Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
{
".": "0.2.52",
"packages/modelaudit-picklescan": "0.1.10"
".": "0.2.53",
"packages/modelaudit-picklescan": "0.1.11"
}
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ This repo publishes **two PyPI packages with independent versions**:
| `modelaudit` | `./` (root) | `pyproject.toml` + `uv.lock` | `CHANGELOG.md` |
| `modelaudit-picklescan` | `packages/modelaudit-picklescan/` | `pyproject.toml` + `Cargo.toml` | `packages/modelaudit-picklescan/CHANGELOG.md` |

Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.10,<0.2.0` — when the sibling crosses `0.2.0`, bump the constraint in the same PR or the next `modelaudit` release is uninstallable. Both packages are driven by a single `release-please` workflow (`.github/workflows/release-please.yml`) with components defined in `release-please-config.json` and current versions in `.release-please-manifest.json`. Full publishing details — trusted publishing, manual `workflow_dispatch` recovery (`root_version` / `picklescan_version`), and yank procedure — are in [`docs/agents/release-process.md`](docs/agents/release-process.md). For work inside the picklescan package, start from [`packages/modelaudit-picklescan/AGENTS.md`](packages/modelaudit-picklescan/AGENTS.md).
Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.11,<0.2.0` — when the sibling crosses `0.2.0`, bump the constraint in the same PR or the next `modelaudit` release is uninstallable. Both packages are driven by a single `release-please` workflow (`.github/workflows/release-please.yml`) with components defined in `release-please-config.json` and current versions in `.release-please-manifest.json`. Full publishing details — trusted publishing, manual `workflow_dispatch` recovery (`root_version` / `picklescan_version`), and yank procedure — are in [`docs/agents/release-process.md`](docs/agents/release-process.md). For work inside the picklescan package, start from [`packages/modelaudit-picklescan/AGENTS.md`](packages/modelaudit-picklescan/AGENTS.md).

## Mission & Principles

Expand Down
52 changes: 49 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,18 +7,63 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.2.53](https://github.com/promptfoo/modelaudit/compare/v0.2.52...v0.2.53) (2026-10-03)

### Security

- Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes.
- Upgrade locked GitPython to 3.1.59 to address four dependency audit advisories.
- Upgrade locked GitPython to 3.1.60 to address newly disclosed dependency audit advisories.
- Upgrade locked AnyIO to 4.15.1 and GitPython to 3.1.62 to address dependency audit advisories.
- Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants.
- Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature.
- Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615.
- Preserve model-card network alerts when documented image examples contain code outside the reviewed generated forms.

### Bug Fixes

- avoid C&C signal for check_input_dim identifiers ([#1847](https://github.com/promptfoo/modelaudit/issues/1847)) ([f906f9a](https://github.com/promptfoo/modelaudit/commit/f906f9a90a0dc692a4d1dd5af69bf267aa47b04c))
- **cache:** ignore macOS file access-time events ([#1821](https://github.com/promptfoo/modelaudit/issues/1821)) ([b5341b5](https://github.com/promptfoo/modelaudit/commit/b5341b5a35c86edba3b315af92ea2a431700156b))
- **cache:** isolate Windows probes and stabilize nightly checks ([#1782](https://github.com/promptfoo/modelaudit/issues/1782)) ([47f94ee](https://github.com/promptfoo/modelaudit/commit/47f94eef3feba8e74c517114094e035c7ea837e8))
- **cache:** keep Windows probes out of concurrently scanned trees ([#1795](https://github.com/promptfoo/modelaudit/issues/1795)) ([c29586b](https://github.com/promptfoo/modelaudit/commit/c29586b09a29f7cf8bbba6e9e4a0a74e006cc27f))
- **cache:** preserve locked probes under directory aliases ([#1787](https://github.com/promptfoo/modelaudit/issues/1787)) ([caa2afe](https://github.com/promptfoo/modelaudit/commit/caa2afea1c2d961aef19d1b149f0c9b8fe20c72f))
- **cache:** preserve macOS entries during ancestor churn ([#1800](https://github.com/promptfoo/modelaudit/issues/1800)) ([2c3512b](https://github.com/promptfoo/modelaudit/commit/2c3512b97cf01ecbce632873cf6e1e17a64b75c3))
- **cache:** preserve Windows source fingerprint cache hits ([#1793](https://github.com/promptfoo/modelaudit/issues/1793)) ([f27ebac](https://github.com/promptfoo/modelaudit/commit/f27ebacdd4008eedf902f6ab87d9d5420a5fa66b))
- **cache:** update scan-result entries atomically on hits ([#1809](https://github.com/promptfoo/modelaudit/issues/1809)) ([a9720c0](https://github.com/promptfoo/modelaudit/commit/a9720c0af126fd2bc3f3c2f76228320336103202))
- **ci:** accept rotated pinned checkout digests ([#1799](https://github.com/promptfoo/modelaudit/issues/1799)) ([704e070](https://github.com/promptfoo/modelaudit/commit/704e07022f814953ebbf1cadb583cda29b58e6eb))
- **ci:** increase nightly correctness shard capacity ([#1866](https://github.com/promptfoo/modelaudit/issues/1866)) ([7bb0378](https://github.com/promptfoo/modelaudit/commit/7bb03789e0d821709a1d994d778617a715c2251b))
- **ci:** route hash timing test to performance lane ([#1824](https://github.com/promptfoo/modelaudit/issues/1824)) ([b4c10f2](https://github.com/promptfoo/modelaudit/commit/b4c10f2fe39a253c9d10f60fea3b8803c850db8d))
- compact ONNX runtime lineage fanout ([#1845](https://github.com/promptfoo/modelaudit/issues/1845)) ([4b7ebbc](https://github.com/promptfoo/modelaudit/commit/4b7ebbc4e179d20b1a864c6eb9b7ab2ffdee6010))
- **deps:** bump anyio from 4.13.0 to 4.14.2 ([#1855](https://github.com/promptfoo/modelaudit/issues/1855)) ([e635b8a](https://github.com/promptfoo/modelaudit/commit/e635b8ac950964d473742fe70f1bc45995d200cc))
- **deps:** bump gitpython from 3.1.51 to 3.1.54 ([#1786](https://github.com/promptfoo/modelaudit/issues/1786)) ([32de965](https://github.com/promptfoo/modelaudit/commit/32de965e4345b9749e6cd8bb88f5a7e01a08933b))
- **deps:** bump oauthlib from 3.3.1 to 4.0.0 ([#1860](https://github.com/promptfoo/modelaudit/issues/1860)) ([72d3777](https://github.com/promptfoo/modelaudit/commit/72d3777374f23165d63b6c28bb510cc2de07cd23))
- **deps:** harden audit coverage and vulnerable packages ([#1808](https://github.com/promptfoo/modelaudit/issues/1808)) ([995767e](https://github.com/promptfoo/modelaudit/commit/995767ed16bda0f6019d27b02239ed308dd669b6))
- **deps:** prevent incompatible XGBoost Renovate upgrades ([#1810](https://github.com/promptfoo/modelaudit/issues/1810)) ([ee2025e](https://github.com/promptfoo/modelaudit/commit/ee2025e3a65273b8ae3aa4f7dbb313dffac3dd89))
- **deps:** update dependency xgboost to &gt;=3.4,&lt;3.5 ([#1805](https://github.com/promptfoo/modelaudit/issues/1805)) ([e84cf95](https://github.com/promptfoo/modelaudit/commit/e84cf9566c5a6da144a17ebe7a3e30812a60184b))
- **docker:** upgrade vulnerable runtime Debian packages ([#1849](https://github.com/promptfoo/modelaudit/issues/1849)) ([fafb9fb](https://github.com/promptfoo/modelaudit/commit/fafb9fb1cbd215d8152f9863dab4c6fd4764f5ce))
- **docker:** upgrade vulnerable util-linux runtime packages ([#1813](https://github.com/promptfoo/modelaudit/issues/1813)) ([521e941](https://github.com/promptfoo/modelaudit/commit/521e94164e0e1b7ce488f0b405b7ab48404776cd))
- downgrade passive model metadata URLs ([#1837](https://github.com/promptfoo/modelaudit/issues/1837)) ([de299cf](https://github.com/promptfoo/modelaudit/commit/de299cfebc3e3597b50f98b01bb598dea408b321))
- **ggml:** detect embedded ZIP polyglot payloads ([#1780](https://github.com/promptfoo/modelaudit/issues/1780)) ([9631527](https://github.com/promptfoo/modelaudit/commit/9631527b3e81e0458fe9e0242c3178af406bfa5f))
- ignore ONNX tensor bytes for network text ([#1840](https://github.com/promptfoo/modelaudit/issues/1840)) ([12c6287](https://github.com/promptfoo/modelaudit/commit/12c6287d655cd97ba46833c6fa31f8e983ea7a4e))
- install tomli for Python 3.10 runtime ([#1843](https://github.com/promptfoo/modelaudit/issues/1843)) ([242e08b](https://github.com/promptfoo/modelaudit/commit/242e08b71c454c6e573c2ba9a060138b5a40920f))
- **joblib:** fail closed on inconclusive warning scans ([#1796](https://github.com/promptfoo/modelaudit/issues/1796)) ([a54bddc](https://github.com/promptfoo/modelaudit/commit/a54bddcb3b35feaa2d1678246da3e6bc8fbe3890))
- **mlflow:** restore SQL-backed registry support ([#1818](https://github.com/promptfoo/modelaudit/issues/1818)) ([3e4e3c9](https://github.com/promptfoo/modelaudit/commit/3e4e3c9619c07eda82543c7c288858d25d695dd9))
- **network:** block README remote-code trust bypasses ([#1788](https://github.com/promptfoo/modelaudit/issues/1788)) ([65111fe](https://github.com/promptfoo/modelaudit/commit/65111fe16b263a31e989ba327f1c84ff84c6f964))
- **network:** preserve detections in README environment files ([#1790](https://github.com/promptfoo/modelaudit/issues/1790)) ([5c1b267](https://github.com/promptfoo/modelaudit/commit/5c1b2671f372655177992fda5a35039b602d67a9))
- **network:** reject side-effectful model-card image examples ([#1825](https://github.com/promptfoo/modelaudit/issues/1825)) ([56417b8](https://github.com/promptfoo/modelaudit/commit/56417b801fc83cde10ba6d2046441af3c9636b50))
- **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed))
- **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244))
- **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7))
- **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b))
- preserve caller-owned Hugging Face cache sidecars ([#1792](https://github.com/promptfoo/modelaudit/issues/1792)) ([eeb0be6](https://github.com/promptfoo/modelaudit/commit/eeb0be69336e668f2b7c341fd2d90886bb43ccdd))
- preserve ONNX shape provenance during weight analysis ([#1838](https://github.com/promptfoo/modelaudit/issues/1838)) ([54d14c3](https://github.com/promptfoo/modelaudit/commit/54d14c3ad15ca8dd3ef41f2454163e0b834f855f))
- preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26))
- recognize bounded official image downloads in model cards ([#1784](https://github.com/promptfoo/modelaudit/issues/1784)) ([64d4f52](https://github.com/promptfoo/modelaudit/commit/64d4f5238573f8d96283ebb241e6ae42258f1140))
- remove tensor_name_count retention budget dimension for remote SafeTensors ([#1822](https://github.com/promptfoo/modelaudit/issues/1822)) ([4c24e17](https://github.com/promptfoo/modelaudit/commit/4c24e1701c456b2bd9256e4d09429fcacd1075fa))
- safely suppress verified Hugging Face model-card image examples ([#1791](https://github.com/promptfoo/modelaudit/issues/1791)) ([6ee2b36](https://github.com/promptfoo/modelaudit/commit/6ee2b368f029d8a9858363938068cbde766b2e2e))
- scan encoded pickle metadata within byte budget ([#1839](https://github.com/promptfoo/modelaudit/issues/1839)) ([169cd17](https://github.com/promptfoo/modelaudit/commit/169cd177a6769d5f461abc75f645bea5f5a2260d))
- **tests:** preserve fail-closed multi-array Joblib scans ([#1819](https://github.com/promptfoo/modelaudit/issues/1819)) ([217f127](https://github.com/promptfoo/modelaudit/commit/217f1270cfa115c6409823556e5170487930fb64))
- treat CoreML license references as informational ([#1852](https://github.com/promptfoo/modelaudit/issues/1852)) ([604bed5](https://github.com/promptfoo/modelaudit/commit/604bed57db2352116ff9099933e560e301d1ef11))
- trust complete legacy PyTorch storage layout ([#1850](https://github.com/promptfoo/modelaudit/issues/1850)) ([08d9fee](https://github.com/promptfoo/modelaudit/commit/08d9fee29cf671705b892ed8bb20d9e5625f742b))
- validate manual release versions before outputs ([#1794](https://github.com/promptfoo/modelaudit/issues/1794)) ([13431f6](https://github.com/promptfoo/modelaudit/commit/13431f61124178250e79552a3770de024b796a54))
- Avoid incomplete ONNX weight analysis when Gather nodes read dimensions from Shape outputs.
- Avoid incomplete ONNX weight analysis when large runtime-activation fanout only adds dynamic bookkeeping lineage.
- Treat documentation, license, and repository links in verified pickle and ONNX metadata as informational across supported Python versions while preserving active and unknown network destinations.
Expand Down Expand Up @@ -49,6 +94,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- Avoid command-and-control false positives for generated TorchScript `_check_input_dim` identifiers while preserving actionable `check_in` detections.
- Avoid incomplete legacy PyTorch storage-layout findings after validating storage bytes when separate source-backed rebuild warnings remain.
- Treat passive built-in CoreML license-reference URLs as informational while preserving active metadata URL and command detections.
- Require `modelaudit-picklescan>=0.1.11` so root upgrades receive the released scanner fixes.

## [0.2.52](https://github.com/promptfoo/modelaudit/compare/v0.2.51...v0.2.52) (2026-07-22)

Expand Down Expand Up @@ -2588,7 +2634,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- **style**: improve code formatting and documentation standards (#12, #23)
- **fix**: improve core scanner functionality and comprehensive test coverage (#11)

[unreleased]: https://github.com/promptfoo/modelaudit/compare/v0.2.52...HEAD
[unreleased]: https://github.com/promptfoo/modelaudit/compare/v0.2.53...HEAD
[0.2.25]: https://github.com/promptfoo/modelaudit/compare/v0.2.24...v0.2.25
[0.2.24]: https://github.com/promptfoo/modelaudit/compare/v0.2.23...v0.2.24
[0.2.23]: https://github.com/promptfoo/modelaudit/compare/v0.2.22...v0.2.23
Expand Down
2 changes: 1 addition & 1 deletion docs/agents/release-process.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Both packages are driven by a single [release-please](https://github.com/googlea

The root release intentionally omits `package-name` and `component`. Release-please reads `project.name` from `pyproject.toml` for Python updates, while the empty branch component lets a root-only grouped Release PR match `release-please--branches--main` and keeps the existing `v{X.Y.Z}` tags. Restoring a non-empty `package-name` or `component` makes root-only releases look like a different component and silently skips publication after merge.

The root `modelaudit` wheel declares a **hard dependency** on `modelaudit-picklescan>=0.1.10,<0.2.0` in `pyproject.toml`. When the sibling version crosses `0.2.0`, the constraint must be bumped in the same PR.
The root `modelaudit` wheel declares a **hard dependency** on `modelaudit-picklescan>=0.1.11,<0.2.0` in `pyproject.toml`. When the sibling version crosses `0.2.0`, the constraint must be bumped in the same PR.

## Normal flow

Expand Down
4 changes: 2 additions & 2 deletions packages/modelaudit-picklescan/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Scoped agent guide for work inside `packages/modelaudit-picklescan/`. The root [

## What this package is

`modelaudit-picklescan` is the Rust-backed pickle scanner that ships as an independent PyPI package. The root `modelaudit` wheel depends on it at runtime via a hard `modelaudit-picklescan>=0.1.10,<0.2.0` pin in the root `pyproject.toml`.
`modelaudit-picklescan` is the Rust-backed pickle scanner that ships as an independent PyPI package. The root `modelaudit` wheel depends on it at runtime via a hard `modelaudit-picklescan>=0.1.11,<0.2.0` pin in the root `pyproject.toml`.

- **Public API** — exported from `src/modelaudit_picklescan/__init__.py`: `PickleScanner`, `ScanOptions`, `scan_file`, `scan_bytes`, `scan_stream`, `shared_source_sensitive_caches`, `PickleReport`, `Finding`, `Notice`, `ScanError`, `Severity`, `ScanStatus`, `SafetyVerdict`, `CoverageSummary`. Treat these names as a stable surface.
- **Rust engine** — `rust/src/` compiled to `modelaudit_picklescan._rust` via maturin + PyO3. Rust 1.83+, edition 2021.
Expand Down Expand Up @@ -74,7 +74,7 @@ Root-level validation (`uv run ruff check modelaudit/ packages/modelaudit-pickle
- Release tag format: `modelaudit-picklescan-v{X.Y.Z}`.
- Bumps are driven by Conventional Commits that **touch files inside `packages/modelaudit-picklescan/`**. Commits that only touch `modelaudit/` or the repo root do not bump this package.

When this package reaches `0.2.0`, the root `pyproject.toml` `modelaudit-picklescan>=0.1.10,<0.2.0` constraint must be widened in the same PR, or the next `modelaudit` release will be uninstallable.
When this package reaches `0.2.0`, the root `pyproject.toml` `modelaudit-picklescan>=0.1.11,<0.2.0` constraint must be widened in the same PR, or the next `modelaudit` release will be uninstallable.

## Publishing

Expand Down
7 changes: 7 additions & 0 deletions packages/modelaudit-picklescan/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,15 @@ and this package adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [0.1.11](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.10...modelaudit-picklescan-v0.1.11) (2026-10-03)

### Bug Fixes

- **picklescan:** avoid scalar storage pickle false positives ([#1842](https://github.com/promptfoo/modelaudit/issues/1842)) ([7408ed1](https://github.com/promptfoo/modelaudit/commit/7408ed1ac48a202ba931a2d6efc5ac79dde4d8ed))
- **picklescan:** diagnose Windows call-graph source-stability failures ([#1789](https://github.com/promptfoo/modelaudit/issues/1789)) ([89b5024](https://github.com/promptfoo/modelaudit/commit/89b50246fc9226770d46b26e8582a6d161dc0244))
- **picklescan:** preserve nested storage probe coverage ([#1846](https://github.com/promptfoo/modelaudit/issues/1846)) ([28ad1c9](https://github.com/promptfoo/modelaudit/commit/28ad1c9b5c7b98d76b4b3db466f5c55526fd3fa7))
- **picklescan:** safely parse bounded PyTorch tensor batches ([#1783](https://github.com/promptfoo/modelaudit/issues/1783)) ([705059c](https://github.com/promptfoo/modelaudit/commit/705059c4280056a4b72106fbd474c00e270ecf0b))
- preserve PyTorch storage import trust ([#1841](https://github.com/promptfoo/modelaudit/issues/1841)) ([a2f040e](https://github.com/promptfoo/modelaudit/commit/a2f040e5af66bde03cc31ffc3ee545dd8d96fa26))
- Ignore canonical PyTorch storage persistent-ID globals during source-sensitive call-graph enrichment.
- Report which snapshot gate invalidated a shared call-graph source-stability failure.
- Validate bounded batched PyTorch state-dictionary entries without falsely flagging canonical tensor reconstruction.
Expand Down
2 changes: 1 addition & 1 deletion packages/modelaudit-picklescan/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion packages/modelaudit-picklescan/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "modelaudit-picklescan-rust"
version = "0.1.10" # x-release-please-version
version = "0.1.11" # x-release-please-version
edition = "2021"
rust-version = "1.83"
description = "Native pickle security scanner engine for modelaudit-picklescan"
Expand Down
2 changes: 1 addition & 1 deletion packages/modelaudit-picklescan/pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ build-backend = "maturin"

[project]
name = "modelaudit-picklescan"
version = "0.1.10" # x-release-please-version
version = "0.1.11" # x-release-please-version
description = "Standalone pickle security scanner extracted from ModelAudit"
authors = [
{ name = "Ian Webster", email = "ian@promptfoo.dev" },
Expand Down
4 changes: 2 additions & 2 deletions packages/modelaudit-picklescan/uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading