Skip to content

docs: Add SECURITY.md - #23

Merged
mc-nv merged 7 commits into
mainfrom
mchornyi/TRI-1935/fix-reports
Oct 6, 2026
Merged

mc-nv merged 7 commits into
mainfrom
mchornyi/TRI-1935/fix-reports

Conversation

@mc-nv

@mc-nv mc-nv commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

What does the PR do?

  • Adds SECURITY.md, which this repository did not have. Flagged by an AIVO asset review.
  • Uses NVIDIA's current standard template, as in NVIDIA/NeMo, cuda-python and Megatron-LM. Text is NVIDIA-authored, unmodified except the platform-neutral "GitHub/GitLab" wording from cuda-python.
  • Reporting policy only: no threat model or architecture section.
  • Applied across all Triton repositories.

Checklist

  • PR title reflects the change and is of format <commit_type>: <Title>
  • Changes are described in the pull request.
  • Related issues are referenced.
  • Populated github labels field
  • Added test plan and verified test passes.
  • Verified that the PR passes existing CI.
  • Verified copyright is correct on all changed files.
  • Added succinct git squash message before merging ref.
  • All template sections are filled out.
  • Optional: Additional screenshots for behavior/output changes with before/after.

Commit Type:

Check the conventional commit type
box here and add the label to the github PR.

  • build
  • ci
  • docs
  • feat
  • fix
  • perf
  • refactor
  • revert
  • style
  • test

Related PRs:

Where should the reviewer start?

  • SECURITY.md — compare against NVIDIA/NeMo/SECURITY.md for the canonical wording.

Test plan:

  • Documentation only; no code paths affected.

  • CI Pipeline ID:

Caveats:

  • NVIDIA ships two variants of the warning sentence: NVIDIA/NeMo says "through GitHub", NVIDIA/cuda-python says "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.
  • The template's PGP wording is "we encourage you" rather than a hard requirement. Kept as-is for template fidelity; raised on docs: Adopt current NVIDIA SECURITY.md template server#8997.

Background

An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Resolves: TRI-1935

@mc-nv mc-nv added the documentation Improvements or additions to documentation (docs: PRs) label Oct 3, 2026
@mc-nv mc-nv self-assigned this Oct 3, 2026
@mc-nv
mc-nv marked this pull request as ready for review October 5, 2026 16:38
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Adds security reporting guidance document.

The documentation change appears safe to merge.

Summary

The PR replaces repository-specific security guidance with NVIDIA’s standard vulnerability-reporting policy.

  • Directs reporters to NVIDIA’s submission form or PSIRT email instead of GitHub/GitLab.
  • Removes the earlier threat model and deployment assumptions.

Reviews (4) · Last reviewed commit: "docs: Adopt current NVIDIA SECURITY.md t..."

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@mc-nv
mc-nv merged commit fac30b6 into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation (docs: PRs)

Development

Successfully merging this pull request may close these issues.

2 participants