promptfoo/modelaudit/commit/e84cf9566c5a6da144a17ebe7a3e30812a60184b)) +- **docker:** upgrade vulnerable runtime Debian packages ([#1849](https://github.com/promptfoo/modelaudit/issues/1849)) ([fafb9fb](https://github.com/promptfoo/modelaudit/commit/fafb9fb1cbd215d8152f9863dab4c6fd4764f5ce)) +- **docker:** upgrade vulnerable util-linux runtime packages ([#1813](https://github.com/promptfoo/modelaudit/issues/1813)) ([521e941](https://github.com/promptfoo/modelaudit/commit/521e94164e0e1b7ce488f0b405b7ab48404776cd)) +- downgrade passive model metadata URLs ([#1837](https://github.com/promptfoo/modelaudit/issues/1837)) ([de299cf](https://github.com/promptfoo/modelaudit/commit/de299cfebc3e3597b50f98b01bb598dea408b321)) +- **ggml:** detect embedded ZIP polyglot payloads ([#1780](https://github.com/promptfoo/modelaudit/issues/1780)) ([9631527](https://github.com/promptfoo/modelaudit/commit/9631527b3e81e0458fe9e0242c3178af406bfa5f)) +- ignore ONNX tensor bytes for network text ([#1840](https://github.com/promptfoo/modelaudit/issues/1840)) ([12c6287](https://github.com/promptfoo/modelaudit/commit/12c6287d655cd97ba46833c6fa31f8e983ea7a4e)) +- install tomli for Python 3.10 runtime ([#1843](https://github.com/promptfoo/modelaudit/issues/1843)) ([242e08b](https://github.com/promptfoo/modelaudit/commit/242e08b71c454c6e573c2ba9a060138b5a40920f)) +- **joblib:** fail closed on inconclusive warning scans ([#1796](https://github.com/promptfoo/modelaudit/issues/1796)) ([a54bddc](https://github.com/promptfoo/modelaudit/commit/a54bddcb3b35feaa2d1678246da3e6bc8fbe3890)) +- **mlflow:** restore SQL-backed registry support ([#1818](https://github.com/promptfoo/modelaudit/issues/1818)) ([3e4e3c9](https://github.com/promptfoo/modelaudit/commit/3e4e3c9619c07eda82543c7c288858d25d695dd9)) +- **network:** block README remote-code trust bypasses ([#1788](https://github.com/promptfoo/modelaudit/issues/1788)) ([65111fe](https://github.com/promptfoo/modelaudit/commit/65111fe16b263a31e989ba327f1c84ff84c6f964)) +- **network:** preserve detections in README environment files ([#1790](https://github.com/promptfoo/modelaudit/issues/1790)) ([5c1b267](https://github.com/promptfoo/modelaudit/commit/5c1b2671f372655177992fda5a35039b602d67a9)) +- **network:** reject side-effectful model-card image examples ([#1825](https://github.com/promptfoo/modelaudit/issues/1825)) ([56417b8](https://github.com/promptfoo/modelaudit/commit/56417b801fc83cde10ba6d2046441af3c9636b50)) +- **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) +- **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) +- **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) +- **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) +- preserve caller-owned Hugging Face cache sidecars ([#1792](https://github.com/promptfoo/modelaudit/issues/1792)) ([eeb0be6](https://github.com/promptfoo/modelaudit/commit/eeb0be69336e668f2b7c341fd2d90886bb43ccdd)) +- preserve ONNX shape provenance during weight analysis ([#1838](https://github.com/promptfoo/modelaudit/issues/1838)) ([54d14c3](https://github.com/promptfoo/modelaudit/commit/54d14c3ad15ca8dd3ef41f2454163e0b834f855f)) +- preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) +- recognize bounded official image downloads in model cards ([#1784](https://github.com/promptfoo/modelaudit/issues/1784)) ([64d4f52](https://github.com/promptfoo/modelaudit/commit/64d4f5238573f8d96283ebb241e6ae42258f1140)) +- remove tensor_name_count retention budget dimension for remote SafeTensors ([#1822](https://github.com/promptfoo/modelaudit/issues/1822)) ([4c24e17](https://github.com/promptfoo/modelaudit/commit/4c24e1701c456b2bd9256e4d09429fcacd1075fa)) +- safely suppress verified Hugging Face model-card image examples ([#1791](https://github.com/promptfoo/modelaudit/issues/1791)) ([6ee2b36](https://github.com/promptfoo/modelaudit/commit/6ee2b368f029d8a9858363938068cbde766b2e2e)) +- scan encoded pickle metadata within byte budget ([#1839](https://github.com/promptfoo/modelaudit/issues/1839)) ([169cd17](https://github.com/promptfoo/modelaudit/commit/169cd177a6769d5f461abc75f645bea5f5a2260d)) +- **tests:** preserve fail-closed multi-array Joblib scans ([#1819](https://github.com/promptfoo/modelaudit/issues/1819)) ([217f127](https://github.com/promptfoo/modelaudit/commit/217f1270cfa115c6409823556e5170487930fb64)) +- treat CoreML license references as informational ([#1852](https://github.com/promptfoo/modelaudit/issues/1852)) ([604bed5](https://github.com/promptfoo/modelaudit/commit/604bed57db2352116ff9099933e560e301d1ef11)) +- trust complete legacy PyTorch storage layout ([#1850](https://github.com/promptfoo/modelaudit/issues/1850)) ([08d9fee](https://github.com/promptfoo/modelaudit/commit/08d9fee29cf671705b892ed8bb20d9e5625f742b)) +- validate manual release versions before outputs ([#1794](https://github.com/promptfoo/modelaudit/issues/1794)) ([13431f6](https://github.com/promptfoo/modelaudit/commit/13431f61124178250e79552a3770de024b796a54)) - Avoid incomplete ONNX weight analysis when Gather nodes read dimensions from Shape outputs. - Avoid incomplete ONNX weight analysis when large runtime-activation fanout only adds dynamic bookkeeping lineage. - Treat documentation, license, and repository links in verified pickle and ONNX metadata as informational across supported Python versions while preserving active and unknown network destinations. @@ -49,6 +94,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Avoid command-and-control false positives for generated TorchScript `_check_input_dim` identifiers while preserving actionable `check_in` detections. - Avoid incomplete legacy PyTorch storage-layout findings after validating storage bytes when separate source-backed rebuild warnings remain. - Treat passive built-in CoreML license-reference URLs as informational while preserving active metadata URL and command detections. +- Require `modelaudit-picklescan>=0.1.11` so root upgrades receive the released scanner fixes. ## [0.2.52](https://github.com/promptfoo/modelaudit/compare/v0.2.51...v0.2.52) (2026-07-22) @@ -2588,7 +2634,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - **style**: improve code formatting and documentation standards (#12, #23) - **fix**: improve core scanner functionality and comprehensive test coverage (#11) -[unreleased]: https://github.com/promptfoo/modelaudit/compare/v0.2.52...HEAD +[unreleased]: https://github.com/promptfoo/modelaudit/compare/v0.2.53...HEAD [0.2.25]: https://github.com/promptfoo/modelaudit/compare/v0.2.24...v0.2.25 [0.2.24]: https://github.com/promptfoo/modelaudit/compare/v0.2.23...v0.2.24 [0.2.23]: https://github.com/promptfoo/modelaudit/compare/v0.2.22...v0.2.23 diff --git a/docs/agents/release-process.md b/docs/agents/release-process.md index c9a9edd74..e33b5d5a8 100644 --- a/docs/agents/release-process.md +++ b/docs/agents/release-process.md @@ -11,7 +11,7 @@ Both packages are driven by a single [release-please](https://github.com/googlea The root release intentionally omits `package-name` and `component`. Release-please reads `project.name` from `pyproject.toml` for Python updates, while the empty branch component lets a root-only grouped Release PR match `release-please--branches--main` and keeps the existing `v{X.Y.Z}` tags. Restoring a non-empty `package-name` or `component` makes root-only releases look like a different component and silently skips publication after merge. -The root `modelaudit` wheel declares a **hard dependency** on `modelaudit-picklescan>=0.1.10,<0.2.0` in `pyproject.toml`. When the sibling version crosses `0.2.0`, the constraint must be bumped in the same PR. +The root `modelaudit` wheel declares a **hard dependency** on `modelaudit-picklescan>=0.1.11,<0.2.0` in `pyproject.toml`. When the sibling version crosses `0.2.0`, the constraint must be bumped in the same PR. ## Normal flow diff --git a/packages/modelaudit-picklescan/AGENTS.md b/packages/modelaudit-picklescan/AGENTS.md index 06172b582..06a387bc7 100644 --- a/packages/modelaudit-picklescan/AGENTS.md +++ b/packages/modelaudit-picklescan/AGENTS.md @@ -4,7 +4,7 @@ Scoped agent guide for work inside `packages/modelaudit-picklescan/`. The root [ ## What this package is -`modelaudit-picklescan` is the Rust-backed pickle scanner that ships as an independent PyPI package. The root `modelaudit` wheel depends on it at runtime via a hard `modelaudit-picklescan>=0.1.10,<0.2.0` pin in the root `pyproject.toml`. +`modelaudit-picklescan` is the Rust-backed pickle scanner that ships as an independent PyPI package. The root `modelaudit` wheel depends on it at runtime via a hard `modelaudit-picklescan>=0.1.11,<0.2.0` pin in the root `pyproject.toml`. - **Public API** — exported from `src/modelaudit_picklescan/__init__.py`: `PickleScanner`, `ScanOptions`, `scan_file`, `scan_bytes`, `scan_stream`, `shared_source_sensitive_caches`, `PickleReport`, `Finding`, `Notice`, `ScanError`, `Severity`, `ScanStatus`, `SafetyVerdict`, `CoverageSummary`. Treat these names as a stable surface. - **Rust engine** — `rust/src/` compiled to `modelaudit_picklescan._rust` via maturin + PyO3. Rust 1.83+, edition 2021. @@ -74,7 +74,7 @@ Root-level validation (`uv run ruff check modelaudit/ packages/modelaudit-pickle - Release tag format: `modelaudit-picklescan-v{X.Y.Z}`. - Bumps are driven by Conventional Commits that **touch files inside `packages/modelaudit-picklescan/`**. Commits that only touch `modelaudit/` or the repo root do not bump this package. -When this package reaches `0.2.0`, the root `pyproject.toml` `modelaudit-picklescan>=0.1.10,<0.2.0` constraint must be widened in the same PR, or the next `modelaudit` release will be uninstallable. +When this package reaches `0.2.0`, the root `pyproject.toml` `modelaudit-picklescan>=0.1.11,<0.2.0` constraint must be widened in the same PR, or the next `modelaudit` release will be uninstallable. ## Publishing diff --git a/packages/modelaudit-picklescan/CHANGELOG.md b/packages/modelaudit-picklescan/CHANGELOG.md index ba8425434..abfbb09d5 100644 --- a/packages/modelaudit-picklescan/CHANGELOG.md +++ b/packages/modelaudit-picklescan/CHANGELOG.md @@ -7,8 +7,15 @@ and this package adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [0.1.11](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.10...modelaudit-picklescan-v0.1.11) (2026-10-03) + ### Bug Fixes +- **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) +- **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) +- **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) +- **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) +- preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) - Ignore canonical PyTorch storage persistent-ID globals during source-sensitive call-graph enrichment. - Report which snapshot gate invalidated a shared call-graph source-stability failure. - Validate bounded batched PyTorch state-dictionary entries without falsely flagging canonical tensor reconstruction. diff --git a/packages/modelaudit-picklescan/Cargo.lock b/packages/modelaudit-picklescan/Cargo.lock index 4d1bfcd74..43ff626a4 100644 --- a/packages/modelaudit-picklescan/Cargo.lock +++ b/packages/modelaudit-picklescan/Cargo.lock @@ -16,7 +16,7 @@ checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" [[package]] name = "modelaudit-picklescan-rust" -version = "0.1.10" +version = "0.1.11" dependencies = [ "pyo3", ] diff --git a/packages/modelaudit-picklescan/Cargo.toml b/packages/modelaudit-picklescan/Cargo.toml index 23637ebf1..271c14290 100644 --- a/packages/modelaudit-picklescan/Cargo.toml +++ b/packages/modelaudit-picklescan/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "modelaudit-picklescan-rust" -version = "0.1.10" # x-release-please-version +version = "0.1.11" # x-release-please-version edition = "2021" rust-version = "1.83" description = "Native pickle security scanner engine for modelaudit-picklescan" diff --git a/packages/modelaudit-picklescan/pyproject.toml b/packages/modelaudit-picklescan/pyproject.toml index 6fd378ea9..88f6a251e 100644 --- a/packages/modelaudit-picklescan/pyproject.toml +++ b/packages/modelaudit-picklescan/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "modelaudit-picklescan" -version = "0.1.10" # x-release-please-version +version = "0.1.11" # x-release-please-version description = "Standalone pickle security scanner extracted from ModelAudit" authors = [ { name = "Ian Webster", email = "ian@promptfoo.dev" }, diff --git a/packages/modelaudit-picklescan/uv.lock b/packages/modelaudit-picklescan/uv.lock index bef92f79f..649cb9424 100644 --- a/packages/modelaudit-picklescan/uv.lock +++ b/packages/modelaudit-picklescan/uv.lock @@ -1,8 +1,8 @@ version = 1 -revision = 3 +revision = 5 requires-python = ">=3.10" [[package]] name = "modelaudit-picklescan" -version = "0.1.10" +version = "0.1.11" source = { editable = "." } diff --git a/pyproject.toml b/pyproject.toml index d81ace34b..b1897aa5c 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "hatchling.build" [project] name = "modelaudit" -version = "0.2.52" +version = "0.2.53" description = "Static scanning library for detecting malicious code, potential backdoor indicators, and other security risks in ML model files" authors = [ { name = "Ian Webster", email = "ian@promptfoo.dev" }, @@ -53,7 +53,7 @@ dependencies = [ "protobuf>=5.29.0", "msgpack>=1.2.1,<2.0", "tomli>=2.0.0; python_version < '3.11'", - "modelaudit-picklescan>=0.1.10,<0.2.0", + "modelaudit-picklescan>=0.1.11,<0.2.0", ] [project.optional-dependencies] diff --git a/tests/test_dependency_lock.py b/tests/test_dependency_lock.py index cfb76589e..9866da2e4 100644 --- a/tests/test_dependency_lock.py +++ b/tests/test_dependency_lock.py @@ -5,6 +5,8 @@ from pathlib import Path import pytest +from packaging.requirements import Requirement +from packaging.version import Version try: import tomllib @@ -18,7 +20,6 @@ PICKLESCAN_PYPROJECT = ROOT_DIR / "packages" / "modelaudit-picklescan" / "pyproject.toml" PATCHED_GITPYTHON_FLOOR = (3, 1, 60) PINNED_MATURIN_BACKEND = "maturin===1.13.3" -REQUIRED_PICKLESCAN_RELEASE = "modelaudit-picklescan>=0.1.10,<0.2.0" PATCHED_PY7ZR_REQUIREMENT = "py7zr>=1.1.3" PY7ZR_EXTRAS = ("sevenzip", "all-ci", "all") PATCHED_MLFLOW_CLIENT_REQUIREMENT = "mlflow-skinny>=3.13.0" @@ -137,8 +138,21 @@ def test_picklescan_build_backend_is_exactly_pinned() -> None: def test_root_requires_hardened_picklescan_release() -> None: root_config = tomllib.loads(ROOT_PYPROJECT.read_text(encoding="utf-8")) - - assert REQUIRED_PICKLESCAN_RELEASE in root_config["project"]["dependencies"] + dependency = next( + requirement + for entry in root_config["project"]["dependencies"] + if (requirement := Requirement(entry)).name == "modelaudit-picklescan" + ) + + assert dependency.marker is None + # Root upgrades must receive these fixes, while later floor increases remain valid. + bounds = {specifier.operator: specifier.version for specifier in dependency.specifier} + assert len(dependency.specifier) == 2 + assert set(bounds) == {">=", "<"} + assert Version(bounds[">="]) >= Version("0.1.11") + assert Version(bounds["<"]) == Version("0.2.0") + locked_version = ".".join(str(part) for part in _locked_version(_lock_package_block("modelaudit-picklescan"))) + assert dependency.specifier.contains(locked_version) def test_py7zr_extras_require_patched_release() -> None: diff --git a/uv.lock b/uv.lock index b1e910679..eb6980dcd 100644 --- a/uv.lock +++ b/uv.lock @@ -1,5 +1,5 @@ version = 1 -revision = 3 +revision = 5 requires-python = ">=3.10, <3.14" resolution-markers = [ "python_full_version >= '3.13'", @@ -1982,7 +1982,7 @@ wheels = [ [[package]] name = "modelaudit" -version = "0.2.52" +version = "0.2.53" source = { editable = "." } dependencies = [ { name = "click" }, @@ -2269,7 +2269,7 @@ dev = [ [[package]] name = "modelaudit-picklescan" -version = "0.1.10" +version = "0.1.11" source = { editable = "packages/modelaudit-picklescan" } [[package]]