Conversation
TRI-1935
|
TRI-1935
|
Closing: SECURITY.md already exists in this repository with NVIDIA's standard reporting text, so no change is needed here. Tracked in TRI-1935. |
|
|
||
| - Web: [Security Vulnerability Submission Form](https://www.nvidia.com/object/submit-security-vulnerability.html) | ||
| - E-Mail: psirt@nvidia.com | ||
| - We encourage you to use the following PGP key for secure email communication: [NVIDIA public PGP Key for communication](https://www.nvidia.com/en-us/security/pgp-key) |
There was a problem hiding this comment.
Email encryption is optional The previous instructions told reporters to encrypt vulnerability reports sent by email. This version only encourages PGP use, while still asking reporters to include reproduction steps and proof-of-concept or exploit code. Someone following these instructions could email sensitive vulnerability details without end-to-end encryption. Please keep a clear encryption requirement for email reports or direct unencrypted reports to the web form.
How this was verified: The email reporting channel requests exploit details, and its PGP instruction is now optional rather than required.
| - We encourage you to use the following PGP key for secure email communication: [NVIDIA public PGP Key for communication](https://www.nvidia.com/en-us/security/pgp-key) | |
| - If reporting a potential vulnerability by email, please encrypt it using [NVIDIA's public PGP key](https://www.nvidia.com/en-us/security/pgp-key). |
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
What does the PR do?
NVIDIA/NeMo,NVIDIA/cuda-python,NVIDIA/Megatron-LMandNVIDIA/nvidia-container-toolkit. This repository was still on the older# Report a Security Vulnerabilityblock.NVIDIA/cuda-python, since Triton repositories are mirrored between GitHub and internal GitLab.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only. Pre-commit hooks (license header, codespell, whitespace) pass.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both hosts.**OEM Partners should contact their NVIDIA Customer Program Manager**is not present in NVIDIA's current template and is therefore dropped. Flagging in case it should be retained for NVIDIA AI Enterprise customers.Background
Raised by an AIVO asset review (securityportal.nvidia.com/aivo/assets) that flagged repositories without a SECURITY.md. This repository already had one, so the change here is to bring it onto NVIDIA's current template rather than to add a missing file.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)