From 190afa7adbaf934dff22c47119b3327838b6bc66 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 00:02:32 +0000 Subject: [PATCH 1/4] chore: release main --- .release-please-manifest.json | 4 +- CHANGELOG.md | 50 +++++++++++++++++++ packages/modelaudit-picklescan/CHANGELOG.md | 12 +++++ packages/modelaudit-picklescan/Cargo.toml | 2 +- packages/modelaudit-picklescan/pyproject.toml | 2 +- pyproject.toml | 2 +- 6 files changed, 67 insertions(+), 5 deletions(-) diff --git a/.release-please-manifest.json b/.release-please-manifest.json index 9d58c97e1..78e1adfd6 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,4 +1,4 @@ { - ".": "0.2.52", - "packages/modelaudit-picklescan": "0.1.10" + ".": "0.2.53", + "packages/modelaudit-picklescan": "0.1.11" } diff --git a/CHANGELOG.md b/CHANGELOG.md index 33027145b..1a4fdee4c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,56 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [0.2.53](https://github.com/promptfoo/modelaudit/compare/v0.2.52...v0.2.53) (2026-10-03) + + +### Bug Fixes + +* avoid C&C signal for check_input_dim identifiers ([#1847](https://github.com/promptfoo/modelaudit/issues/1847)) ([f906f9a](https://github.com/promptfoo/modelaudit/commit/f906f9a90a0dc692a4d1dd5af69bf267aa47b04c)) +* **cache:** ignore macOS file access-time events ([#1821](https://github.com/promptfoo/modelaudit/issues/1821)) ([b5341b5](https://github.com/promptfoo/modelaudit/commit/b5341b5a35c86edba3b315af92ea2a431700156b)) +* **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) +* **cache:** keep Windows probes out of concurrently scanned trees ([#1795](https://github.com/promptfoo/modelaudit/issues/1795)) ([c29586b](https://github.com/promptfoo/modelaudit/commit/c29586b09a29f7cf8bbba6e9e4a0a74e006cc27f)) +* **cache:** preserve locked probes under directory aliases ([#1787](https://github.com/promptfoo/modelaudit/issues/1787)) ([caa2afe](https://github.com/promptfoo/modelaudit/commit/caa2afea1c2d961aef19d1b149f0c9b8fe20c72f)) +* **cache:** preserve macOS entries during ancestor churn ([#1800](https://github.com/promptfoo/modelaudit/issues/1800)) ([2c3512b](https://github.com/promptfoo/modelaudit/commit/2c3512b97cf01ecbce632873cf6e1e17a64b75c3)) +* **cache:** preserve Windows source fingerprint cache hits ([#1793](https://github.com/promptfoo/modelaudit/issues/1793)) ([f27ebac](https://github.com/promptfoo/modelaudit/commit/f27ebacdd4008eedf902f6ab87d9d5420a5fa66b)) +* **cache:** update scan-result entries atomically on hits ([#1809](https://github.com/promptfoo/modelaudit/issues/1809)) ([a9720c0](https://github.com/promptfoo/modelaudit/commit/a9720c0af126fd2bc3f3c2f76228320336103202)) +* **ci:** accept rotated pinned checkout digests ([#1799](https://github.com/promptfoo/modelaudit/issues/1799)) ([704e070](https://github.com/promptfoo/modelaudit/commit/704e07022f814953ebbf1cadb583cda29b58e6eb)) +* **ci:** increase nightly correctness shard capacity ([#1866](https://github.com/promptfoo/modelaudit/issues/1866)) ([7bb0378](https://github.com/promptfoo/modelaudit/commit/7bb03789e0d821709a1d994d778617a715c2251b)) +* **ci:** route hash timing test to performance lane ([#1824](https://github.com/promptfoo/modelaudit/issues/1824)) ([b4c10f2](https://github.com/promptfoo/modelaudit/commit/b4c10f2fe39a253c9d10f60fea3b8803c850db8d)) +* compact ONNX runtime lineage fanout ([#1845](https://github.com/promptfoo/modelaudit/issues/1845)) ([4b7ebbc](https://github.com/promptfoo/modelaudit/commit/4b7ebbc4e179d20b1a864c6eb9b7ab2ffdee6010)) +* **deps:** bump anyio from 4.13.0 to 4.14.2 ([#1855](https://github.com/promptfoo/modelaudit/issues/1855)) ([e635b8a](https://github.com/promptfoo/modelaudit/commit/e635b8ac950964d473742fe70f1bc45995d200cc)) +* **deps:** bump gitpython from 3.1.51 to 3.1.54 ([#1786](https://github.com/promptfoo/modelaudit/issues/1786)) ([32de965](https://github.com/promptfoo/modelaudit/commit/32de965e4345b9749e6cd8bb88f5a7e01a08933b)) +* **deps:** bump oauthlib from 3.3.1 to 4.0.0 ([#1860](https://github.com/promptfoo/modelaudit/issues/1860)) ([72d3777](https://github.com/promptfoo/modelaudit/commit/72d3777374f23165d63b6c28bb510cc2de07cd23)) +* **deps:** harden audit coverage and vulnerable packages ([#1808](https://github.com/promptfoo/modelaudit/issues/1808)) ([995767e](https://github.com/promptfoo/modelaudit/commit/995767ed16bda0f6019d27b02239ed308dd669b6)) +* **deps:** prevent incompatible XGBoost Renovate upgrades ([#1810](https://github.com/promptfoo/modelaudit/issues/1810)) ([ee2025e](https://github.com/promptfoo/modelaudit/commit/ee2025e3a65273b8ae3aa4f7dbb313dffac3dd89)) +* **deps:** update dependency xgboost to >=3.4,<3.5 ([#1805](https://github.com/promptfoo/modelaudit/issues/1805)) ([e84cf95](https://github.com/promptfoo/modelaudit/commit/e84cf9566c5a6da144a17ebe7a3e30812a60184b)) +* **docker:** upgrade vulnerable runtime Debian packages ([#1849](https://github.com/promptfoo/modelaudit/issues/1849)) ([fafb9fb](https://github.com/promptfoo/modelaudit/commit/fafb9fb1cbd215d8152f9863dab4c6fd4764f5ce)) +* **docker:** upgrade vulnerable util-linux runtime packages ([#1813](https://github.com/promptfoo/modelaudit/issues/1813)) ([521e941](https://github.com/promptfoo/modelaudit/commit/521e94164e0e1b7ce488f0b405b7ab48404776cd)) +* downgrade passive model metadata URLs ([#1837](https://github.com/promptfoo/modelaudit/issues/1837)) ([de299cf](https://github.com/promptfoo/modelaudit/commit/de299cfebc3e3597b50f98b01bb598dea408b321)) +* **ggml:** detect embedded ZIP polyglot payloads ([#1780](https://github.com/promptfoo/modelaudit/issues/1780)) ([9631527](https://github.com/promptfoo/modelaudit/commit/9631527b3e81e0458fe9e0242c3178af406bfa5f)) +* ignore ONNX tensor bytes for network text ([#1840](https://github.com/promptfoo/modelaudit/issues/1840)) ([12c6287](https://github.com/promptfoo/modelaudit/commit/12c6287d655cd97ba46833c6fa31f8e983ea7a4e)) +* install tomli for Python 3.10 runtime ([#1843](https://github.com/promptfoo/modelaudit/issues/1843)) ([242e08b](https://github.com/promptfoo/modelaudit/commit/242e08b71c454c6e573c2ba9a060138b5a40920f)) +* **joblib:** fail closed on inconclusive warning scans ([#1796](https://github.com/promptfoo/modelaudit/issues/1796)) ([a54bddc](https://github.com/promptfoo/modelaudit/commit/a54bddcb3b35feaa2d1678246da3e6bc8fbe3890)) +* **mlflow:** restore SQL-backed registry support ([#1818](https://github.com/promptfoo/modelaudit/issues/1818)) ([3e4e3c9](https://github.com/promptfoo/modelaudit/commit/3e4e3c9619c07eda82543c7c288858d25d695dd9)) +* **network:** block README remote-code trust bypasses ([#1788](https://github.com/promptfoo/modelaudit/issues/1788)) ([65111fe](https://github.com/promptfoo/modelaudit/commit/65111fe16b263a31e989ba327f1c84ff84c6f964)) +* **network:** preserve detections in README environment files ([#1790](https://github.com/promptfoo/modelaudit/issues/1790)) ([5c1b267](https://github.com/promptfoo/modelaudit/commit/5c1b2671f372655177992fda5a35039b602d67a9)) +* **network:** reject side-effectful model-card image examples ([#1825](https://github.com/promptfoo/modelaudit/issues/1825)) ([56417b8](https://github.com/promptfoo/modelaudit/commit/56417b801fc83cde10ba6d2046441af3c9636b50)) +* **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) +* **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) +* **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) +* **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) +* preserve caller-owned Hugging Face cache sidecars ([#1792](https://github.com/promptfoo/modelaudit/issues/1792)) ([eeb0be6](https://github.com/promptfoo/modelaudit/commit/eeb0be69336e668f2b7c341fd2d90886bb43ccdd)) +* preserve ONNX shape provenance during weight analysis ([#1838](https://github.com/promptfoo/modelaudit/issues/1838)) ([54d14c3](https://github.com/promptfoo/modelaudit/commit/54d14c3ad15ca8dd3ef41f2454163e0b834f855f)) +* preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) +* recognize bounded official image downloads in model cards ([#1784](https://github.com/promptfoo/modelaudit/issues/1784)) ([64d4f52](https://github.com/promptfoo/modelaudit/commit/64d4f5238573f8d96283ebb241e6ae42258f1140)) +* remove tensor_name_count retention budget dimension for remote SafeTensors ([#1822](https://github.com/promptfoo/modelaudit/issues/1822)) ([4c24e17](https://github.com/promptfoo/modelaudit/commit/4c24e1701c456b2bd9256e4d09429fcacd1075fa)) +* safely suppress verified Hugging Face model-card image examples ([#1791](https://github.com/promptfoo/modelaudit/issues/1791)) ([6ee2b36](https://github.com/promptfoo/modelaudit/commit/6ee2b368f029d8a9858363938068cbde766b2e2e)) +* scan encoded pickle metadata within byte budget ([#1839](https://github.com/promptfoo/modelaudit/issues/1839)) ([169cd17](https://github.com/promptfoo/modelaudit/commit/169cd177a6769d5f461abc75f645bea5f5a2260d)) +* **tests:** preserve fail-closed multi-array Joblib scans ([#1819](https://github.com/promptfoo/modelaudit/issues/1819)) ([217f127](https://github.com/promptfoo/modelaudit/commit/217f1270cfa115c6409823556e5170487930fb64)) +* treat CoreML license references as informational ([#1852](https://github.com/promptfoo/modelaudit/issues/1852)) ([604bed5](https://github.com/promptfoo/modelaudit/commit/604bed57db2352116ff9099933e560e301d1ef11)) +* trust complete legacy PyTorch storage layout ([#1850](https://github.com/promptfoo/modelaudit/issues/1850)) ([08d9fee](https://github.com/promptfoo/modelaudit/commit/08d9fee29cf671705b892ed8bb20d9e5625f742b)) +* validate manual release versions before outputs ([#1794](https://github.com/promptfoo/modelaudit/issues/1794)) ([13431f6](https://github.com/promptfoo/modelaudit/commit/13431f61124178250e79552a3770de024b796a54)) + ## [Unreleased] ### Security diff --git a/packages/modelaudit-picklescan/CHANGELOG.md b/packages/modelaudit-picklescan/CHANGELOG.md index ba8425434..07a209ab2 100644 --- a/packages/modelaudit-picklescan/CHANGELOG.md +++ b/packages/modelaudit-picklescan/CHANGELOG.md @@ -5,6 +5,18 @@ All notable changes to `modelaudit-picklescan` will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this package adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [0.1.11](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.10...modelaudit-picklescan-v0.1.11) (2026-10-03) + + +### Bug Fixes + +* **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) +* **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) +* **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) +* **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) +* **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) +* preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) + ## [Unreleased] ### Bug Fixes diff --git a/packages/modelaudit-picklescan/Cargo.toml b/packages/modelaudit-picklescan/Cargo.toml index 23637ebf1..271c14290 100644 --- a/packages/modelaudit-picklescan/Cargo.toml +++ b/packages/modelaudit-picklescan/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "modelaudit-picklescan-rust" -version = "0.1.10" # x-release-please-version +version = "0.1.11" # x-release-please-version edition = "2021" rust-version = "1.83" description = "Native pickle security scanner engine for modelaudit-picklescan" diff --git a/packages/modelaudit-picklescan/pyproject.toml b/packages/modelaudit-picklescan/pyproject.toml index 6fd378ea9..88f6a251e 100644 --- a/packages/modelaudit-picklescan/pyproject.toml +++ b/packages/modelaudit-picklescan/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "modelaudit-picklescan" -version = "0.1.10" # x-release-please-version +version = "0.1.11" # x-release-please-version description = "Standalone pickle security scanner extracted from ModelAudit" authors = [ { name = "Ian Webster", email = "ian@promptfoo.dev" }, diff --git a/pyproject.toml b/pyproject.toml index d81ace34b..dd772fed6 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "hatchling.build" [project] name = "modelaudit" -version = "0.2.52" +version = "0.2.53" description = "Static scanning library for detecting malicious code, potential backdoor indicators, and other security risks in ML model files" authors = [ { name = "Ian Webster", email = "ian@promptfoo.dev" }, From e1d3b98b717339703d4bed42bb45ee6eccfb795c Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Sat, 3 Oct 2026 00:03:15 +0000 Subject: [PATCH 2/4] chore: sync release metadata --- CHANGELOG.md | 89 ++++++++++----------- packages/modelaudit-picklescan/CHANGELOG.md | 13 ++- packages/modelaudit-picklescan/Cargo.lock | 2 +- packages/modelaudit-picklescan/uv.lock | 4 +- uv.lock | 6 +- 5 files changed, 56 insertions(+), 58 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1a4fdee4c..cd31b55b0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,53 +7,52 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [0.2.53](https://github.com/promptfoo/modelaudit/compare/v0.2.52...v0.2.53) (2026-10-03) - ### Bug Fixes -* avoid C&C signal for check_input_dim identifiers ([#1847](https://github.com/promptfoo/modelaudit/issues/1847)) ([f906f9a](https://github.com/promptfoo/modelaudit/commit/f906f9a90a0dc692a4d1dd5af69bf267aa47b04c)) -* **cache:** ignore macOS file access-time events ([#1821](https://github.com/promptfoo/modelaudit/issues/1821)) ([b5341b5](https://github.com/promptfoo/modelaudit/commit/b5341b5a35c86edba3b315af92ea2a431700156b)) -* **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) -* **cache:** keep Windows probes out of concurrently scanned trees ([#1795](https://github.com/promptfoo/modelaudit/issues/1795)) ([c29586b](https://github.com/promptfoo/modelaudit/commit/c29586b09a29f7cf8bbba6e9e4a0a74e006cc27f)) -* **cache:** preserve locked probes under directory aliases ([#1787](https://github.com/promptfoo/modelaudit/issues/1787)) ([caa2afe](https://github.com/promptfoo/modelaudit/commit/caa2afea1c2d961aef19d1b149f0c9b8fe20c72f)) -* **cache:** preserve macOS entries during ancestor churn ([#1800](https://github.com/promptfoo/modelaudit/issues/1800)) ([2c3512b](https://github.com/promptfoo/modelaudit/commit/2c3512b97cf01ecbce632873cf6e1e17a64b75c3)) -* **cache:** preserve Windows source fingerprint cache hits ([#1793](https://github.com/promptfoo/modelaudit/issues/1793)) ([f27ebac](https://github.com/promptfoo/modelaudit/commit/f27ebacdd4008eedf902f6ab87d9d5420a5fa66b)) -* **cache:** update scan-result entries atomically on hits ([#1809](https://github.com/promptfoo/modelaudit/issues/1809)) ([a9720c0](https://github.com/promptfoo/modelaudit/commit/a9720c0af126fd2bc3f3c2f76228320336103202)) -* **ci:** accept rotated pinned checkout digests ([#1799](https://github.com/promptfoo/modelaudit/issues/1799)) ([704e070](https://github.com/promptfoo/modelaudit/commit/704e07022f814953ebbf1cadb583cda29b58e6eb)) -* **ci:** increase nightly correctness shard capacity ([#1866](https://github.com/promptfoo/modelaudit/issues/1866)) ([7bb0378](https://github.com/promptfoo/modelaudit/commit/7bb03789e0d821709a1d994d778617a715c2251b)) -* **ci:** route hash timing test to performance lane ([#1824](https://github.com/promptfoo/modelaudit/issues/1824)) ([b4c10f2](https://github.com/promptfoo/modelaudit/commit/b4c10f2fe39a253c9d10f60fea3b8803c850db8d)) -* compact ONNX runtime lineage fanout ([#1845](https://github.com/promptfoo/modelaudit/issues/1845)) ([4b7ebbc](https://github.com/promptfoo/modelaudit/commit/4b7ebbc4e179d20b1a864c6eb9b7ab2ffdee6010)) -* **deps:** bump anyio from 4.13.0 to 4.14.2 ([#1855](https://github.com/promptfoo/modelaudit/issues/1855)) ([e635b8a](https://github.com/promptfoo/modelaudit/commit/e635b8ac950964d473742fe70f1bc45995d200cc)) -* **deps:** bump gitpython from 3.1.51 to 3.1.54 ([#1786](https://github.com/promptfoo/modelaudit/issues/1786)) ([32de965](https://github.com/promptfoo/modelaudit/commit/32de965e4345b9749e6cd8bb88f5a7e01a08933b)) -* **deps:** bump oauthlib from 3.3.1 to 4.0.0 ([#1860](https://github.com/promptfoo/modelaudit/issues/1860)) ([72d3777](https://github.com/promptfoo/modelaudit/commit/72d3777374f23165d63b6c28bb510cc2de07cd23)) -* **deps:** harden audit coverage and vulnerable packages ([#1808](https://github.com/promptfoo/modelaudit/issues/1808)) ([995767e](https://github.com/promptfoo/modelaudit/commit/995767ed16bda0f6019d27b02239ed308dd669b6)) -* **deps:** prevent incompatible XGBoost Renovate upgrades ([#1810](https://github.com/promptfoo/modelaudit/issues/1810)) ([ee2025e](https://github.com/promptfoo/modelaudit/commit/ee2025e3a65273b8ae3aa4f7dbb313dffac3dd89)) -* **deps:** update dependency xgboost to >=3.4,<3.5 ([#1805](https://github.com/promptfoo/modelaudit/issues/1805)) ([e84cf95](https://github.com/promptfoo/modelaudit/commit/e84cf9566c5a6da144a17ebe7a3e30812a60184b)) -* **docker:** upgrade vulnerable runtime Debian packages ([#1849](https://github.com/promptfoo/modelaudit/issues/1849)) ([fafb9fb](https://github.com/promptfoo/modelaudit/commit/fafb9fb1cbd215d8152f9863dab4c6fd4764f5ce)) -* **docker:** upgrade vulnerable util-linux runtime packages ([#1813](https://github.com/promptfoo/modelaudit/issues/1813)) ([521e941](https://github.com/promptfoo/modelaudit/commit/521e94164e0e1b7ce488f0b405b7ab48404776cd)) -* downgrade passive model metadata URLs ([#1837](https://github.com/promptfoo/modelaudit/issues/1837)) ([de299cf](https://github.com/promptfoo/modelaudit/commit/de299cfebc3e3597b50f98b01bb598dea408b321)) -* **ggml:** detect embedded ZIP polyglot payloads ([#1780](https://github.com/promptfoo/modelaudit/issues/1780)) ([9631527](https://github.com/promptfoo/modelaudit/commit/9631527b3e81e0458fe9e0242c3178af406bfa5f)) -* ignore ONNX tensor bytes for network text ([#1840](https://github.com/promptfoo/modelaudit/issues/1840)) ([12c6287](https://github.com/promptfoo/modelaudit/commit/12c6287d655cd97ba46833c6fa31f8e983ea7a4e)) -* install tomli for Python 3.10 runtime ([#1843](https://github.com/promptfoo/modelaudit/issues/1843)) ([242e08b](https://github.com/promptfoo/modelaudit/commit/242e08b71c454c6e573c2ba9a060138b5a40920f)) -* **joblib:** fail closed on inconclusive warning scans ([#1796](https://github.com/promptfoo/modelaudit/issues/1796)) ([a54bddc](https://github.com/promptfoo/modelaudit/commit/a54bddcb3b35feaa2d1678246da3e6bc8fbe3890)) -* **mlflow:** restore SQL-backed registry support ([#1818](https://github.com/promptfoo/modelaudit/issues/1818)) ([3e4e3c9](https://github.com/promptfoo/modelaudit/commit/3e4e3c9619c07eda82543c7c288858d25d695dd9)) -* **network:** block README remote-code trust bypasses ([#1788](https://github.com/promptfoo/modelaudit/issues/1788)) ([65111fe](https://github.com/promptfoo/modelaudit/commit/65111fe16b263a31e989ba327f1c84ff84c6f964)) -* **network:** preserve detections in README environment files ([#1790](https://github.com/promptfoo/modelaudit/issues/1790)) ([5c1b267](https://github.com/promptfoo/modelaudit/commit/5c1b2671f372655177992fda5a35039b602d67a9)) -* **network:** reject side-effectful model-card image examples ([#1825](https://github.com/promptfoo/modelaudit/issues/1825)) ([56417b8](https://github.com/promptfoo/modelaudit/commit/56417b801fc83cde10ba6d2046441af3c9636b50)) -* **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) -* **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) -* **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) -* **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) -* preserve caller-owned Hugging Face cache sidecars ([#1792](https://github.com/promptfoo/modelaudit/issues/1792)) ([eeb0be6](https://github.com/promptfoo/modelaudit/commit/eeb0be69336e668f2b7c341fd2d90886bb43ccdd)) -* preserve ONNX shape provenance during weight analysis ([#1838](https://github.com/promptfoo/modelaudit/issues/1838)) ([54d14c3](https://github.com/promptfoo/modelaudit/commit/54d14c3ad15ca8dd3ef41f2454163e0b834f855f)) -* preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) -* recognize bounded official image downloads in model cards ([#1784](https://github.com/promptfoo/modelaudit/issues/1784)) ([64d4f52](https://github.com/promptfoo/modelaudit/commit/64d4f5238573f8d96283ebb241e6ae42258f1140)) -* remove tensor_name_count retention budget dimension for remote SafeTensors ([#1822](https://github.com/promptfoo/modelaudit/issues/1822)) ([4c24e17](https://github.com/promptfoo/modelaudit/commit/4c24e1701c456b2bd9256e4d09429fcacd1075fa)) -* safely suppress verified Hugging Face model-card image examples ([#1791](https://github.com/promptfoo/modelaudit/issues/1791)) ([6ee2b36](https://github.com/promptfoo/modelaudit/commit/6ee2b368f029d8a9858363938068cbde766b2e2e)) -* scan encoded pickle metadata within byte budget ([#1839](https://github.com/promptfoo/modelaudit/issues/1839)) ([169cd17](https://github.com/promptfoo/modelaudit/commit/169cd177a6769d5f461abc75f645bea5f5a2260d)) -* **tests:** preserve fail-closed multi-array Joblib scans ([#1819](https://github.com/promptfoo/modelaudit/issues/1819)) ([217f127](https://github.com/promptfoo/modelaudit/commit/217f1270cfa115c6409823556e5170487930fb64)) -* treat CoreML license references as informational ([#1852](https://github.com/promptfoo/modelaudit/issues/1852)) ([604bed5](https://github.com/promptfoo/modelaudit/commit/604bed57db2352116ff9099933e560e301d1ef11)) -* trust complete legacy PyTorch storage layout ([#1850](https://github.com/promptfoo/modelaudit/issues/1850)) ([08d9fee](https://github.com/promptfoo/modelaudit/commit/08d9fee29cf671705b892ed8bb20d9e5625f742b)) -* validate manual release versions before outputs ([#1794](https://github.com/promptfoo/modelaudit/issues/1794)) ([13431f6](https://github.com/promptfoo/modelaudit/commit/13431f61124178250e79552a3770de024b796a54)) +- avoid C&C signal for check_input_dim identifiers ([#1847](https://github.com/promptfoo/modelaudit/issues/1847)) ([f906f9a](https://github.com/promptfoo/modelaudit/commit/f906f9a90a0dc692a4d1dd5af69bf267aa47b04c)) +- **cache:** ignore macOS file access-time events ([#1821](https://github.com/promptfoo/modelaudit/issues/1821)) ([b5341b5](https://github.com/promptfoo/modelaudit/commit/b5341b5a35c86edba3b315af92ea2a431700156b)) +- **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) +- **cache:** keep Windows probes out of concurrently scanned trees ([#1795](https://github.com/promptfoo/modelaudit/issues/1795)) ([c29586b](https://github.com/promptfoo/modelaudit/commit/c29586b09a29f7cf8bbba6e9e4a0a74e006cc27f)) +- **cache:** preserve locked probes under directory aliases ([#1787](https://github.com/promptfoo/modelaudit/issues/1787)) ([caa2afe](https://github.com/promptfoo/modelaudit/commit/caa2afea1c2d961aef19d1b149f0c9b8fe20c72f)) +- **cache:** preserve macOS entries during ancestor churn ([#1800](https://github.com/promptfoo/modelaudit/issues/1800)) ([2c3512b](https://github.com/promptfoo/modelaudit/commit/2c3512b97cf01ecbce632873cf6e1e17a64b75c3)) +- **cache:** preserve Windows source fingerprint cache hits ([#1793](https://github.com/promptfoo/modelaudit/issues/1793)) ([f27ebac](https://github.com/promptfoo/modelaudit/commit/f27ebacdd4008eedf902f6ab87d9d5420a5fa66b)) +- **cache:** update scan-result entries atomically on hits ([#1809](https://github.com/promptfoo/modelaudit/issues/1809)) ([a9720c0](https://github.com/promptfoo/modelaudit/commit/a9720c0af126fd2bc3f3c2f76228320336103202)) +- **ci:** accept rotated pinned checkout digests ([#1799](https://github.com/promptfoo/modelaudit/issues/1799)) ([704e070](https://github.com/promptfoo/modelaudit/commit/704e07022f814953ebbf1cadb583cda29b58e6eb)) +- **ci:** increase nightly correctness shard capacity ([#1866](https://github.com/promptfoo/modelaudit/issues/1866)) ([7bb0378](https://github.com/promptfoo/modelaudit/commit/7bb03789e0d821709a1d994d778617a715c2251b)) +- **ci:** route hash timing test to performance lane ([#1824](https://github.com/promptfoo/modelaudit/issues/1824)) ([b4c10f2](https://github.com/promptfoo/modelaudit/commit/b4c10f2fe39a253c9d10f60fea3b8803c850db8d)) +- compact ONNX runtime lineage fanout ([#1845](https://github.com/promptfoo/modelaudit/issues/1845)) ([4b7ebbc](https://github.com/promptfoo/modelaudit/commit/4b7ebbc4e179d20b1a864c6eb9b7ab2ffdee6010)) +- **deps:** bump anyio from 4.13.0 to 4.14.2 ([#1855](https://github.com/promptfoo/modelaudit/issues/1855)) ([e635b8a](https://github.com/promptfoo/modelaudit/commit/e635b8ac950964d473742fe70f1bc45995d200cc)) +- **deps:** bump gitpython from 3.1.51 to 3.1.54 ([#1786](https://github.com/promptfoo/modelaudit/issues/1786)) ([32de965](https://github.com/promptfoo/modelaudit/commit/32de965e4345b9749e6cd8bb88f5a7e01a08933b)) +- **deps:** bump oauthlib from 3.3.1 to 4.0.0 ([#1860](https://github.com/promptfoo/modelaudit/issues/1860)) ([72d3777](https://github.com/promptfoo/modelaudit/commit/72d3777374f23165d63b6c28bb510cc2de07cd23)) +- **deps:** harden audit coverage and vulnerable packages ([#1808](https://github.com/promptfoo/modelaudit/issues/1808)) ([995767e](https://github.com/promptfoo/modelaudit/commit/995767ed16bda0f6019d27b02239ed308dd669b6)) +- **deps:** prevent incompatible XGBoost Renovate upgrades ([#1810](https://github.com/promptfoo/modelaudit/issues/1810)) ([ee2025e](https://github.com/promptfoo/modelaudit/commit/ee2025e3a65273b8ae3aa4f7dbb313dffac3dd89)) +- **deps:** update dependency xgboost to >=3.4,<3.5 ([#1805](https://github.com/promptfoo/modelaudit/issues/1805)) ([e84cf95](https://github.com/promptfoo/modelaudit/commit/e84cf9566c5a6da144a17ebe7a3e30812a60184b)) +- **docker:** upgrade vulnerable runtime Debian packages ([#1849](https://github.com/promptfoo/modelaudit/issues/1849)) ([fafb9fb](https://github.com/promptfoo/modelaudit/commit/fafb9fb1cbd215d8152f9863dab4c6fd4764f5ce)) +- **docker:** upgrade vulnerable util-linux runtime packages ([#1813](https://github.com/promptfoo/modelaudit/issues/1813)) ([521e941](https://github.com/promptfoo/modelaudit/commit/521e94164e0e1b7ce488f0b405b7ab48404776cd)) +- downgrade passive model metadata URLs ([#1837](https://github.com/promptfoo/modelaudit/issues/1837)) ([de299cf](https://github.com/promptfoo/modelaudit/commit/de299cfebc3e3597b50f98b01bb598dea408b321)) +- **ggml:** detect embedded ZIP polyglot payloads ([#1780](https://github.com/promptfoo/modelaudit/issues/1780)) ([9631527](https://github.com/promptfoo/modelaudit/commit/9631527b3e81e0458fe9e0242c3178af406bfa5f)) +- ignore ONNX tensor bytes for network text ([#1840](https://github.com/promptfoo/modelaudit/issues/1840)) ([12c6287](https://github.com/promptfoo/modelaudit/commit/12c6287d655cd97ba46833c6fa31f8e983ea7a4e)) +- install tomli for Python 3.10 runtime ([#1843](https://github.com/promptfoo/modelaudit/issues/1843)) ([242e08b](https://github.com/promptfoo/modelaudit/commit/242e08b71c454c6e573c2ba9a060138b5a40920f)) +- **joblib:** fail closed on inconclusive warning scans ([#1796](https://github.com/promptfoo/modelaudit/issues/1796)) ([a54bddc](https://github.com/promptfoo/modelaudit/commit/a54bddcb3b35feaa2d1678246da3e6bc8fbe3890)) +- **mlflow:** restore SQL-backed registry support ([#1818](https://github.com/promptfoo/modelaudit/issues/1818)) ([3e4e3c9](https://github.com/promptfoo/modelaudit/commit/3e4e3c9619c07eda82543c7c288858d25d695dd9)) +- **network:** block README remote-code trust bypasses ([#1788](https://github.com/promptfoo/modelaudit/issues/1788)) ([65111fe](https://github.com/promptfoo/modelaudit/commit/65111fe16b263a31e989ba327f1c84ff84c6f964)) +- **network:** preserve detections in README environment files ([#1790](https://github.com/promptfoo/modelaudit/issues/1790)) ([5c1b267](https://github.com/promptfoo/modelaudit/commit/5c1b2671f372655177992fda5a35039b602d67a9)) +- **network:** reject side-effectful model-card image examples ([#1825](https://github.com/promptfoo/modelaudit/issues/1825)) ([56417b8](https://github.com/promptfoo/modelaudit/commit/56417b801fc83cde10ba6d2046441af3c9636b50)) +- **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) +- **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) +- **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) +- **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) +- preserve caller-owned Hugging Face cache sidecars ([#1792](https://github.com/promptfoo/modelaudit/issues/1792)) ([eeb0be6](https://github.com/promptfoo/modelaudit/commit/eeb0be69336e668f2b7c341fd2d90886bb43ccdd)) +- preserve ONNX shape provenance during weight analysis ([#1838](https://github.com/promptfoo/modelaudit/issues/1838)) ([54d14c3](https://github.com/promptfoo/modelaudit/commit/54d14c3ad15ca8dd3ef41f2454163e0b834f855f)) +- preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) +- recognize bounded official image downloads in model cards ([#1784](https://github.com/promptfoo/modelaudit/issues/1784)) ([64d4f52](https://github.com/promptfoo/modelaudit/commit/64d4f5238573f8d96283ebb241e6ae42258f1140)) +- remove tensor_name_count retention budget dimension for remote SafeTensors ([#1822](https://github.com/promptfoo/modelaudit/issues/1822)) ([4c24e17](https://github.com/promptfoo/modelaudit/commit/4c24e1701c456b2bd9256e4d09429fcacd1075fa)) +- safely suppress verified Hugging Face model-card image examples ([#1791](https://github.com/promptfoo/modelaudit/issues/1791)) ([6ee2b36](https://github.com/promptfoo/modelaudit/commit/6ee2b368f029d8a9858363938068cbde766b2e2e)) +- scan encoded pickle metadata within byte budget ([#1839](https://github.com/promptfoo/modelaudit/issues/1839)) ([169cd17](https://github.com/promptfoo/modelaudit/commit/169cd177a6769d5f461abc75f645bea5f5a2260d)) +- **tests:** preserve fail-closed multi-array Joblib scans ([#1819](https://github.com/promptfoo/modelaudit/issues/1819)) ([217f127](https://github.com/promptfoo/modelaudit/commit/217f1270cfa115c6409823556e5170487930fb64)) +- treat CoreML license references as informational ([#1852](https://github.com/promptfoo/modelaudit/issues/1852)) ([604bed5](https://github.com/promptfoo/modelaudit/commit/604bed57db2352116ff9099933e560e301d1ef11)) +- trust complete legacy PyTorch storage layout ([#1850](https://github.com/promptfoo/modelaudit/issues/1850)) ([08d9fee](https://github.com/promptfoo/modelaudit/commit/08d9fee29cf671705b892ed8bb20d9e5625f742b)) +- validate manual release versions before outputs ([#1794](https://github.com/promptfoo/modelaudit/issues/1794)) ([13431f6](https://github.com/promptfoo/modelaudit/commit/13431f61124178250e79552a3770de024b796a54)) ## [Unreleased] diff --git a/packages/modelaudit-picklescan/CHANGELOG.md b/packages/modelaudit-picklescan/CHANGELOG.md index 07a209ab2..9f9b4087c 100644 --- a/packages/modelaudit-picklescan/CHANGELOG.md +++ b/packages/modelaudit-picklescan/CHANGELOG.md @@ -7,15 +7,14 @@ and this package adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [0.1.11](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.10...modelaudit-picklescan-v0.1.11) (2026-10-03) - ### Bug Fixes -* **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) -* **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) -* **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) -* **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) -* **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) -* preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) +- **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) +- **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) +- **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) +- **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) +- **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) +- preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) ## [Unreleased] diff --git a/packages/modelaudit-picklescan/Cargo.lock b/packages/modelaudit-picklescan/Cargo.lock index 4d1bfcd74..43ff626a4 100644 --- a/packages/modelaudit-picklescan/Cargo.lock +++ b/packages/modelaudit-picklescan/Cargo.lock @@ -16,7 +16,7 @@ checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" [[package]] name = "modelaudit-picklescan-rust" -version = "0.1.10" +version = "0.1.11" dependencies = [ "pyo3", ] diff --git a/packages/modelaudit-picklescan/uv.lock b/packages/modelaudit-picklescan/uv.lock index bef92f79f..649cb9424 100644 --- a/packages/modelaudit-picklescan/uv.lock +++ b/packages/modelaudit-picklescan/uv.lock @@ -1,8 +1,8 @@ version = 1 -revision = 3 +revision = 5 requires-python = ">=3.10" [[package]] name = "modelaudit-picklescan" -version = "0.1.10" +version = "0.1.11" source = { editable = "." } diff --git a/uv.lock b/uv.lock index b1e910679..eb6980dcd 100644 --- a/uv.lock +++ b/uv.lock @@ -1,5 +1,5 @@ version = 1 -revision = 3 +revision = 5 requires-python = ">=3.10, <3.14" resolution-markers = [ "python_full_version >= '3.13'", @@ -1982,7 +1982,7 @@ wheels = [ [[package]] name = "modelaudit" -version = "0.2.52" +version = "0.2.53" source = { editable = "." } dependencies = [ { name = "click" }, @@ -2269,7 +2269,7 @@ dev = [ [[package]] name = "modelaudit-picklescan" -version = "0.1.10" +version = "0.1.11" source = { editable = "packages/modelaudit-picklescan" } [[package]] From 4352cee5e878c50c7d8d1b7a2fc0213326e8374b Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Sat, 3 Oct 2026 00:37:42 +0000 Subject: [PATCH 3/4] fix(release): align package requirements and release notes --- AGENTS.md | 2 +- CHANGELOG.md | 29 +++++++++------------ docs/agents/release-process.md | 2 +- packages/modelaudit-picklescan/AGENTS.md | 4 +-- packages/modelaudit-picklescan/CHANGELOG.md | 8 ++---- pyproject.toml | 2 +- tests/test_dependency_lock.py | 17 +++++++++--- 7 files changed, 34 insertions(+), 30 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 9922106e7..dd8099d21 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -18,7 +18,7 @@ This repo publishes **two PyPI packages with independent versions**: | `modelaudit` | `./` (root) | `pyproject.toml` + `uv.lock` | `CHANGELOG.md` | | `modelaudit-picklescan` | `packages/modelaudit-picklescan/` | `pyproject.toml` + `Cargo.toml` | `packages/modelaudit-picklescan/CHANGELOG.md` | -Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.10,<0.2.0` — when the sibling crosses `0.2.0`, bump the constraint in the same PR or the next `modelaudit` release is uninstallable. Both packages are driven by a single `release-please` workflow (`.github/workflows/release-please.yml`) with components defined in `release-please-config.json` and current versions in `.release-please-manifest.json`. Full publishing details — trusted publishing, manual `workflow_dispatch` recovery (`root_version` / `picklescan_version`), and yank procedure — are in [`docs/agents/release-process.md`](docs/agents/release-process.md). For work inside the picklescan package, start from [`packages/modelaudit-picklescan/AGENTS.md`](packages/modelaudit-picklescan/AGENTS.md). +Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.11,<0.2.0` — when the sibling crosses `0.2.0`, bump the constraint in the same PR or the next `modelaudit` release is uninstallable. Both packages are driven by a single `release-please` workflow (`.github/workflows/release-please.yml`) with components defined in `release-please-config.json` and current versions in `.release-please-manifest.json`. Full publishing details — trusted publishing, manual `workflow_dispatch` recovery (`root_version` / `picklescan_version`), and yank procedure — are in [`docs/agents/release-process.md`](docs/agents/release-process.md). For work inside the picklescan package, start from [`packages/modelaudit-picklescan/AGENTS.md`](packages/modelaudit-picklescan/AGENTS.md). ## Mission & Principles diff --git a/CHANGELOG.md b/CHANGELOG.md index cd31b55b0..e7f427a95 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,8 +5,19 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [Unreleased] + ## [0.2.53](https://github.com/promptfoo/modelaudit/compare/v0.2.52...v0.2.53) (2026-10-03) +### Security + +- Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes. +- Upgrade locked AnyIO to 4.15.1 and GitPython to 3.1.62 to address dependency audit advisories. +- Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants. +- Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature. +- Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615. +- Preserve model-card network alerts when documented image examples contain code outside the reviewed generated forms. + ### Bug Fixes - avoid C&C signal for check_input_dim identifiers ([#1847](https://github.com/promptfoo/modelaudit/issues/1847)) ([f906f9a](https://github.com/promptfoo/modelaudit/commit/f906f9a90a0dc692a4d1dd5af69bf267aa47b04c)) @@ -53,21 +64,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - treat CoreML license references as informational ([#1852](https://github.com/promptfoo/modelaudit/issues/1852)) ([604bed5](https://github.com/promptfoo/modelaudit/commit/604bed57db2352116ff9099933e560e301d1ef11)) - trust complete legacy PyTorch storage layout ([#1850](https://github.com/promptfoo/modelaudit/issues/1850)) ([08d9fee](https://github.com/promptfoo/modelaudit/commit/08d9fee29cf671705b892ed8bb20d9e5625f742b)) - validate manual release versions before outputs ([#1794](https://github.com/promptfoo/modelaudit/issues/1794)) ([13431f6](https://github.com/promptfoo/modelaudit/commit/13431f61124178250e79552a3770de024b796a54)) - -## [Unreleased] - -### Security - -- Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes. -- Upgrade locked GitPython to 3.1.59 to address four dependency audit advisories. -- Upgrade locked GitPython to 3.1.60 to address newly disclosed dependency audit advisories. -- Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants. -- Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature. -- Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615. -- Preserve model-card network alerts when documented image examples contain code outside the reviewed generated forms. - -### Bug Fixes - - Avoid incomplete ONNX weight analysis when Gather nodes read dimensions from Shape outputs. - Avoid incomplete ONNX weight analysis when large runtime-activation fanout only adds dynamic bookkeeping lineage. - Treat documentation, license, and repository links in verified pickle and ONNX metadata as informational across supported Python versions while preserving active and unknown network destinations. @@ -98,6 +94,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Avoid command-and-control false positives for generated TorchScript `_check_input_dim` identifiers while preserving actionable `check_in` detections. - Avoid incomplete legacy PyTorch storage-layout findings after validating storage bytes when separate source-backed rebuild warnings remain. - Treat passive built-in CoreML license-reference URLs as informational while preserving active metadata URL and command detections. +- Require `modelaudit-picklescan>=0.1.11` so root upgrades receive the released scanner fixes. ## [0.2.52](https://github.com/promptfoo/modelaudit/compare/v0.2.51...v0.2.52) (2026-07-22) @@ -2637,7 +2634,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - **style**: improve code formatting and documentation standards (#12, #23) - **fix**: improve core scanner functionality and comprehensive test coverage (#11) -[unreleased]: https://github.com/promptfoo/modelaudit/compare/v0.2.52...HEAD +[unreleased]: https://github.com/promptfoo/modelaudit/compare/v0.2.53...HEAD [0.2.25]: https://github.com/promptfoo/modelaudit/compare/v0.2.24...v0.2.25 [0.2.24]: https://github.com/promptfoo/modelaudit/compare/v0.2.23...v0.2.24 [0.2.23]: https://github.com/promptfoo/modelaudit/compare/v0.2.22...v0.2.23 diff --git a/docs/agents/release-process.md b/docs/agents/release-process.md index c9a9edd74..e33b5d5a8 100644 --- a/docs/agents/release-process.md +++ b/docs/agents/release-process.md @@ -11,7 +11,7 @@ Both packages are driven by a single [release-please](https://github.com/googlea The root release intentionally omits `package-name` and `component`. Release-please reads `project.name` from `pyproject.toml` for Python updates, while the empty branch component lets a root-only grouped Release PR match `release-please--branches--main` and keeps the existing `v{X.Y.Z}` tags. Restoring a non-empty `package-name` or `component` makes root-only releases look like a different component and silently skips publication after merge. -The root `modelaudit` wheel declares a **hard dependency** on `modelaudit-picklescan>=0.1.10,<0.2.0` in `pyproject.toml`. When the sibling version crosses `0.2.0`, the constraint must be bumped in the same PR. +The root `modelaudit` wheel declares a **hard dependency** on `modelaudit-picklescan>=0.1.11,<0.2.0` in `pyproject.toml`. When the sibling version crosses `0.2.0`, the constraint must be bumped in the same PR. ## Normal flow diff --git a/packages/modelaudit-picklescan/AGENTS.md b/packages/modelaudit-picklescan/AGENTS.md index 06172b582..06a387bc7 100644 --- a/packages/modelaudit-picklescan/AGENTS.md +++ b/packages/modelaudit-picklescan/AGENTS.md @@ -4,7 +4,7 @@ Scoped agent guide for work inside `packages/modelaudit-picklescan/`. The root [ ## What this package is -`modelaudit-picklescan` is the Rust-backed pickle scanner that ships as an independent PyPI package. The root `modelaudit` wheel depends on it at runtime via a hard `modelaudit-picklescan>=0.1.10,<0.2.0` pin in the root `pyproject.toml`. +`modelaudit-picklescan` is the Rust-backed pickle scanner that ships as an independent PyPI package. The root `modelaudit` wheel depends on it at runtime via a hard `modelaudit-picklescan>=0.1.11,<0.2.0` pin in the root `pyproject.toml`. - **Public API** — exported from `src/modelaudit_picklescan/__init__.py`: `PickleScanner`, `ScanOptions`, `scan_file`, `scan_bytes`, `scan_stream`, `shared_source_sensitive_caches`, `PickleReport`, `Finding`, `Notice`, `ScanError`, `Severity`, `ScanStatus`, `SafetyVerdict`, `CoverageSummary`. Treat these names as a stable surface. - **Rust engine** — `rust/src/` compiled to `modelaudit_picklescan._rust` via maturin + PyO3. Rust 1.83+, edition 2021. @@ -74,7 +74,7 @@ Root-level validation (`uv run ruff check modelaudit/ packages/modelaudit-pickle - Release tag format: `modelaudit-picklescan-v{X.Y.Z}`. - Bumps are driven by Conventional Commits that **touch files inside `packages/modelaudit-picklescan/`**. Commits that only touch `modelaudit/` or the repo root do not bump this package. -When this package reaches `0.2.0`, the root `pyproject.toml` `modelaudit-picklescan>=0.1.10,<0.2.0` constraint must be widened in the same PR, or the next `modelaudit` release will be uninstallable. +When this package reaches `0.2.0`, the root `pyproject.toml` `modelaudit-picklescan>=0.1.11,<0.2.0` constraint must be widened in the same PR, or the next `modelaudit` release will be uninstallable. ## Publishing diff --git a/packages/modelaudit-picklescan/CHANGELOG.md b/packages/modelaudit-picklescan/CHANGELOG.md index 9f9b4087c..abfbb09d5 100644 --- a/packages/modelaudit-picklescan/CHANGELOG.md +++ b/packages/modelaudit-picklescan/CHANGELOG.md @@ -5,21 +5,17 @@ All notable changes to `modelaudit-picklescan` will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this package adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [Unreleased] + ## [0.1.11](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.10...modelaudit-picklescan-v0.1.11) (2026-10-03) ### Bug Fixes -- **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8)) - **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed)) - **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244)) - **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7)) - **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b)) - preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26)) - -## [Unreleased] - -### Bug Fixes - - Ignore canonical PyTorch storage persistent-ID globals during source-sensitive call-graph enrichment. - Report which snapshot gate invalidated a shared call-graph source-stability failure. - Validate bounded batched PyTorch state-dictionary entries without falsely flagging canonical tensor reconstruction. diff --git a/pyproject.toml b/pyproject.toml index dd772fed6..b1897aa5c 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -53,7 +53,7 @@ dependencies = [ "protobuf>=5.29.0", "msgpack>=1.2.1,<2.0", "tomli>=2.0.0; python_version < '3.11'", - "modelaudit-picklescan>=0.1.10,<0.2.0", + "modelaudit-picklescan>=0.1.11,<0.2.0", ] [project.optional-dependencies] diff --git a/tests/test_dependency_lock.py b/tests/test_dependency_lock.py index cfb76589e..62bd4c44a 100644 --- a/tests/test_dependency_lock.py +++ b/tests/test_dependency_lock.py @@ -5,6 +5,7 @@ from pathlib import Path import pytest +from packaging.requirements import Requirement try: import tomllib @@ -18,7 +19,6 @@ PICKLESCAN_PYPROJECT = ROOT_DIR / "packages" / "modelaudit-picklescan" / "pyproject.toml" PATCHED_GITPYTHON_FLOOR = (3, 1, 60) PINNED_MATURIN_BACKEND = "maturin===1.13.3" -REQUIRED_PICKLESCAN_RELEASE = "modelaudit-picklescan>=0.1.10,<0.2.0" PATCHED_PY7ZR_REQUIREMENT = "py7zr>=1.1.3" PY7ZR_EXTRAS = ("sevenzip", "all-ci", "all") PATCHED_MLFLOW_CLIENT_REQUIREMENT = "mlflow-skinny>=3.13.0" @@ -137,8 +137,19 @@ def test_picklescan_build_backend_is_exactly_pinned() -> None: def test_root_requires_hardened_picklescan_release() -> None: root_config = tomllib.loads(ROOT_PYPROJECT.read_text(encoding="utf-8")) - - assert REQUIRED_PICKLESCAN_RELEASE in root_config["project"]["dependencies"] + dependency = next( + requirement + for entry in root_config["project"]["dependencies"] + if (requirement := Requirement(entry)).name == "modelaudit-picklescan" + ) + + assert dependency.marker is None + # Root upgrades must receive these fixes, while later floor increases remain valid. + assert not dependency.specifier.contains("0.1.10", prereleases=True) + assert not dependency.specifier.contains("0.1.11rc1", prereleases=True) + assert not dependency.specifier.contains("0.2.0", prereleases=True) + locked_version = ".".join(str(part) for part in _locked_version(_lock_package_block("modelaudit-picklescan"))) + assert dependency.specifier.contains(locked_version) def test_py7zr_extras_require_patched_release() -> None: From 2818eee523917f4f4c3d3fe791defd92d4bec625 Mon Sep 17 00:00:00 2001 From: Michael D'Angelo Date: Sat, 3 Oct 2026 01:09:57 +0000 Subject: [PATCH 4/4] test(deps): enforce explicit picklescan version bounds --- tests/test_dependency_lock.py | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/tests/test_dependency_lock.py b/tests/test_dependency_lock.py index 62bd4c44a..9866da2e4 100644 --- a/tests/test_dependency_lock.py +++ b/tests/test_dependency_lock.py @@ -6,6 +6,7 @@ import pytest from packaging.requirements import Requirement +from packaging.version import Version try: import tomllib @@ -145,9 +146,11 @@ def test_root_requires_hardened_picklescan_release() -> None: assert dependency.marker is None # Root upgrades must receive these fixes, while later floor increases remain valid. - assert not dependency.specifier.contains("0.1.10", prereleases=True) - assert not dependency.specifier.contains("0.1.11rc1", prereleases=True) - assert not dependency.specifier.contains("0.2.0", prereleases=True) + bounds = {specifier.operator: specifier.version for specifier in dependency.specifier} + assert len(dependency.specifier) == 2 + assert set(bounds) == {">=", "<"} + assert Version(bounds[">="]) >= Version("0.1.11") + assert Version(bounds["<"]) == Version("0.2.0") locked_version = ".".join(str(part) for part in _locked_version(_lock_package_block("modelaudit-picklescan"))) assert dependency.specifier.contains(locked_version)