Skip to content

docs: Adopt current NVIDIA SECURITY.md template - #8997

Open
mc-nv wants to merge 7 commits into
mainfrom
mchornyi/TRI-1935/fix-reports
Open

mc-nv wants to merge 7 commits into
mainfrom
mchornyi/TRI-1935/fix-reports

Conversation

@mc-nv

@mc-nv mc-nv commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What does the PR do?

  • Replaces the SECURITY.md body with NVIDIA's current standard template, as already used in NVIDIA/NeMo, NVIDIA/cuda-python, NVIDIA/Megatron-LM and NVIDIA/nvidia-container-toolkit. This repository was still on the older # Report a Security Vulnerability block.
  • Text is NVIDIA-authored and unmodified apart from the platform-neutral "GitHub/GitLab" wording taken from NVIDIA/cuda-python, since Triton repositories are mirrored between GitHub and internal GitLab.
  • Adds, relative to the previous block: the "do not report through GitHub/GitLab" guidance, the coordinated vulnerability disclosure statement with the PSIRT policies link, and the NVIDIA Product Security portal link.
  • The same change is being applied across the other Triton repositories so every repository carries an identical policy.

Checklist

  • PR title reflects the change and is of format <commit_type>: <Title>
  • Changes are described in the pull request.
  • Related issues are referenced.
  • Populated github labels field
  • Added test plan and verified test passes.
  • Verified that the PR passes existing CI.
  • Verified copyright is correct on all changed files.
  • Added succinct git squash message before merging ref.
  • All template sections are filled out.
  • Optional: Additional screenshots for behavior/output changes with before/after.

Commit Type:

Check the conventional commit type
box here and add the label to the github PR.

  • build
  • ci
  • docs
  • feat
  • fix
  • perf
  • refactor
  • revert
  • style
  • test

Related PRs:

  • The same template is applied across the other Triton repositories; tracked on TRI-1935.

Where should the reviewer start?

  • SECURITY.md — compare against NVIDIA/NeMo/SECURITY.md for the canonical wording.

Test plan:

  • Documentation only. Pre-commit hooks (license header, codespell, whitespace) pass.

  • CI Pipeline ID:

Caveats:

  • NVIDIA ships two variants of the warning sentence: NVIDIA/NeMo says "through GitHub", NVIDIA/cuda-python says "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both hosts.
  • The previous block's line **OEM Partners should contact their NVIDIA Customer Program Manager** is not present in NVIDIA's current template and is therefore dropped. Flagging in case it should be retained for NVIDIA AI Enterprise customers.

Background

Raised by an AIVO asset review (securityportal.nvidia.com/aivo/assets) that flagged repositories without a SECURITY.md. This repository already had one, so the change here is to bring it onto NVIDIA's current template rather than to add a missing file.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Resolves: TRI-1935

@mc-nv mc-nv added the Documentation Improvements or additions to documentation (docs: PRs) label Oct 5, 2026
@mc-nv mc-nv self-assigned this Oct 5, 2026
@mc-nv mc-nv added the Documentation Improvements or additions to documentation (docs: PRs) label Oct 5, 2026
@mc-nv
mc-nv marked this pull request as ready for review October 5, 2026 16:38
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Updates security reporting documentation to current template.

The PR appears safe to merge, though the optional encryption wording leaves a confidentiality concern for emailed reports.

Findings

  1. P2 Security Email encryption is optional ▶

Summary

The PR replaces the repository’s security-reporting instructions with NVIDIA’s current template.

  • It directs vulnerability reports away from public GitHub/GitLab discussions and adds PSIRT policy and Product Security links.
  • The revised email instructions make PGP encryption optional despite requesting sensitive vulnerability details.

Reviews (4) · Last reviewed commit: "docs: Adopt current NVIDIA SECURITY.md t..."

Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@mc-nv

mc-nv commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Closing: SECURITY.md already exists in this repository with NVIDIA's standard reporting text, so no change is needed here. Tracked in TRI-1935.

@mc-nv mc-nv closed this Oct 5, 2026
@mc-nv mc-nv reopened this Oct 5, 2026
@mc-nv mc-nv changed the title docs: Update SECURITY.md docs: Adopt current NVIDIA SECURITY.md template Oct 5, 2026
Comment thread SECURITY.md

- Web: [Security Vulnerability Submission Form](https://www.nvidia.com/object/submit-security-vulnerability.html)
- E-Mail: psirt@nvidia.com
- We encourage you to use the following PGP key for secure email communication: [NVIDIA public PGP Key for communication](https://www.nvidia.com/en-us/security/pgp-key)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Email encryption is optional The previous instructions told reporters to encrypt vulnerability reports sent by email. This version only encourages PGP use, while still asking reporters to include reproduction steps and proof-of-concept or exploit code. Someone following these instructions could email sensitive vulnerability details without end-to-end encryption. Please keep a clear encryption requirement for email reports or direct unencrypted reports to the web form.

How this was verified: The email reporting channel requests exploit details, and its PGP instruction is now optional rather than required.

Suggested change
- We encourage you to use the following PGP key for secure email communication: [NVIDIA public PGP Key for communication](https://www.nvidia.com/en-us/security/pgp-key)
- If reporting a potential vulnerability by email, please encrypt it using [NVIDIA's public PGP key](https://www.nvidia.com/en-us/security/pgp-key).

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Documentation Improvements or additions to documentation (docs: PRs)

Development

Successfully merging this pull request may close these issues.

2 participants