diff --git a/.release-please-manifest.json b/.release-please-manifest.json index 78e1adfd6..948034ba7 100644 --- a/.release-please-manifest.json +++ b/.release-please-manifest.json @@ -1,4 +1,4 @@ { - ".": "0.2.53", - "packages/modelaudit-picklescan": "0.1.11" + ".": "0.2.54", + "packages/modelaudit-picklescan": "0.1.12" } diff --git a/CHANGELOG.md b/CHANGELOG.md index 087498d05..2132d62ef 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [0.2.54](https://github.com/promptfoo/modelaudit/compare/v0.2.53...v0.2.54) (2026-10-06) + ### Security - Require GitPython 3.2.0 or newer in the `mlflow`, `all-ci`, and `all` extras and lockfile to fix `Remote.pull()` refspec option injection ([GHSA-f9j4-qggq-h239](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-f9j4-qggq-h239)). @@ -32,6 +34,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Preserve native SafeTensors routing when a valid bounded header also resembles an FDICT zlib stream. - Avoid false incomplete pickle scans when Python lazily refreshes an import-directory cache after a change made before scanning. +### Features + +- preserve raw evidence in scan output and diagnostics ([#1870](https://github.com/promptfoo/modelaudit/issues/1870)) ([86c40e4](https://github.com/promptfoo/modelaudit/commit/86c40e49b97fcc6b87b6cc44ef5e7fa15f715844)) + +### Bug Fixes + +- avoid PyTorch storage prefix discovery gaps ([#1853](https://github.com/promptfoo/modelaudit/issues/1853)) ([fd02475](https://github.com/promptfoo/modelaudit/commit/fd024759e36f50da5d36d1d5923ad1c4cabb160d)) +- **deps:** enforce GitPython and AnyIO security floors ([#1857](https://github.com/promptfoo/modelaudit/issues/1857)) ([b80c705](https://github.com/promptfoo/modelaudit/commit/b80c70516e446b48ef3e86d94910db9000539ecb)) +- **picklescan:** bound repeated scalar probe work ([#1878](https://github.com/promptfoo/modelaudit/issues/1878)) ([3b63c24](https://github.com/promptfoo/modelaudit/commit/3b63c240906122cbd95f573baa3c82901a38b0cf)) +- refresh importer snapshots between pickle scans ([#1877](https://github.com/promptfoo/modelaudit/issues/1877)) ([9b60dd2](https://github.com/promptfoo/modelaudit/commit/9b60dd239f7b0bd20a6016afda97275c7b40bb4f)) +- **safetensors:** preserve native FDICT-shaped headers ([#1863](https://github.com/promptfoo/modelaudit/issues/1863)) ([2a5185a](https://github.com/promptfoo/modelaudit/commit/2a5185a32a3993ac6188b20a04fe6cec7cc2eddc)) + ## [0.2.53](https://github.com/promptfoo/modelaudit/compare/v0.2.52...v0.2.53) (2026-10-03) ### Security diff --git a/packages/modelaudit-picklescan/CHANGELOG.md b/packages/modelaudit-picklescan/CHANGELOG.md index 2a3f4edee..ca0c3c641 100644 --- a/packages/modelaudit-picklescan/CHANGELOG.md +++ b/packages/modelaudit-picklescan/CHANGELOG.md @@ -7,11 +7,18 @@ and this package adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [0.1.12](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.11...modelaudit-picklescan-v0.1.12) (2026-10-06) + ### Fixed - Reuse scalar-stream skipping during nested storage probes and bound matcher repetition memory so long runs of harmless scalar pickles do not delay scan timeout handling; preserve nested payload detection. - Refresh cached import-directory snapshots between scans so an earlier directory change does not cause a false incomplete call-graph result when Python refreshes its import cache. +### Bug Fixes + +- **picklescan:** bound repeated scalar probe work ([#1878](https://github.com/promptfoo/modelaudit/issues/1878)) ([3b63c24](https://github.com/promptfoo/modelaudit/commit/3b63c240906122cbd95f573baa3c82901a38b0cf)) +- refresh importer snapshots between pickle scans ([#1877](https://github.com/promptfoo/modelaudit/issues/1877)) ([9b60dd2](https://github.com/promptfoo/modelaudit/commit/9b60dd239f7b0bd20a6016afda97275c7b40bb4f)) + ## [0.1.11](https://github.com/promptfoo/modelaudit/compare/modelaudit-picklescan-v0.1.10...modelaudit-picklescan-v0.1.11) (2026-10-03) ### Bug Fixes diff --git a/packages/modelaudit-picklescan/Cargo.lock b/packages/modelaudit-picklescan/Cargo.lock index 68e5ab39f..7d00aeb1c 100644 --- a/packages/modelaudit-picklescan/Cargo.lock +++ b/packages/modelaudit-picklescan/Cargo.lock @@ -16,7 +16,7 @@ checksum = "ce5d3ddc6d3fa000eb1536d85e147bfe31aacaba692ed6a876f95cb7c855be78" [[package]] name = "modelaudit-picklescan-rust" -version = "0.1.11" +version = "0.1.12" dependencies = [ "pyo3", ] diff --git a/packages/modelaudit-picklescan/Cargo.toml b/packages/modelaudit-picklescan/Cargo.toml index 271c14290..d8d2c505a 100644 --- a/packages/modelaudit-picklescan/Cargo.toml +++ b/packages/modelaudit-picklescan/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "modelaudit-picklescan-rust" -version = "0.1.11" # x-release-please-version +version = "0.1.12" # x-release-please-version edition = "2021" rust-version = "1.83" description = "Native pickle security scanner engine for modelaudit-picklescan" diff --git a/packages/modelaudit-picklescan/pyproject.toml b/packages/modelaudit-picklescan/pyproject.toml index 88f6a251e..46bf559d8 100644 --- a/packages/modelaudit-picklescan/pyproject.toml +++ b/packages/modelaudit-picklescan/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "modelaudit-picklescan" -version = "0.1.11" # x-release-please-version +version = "0.1.12" # x-release-please-version description = "Standalone pickle security scanner extracted from ModelAudit" authors = [ { name = "Ian Webster", email = "ian@promptfoo.dev" }, diff --git a/packages/modelaudit-picklescan/uv.lock b/packages/modelaudit-picklescan/uv.lock index 649cb9424..293e12047 100644 --- a/packages/modelaudit-picklescan/uv.lock +++ b/packages/modelaudit-picklescan/uv.lock @@ -4,5 +4,5 @@ requires-python = ">=3.10" [[package]] name = "modelaudit-picklescan" -version = "0.1.11" +version = "0.1.12" source = { editable = "." } diff --git a/pyproject.toml b/pyproject.toml index a8c950859..64aa2ab6e 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "hatchling.build" [project] name = "modelaudit" -version = "0.2.53" +version = "0.2.54" description = "Static scanning library for detecting malicious code, potential backdoor indicators, and other security risks in ML model files" authors = [ { name = "Ian Webster", email = "ian@promptfoo.dev" }, diff --git a/uv.lock b/uv.lock index f81e489a1..a0bf29f0a 100644 --- a/uv.lock +++ b/uv.lock @@ -2006,7 +2006,7 @@ wheels = [ [[package]] name = "modelaudit" -version = "0.2.53" +version = "0.2.54" source = { editable = "." } dependencies = [ { name = "anyio" }, @@ -2301,7 +2301,7 @@ dev = [ [[package]] name = "modelaudit-picklescan" -version = "0.1.11" +version = "0.1.12" source = { editable = "packages/modelaudit-picklescan" } [[package]]