Skip to content

v0.2.48

Choose a tag to compare

@github-actions github-actions released this 24 Jun 14:35
a5536a9

0.2.48 (2026-06-24)

Bug Fixes

  • accept gzip-framed NeMo archives (#1634) (7be6b46)
  • audit dependencies for source changes (#1535) (bf1e109)
  • avoid exact-budget cloud pickle false positives (#1595) (350baa0)
  • bind direct shard cache to siblings (#1543) (45bf167)
  • bound executorch zip scanning (#1546) (ff9e1ae)
  • bound jinja scalar range render probes (#1553) (c00542e)
  • bound joblib decompression output (#1522) (98f41b1)
  • bound keras zip config traversal (#1555) (6e6ba57)
  • bound manifest jinja collection traversal (#1561) (23b6ca2)
  • bound OCI layer extraction budgets (#1566) (5f96b42)
  • bound picklescan pytorch zip members (#1569) (322c01b)
  • bound protocol0 line operands (#1534) (95e27df)
  • bound sevenzip member name collection (#1574) (fb36ad8)
  • bound stream analysis reads (#1525) (d44deb8)
  • bound weight distribution tensor extraction (#1581) (dc0051c)
  • calibrate legacy PyTorch storage persistent IDs (#1652) (4a28b7f)
  • calibrate onnx custom domain findings (149cde4)
  • calibrate validated ONNX alternate framing (59ec990)
  • ci: raise test job timeout for instrumented main lane (#1625) (94e98ca)
  • clarify and enforce telemetry privacy (#1592) (33186db)
  • classify pytorch zip symlink targets (#1573) (c7e1699)
  • classify tar link escapes as symlinks (#1578) (edb65b2)
  • classify text sidecar security findings (#1465) (a3a561c)
  • cli: make streaming dry runs non-executing (c0059d8)
  • close authorization evidence redaction gaps (#1596) (4606b59)
  • close JIT replay review gaps (#1519) (69928bc)
  • close network redaction follow-up gaps (#1518) (c6fa017)
  • cloud: bound directory analysis before download (#1621) (7bf4531)
  • constrain direct sharded symlink expansion (#1463) (9a9f1df)
  • contain cloud object download paths (#1541) (17efed9)
  • contain mlflow download return paths (#1563) (4239134)
  • contextualize SafeTensors license metadata (#1661) (0904a91)
  • deduplicate onnx custom domain findings (#1656) (2bca0c0)
  • deps: require msgpack 1.2.1 (#1705) (d028a15)
  • deps: update rust crate pyo3 to 0.29.0 [security] (#1677) (a2fe49c)
  • detect explicit keras get_file tar extraction (#1556) (e15963f)
  • detect flax msgpack byte keys (#1548) (e640403)
  • detect operator archive Python execution paths (#1538) (ae81048)
  • detect pickle binunicode8 setitem abuse (#1524) (43d2fb8)
  • disable unsafe metadata deserialization (#1523) (5cf4945)
  • discover hidden executorch pickle members (#1547) (1f2059f)
  • dispatch logical model directory scanners (45532e3)
  • distrust Keras artifact runtime versions (#1559) (fd38c3b)
  • docker: preserve native architecture fallback (#1690) (8a466f4)
  • docker: update Python digest and honor target architecture (#1687) (303f7c1)
  • enforce MLflow acquisition budgets (#1442) (0d38924)
  • enforce MLflow artifact backend allowlist (#1564) (74ebeae)
  • escape text output controls (#1580) (164bbb9)
  • exclude Hugging Face cache sidecars (00dcc11)
  • fail closed on capped DVC outputs (#1472) (f854808)
  • fail closed on invalid joblib trusted tails (#1554) (4e957b0)
  • fail closed on nested protocol0 operand limits (#1536) (c018c26)
  • fail closed on raw detector errors (#1457) (85e7c8c)
  • fail closed on unresolved DVC outputs (#1488) (d3dd63f)
  • fail closed when keras h5 lacks h5py (#1432) (0e81de7)
  • fail gated Hugging Face acquisitions honestly (#1646) (8192304)
  • gguf: calibrate metadata string findings (f3e77e4)
  • harden cloud acquisition routing budgets (#1540) (d958807)
  • harden Flax regex streaming (#1600) (0c69e69)
  • harden JFrog redirect targets (#1520) (ea54e39)
  • harden Keras H5 CVE coverage (#1558) (54fd488)
  • harden large tokenizer JSON EOF ownership proof (#1695) (9edbaba)
  • harden NeMo Hydra helper arguments (#1565) (787a1ab)
  • harden NeMo Hydra I/O analysis (#1426) (6670ad3)
  • harden pickle CVE stream probing (#1603) (76352d7)
  • harden picklescan spec resolution (#1568) (b5b1355)
  • harden R named argument detection (#1510) (5c4c4ae)
  • harden streamed TAR and NeMo inspection (#1665) (c52b914)
  • harden telemetry privacy redaction (#1579) (532ae59)
  • huggingface: avoid probes for selection-skipped shards (#1633) (94a89df)
  • inspect large ONNX models without full reads (#1664) (5befbef)
  • invalidate pickle cache on source changes (#1447) (beac45c)
  • isolate legacy pytorch storage controls (#1699) (1a9b556)
  • jinja: require executable SSTI context (#1647) (4cd9a18)
  • jit: bound alias replay before safe runpy calls (#1685) (7bd62ec)
  • jit: bound passive reference replay (#1681) (e542e54)
  • keep sentencepiece tokenizers out of xgboost routing (5ac9efc)
  • llamafile: stream executable runtime coverage (#1622) (8d6c486)
  • manifest: fail closed on scan timeout (#1615) (c769097)
  • onnx: classify custom operator domains (#1614) (d5a6ac2)
  • onnx: reduce weight anomaly noise (#1608) (d5ae100)
  • paginate large Hugging Face inventories (e393dc0)
  • pickle: bound legacy PyTorch control streams (#1619) (e407fb4)
  • pickle: require source proof for framework metadata (bb38b74)
  • picklescan: bound hidden ZIP probe bytes (#1624) (e8dc55e)
  • picklescan: close encoded protocol0 probe gaps (#1594) (dfaedd1)
  • picklescan: fail closed at nested depth limits (#1583) (5eb7390)
  • picklescan: fail closed on unverifiable stream boundaries (#1521) (9cd9e67)
  • picklescan: harden encoded byte probes (#1604) (f8192be)
  • picklescan: ignore short base64 collisions (#1617) (1d1a93d)
  • picklescan: mirror cached path importer semantics (#1683) (b948f8c)
  • picklescan: preserve nested INST limit findings (#1585) (68d1d19)
  • picklescan: reject padded short payload bypasses (#1626) (4edcac0)
  • picklescan: resolve loaded extension exports directly (#1620) (ab6e58e)
  • picklescan: safely filter inert URL metadata (#1658) (8a55653)
  • picklescan: scan encoded byte literals (#1602) (21956ab)
  • picklescan: validate canonical PyTorch ZIP tensor rebuilds (#1680) (2f188ad)
  • preflight generic zip entry limits (#1549) (9da67c9)
  • preserve active HF correlation findings (#1551) (603c782)
  • preserve active HF findings (#1601) (29af2de)
  • preserve default scanner read caps (#1542) (c55de21)
  • preserve ONNX external data in HF streaming (#1635) (67fd0d4)
  • preserve OpenVINO companions in HF streaming (#1642) (2a2aebc)
  • preserve unusual docs filenames in formatter (#1533) (e1b066d)
  • prevent CatBoost credential-redaction ReDoS (#1584) (493436e)
  • preview Hugging Face dry-run scans (#1645) (fd40a81)
  • pytorch: aggregate exact pickle opcodes (#1611) (3728964)
  • pytorch: distinguish producer metadata from runtime CVEs (#1643) (beb34c6)
  • pytorch: stream bounded analysis of large legacy shards (93c0e5b)
  • pytorch: trust referenced storage members (#1654) (3a4f64b)
  • recognize GGUF BF16 tensor type (#1632) (05443d2)
  • reconcile cross-directory model shards (#1587) (b143688)
  • redact authorization evidence variants (#1544) (f3ad852)
  • redact CatBoost evidence secrets (#1428) (5e56d8a)
  • redact exported source identifiers (#1530) (6f4407d)
  • redact Keras and TensorFlow scanner evidence (#1560) (8e9d119)
  • redact keras h5 lambda previews (#1435) (9830ef6)
  • redact mlflow download errors (#1562) (5067f88)
  • redact network finding snippets (#1438) (36f26f0)
  • redact stream source urls (#1429) (77b2295)
  • reduce JIT script detector false positives and negatives (#1513) (0984542)
  • reject cleartext remote model sources (#1527) (6524032)
  • reject jfrog folder local path collisions (#1552) (e22f4e1)
  • reject symlinked CLI report outputs (#1485) (d4003a6)
  • reject undersized nested pickle budgets (#1532) (0ce9bf3)
  • report complete Hugging Face inventory capabilities (#1648) (d8888d1)
  • require defusedxml for pmml parsing (#1570) (b8053d6)
  • require explicit opt-in for PyTorch weight loading (#1582) (067dcba)
  • restore cross-platform scanner baselines (#1597) (2484ac7)
  • restore main CI coverage (#1606) (c81db69)
  • restrict auth bearer token hosts (#1539) (838f250)
  • restrict manual docker publish tags (#1526) (1abc856)
  • restrict progress hook egress (#1571) (bc9419e)
  • results: isolate nested member integrity hashes (#1666) (50e2df3)
  • results: propagate inconclusive file coverage (#1672) (4ab592f)
  • route protocol-less binary pickles (#1577) (ff68cb0)
  • routing: bound tokenizer json scanner selection (#1638) (e47be19)
  • routing: classify tokenizer text before binary formats (#1629) (067717d)
  • routing: keep media out of serialized scanners (0a65650)
  • routing: keep text assets out of Flax MessagePack (34cad20)
  • routing: prefer validated safetensors framing (#1612) (2f782ba)
  • rules: attribute format mismatches to s901 (#1613) (22bc654)
  • safetensors: accept current tensor dtypes (#1610) (fd6f0ea)
  • safetensors: accept empty tensor offsets (#1607) (9d547bb)
  • safetensors: prefer bounded framing over zlib magic (#1623) (54b01e1)
  • scan ExecuTorch raw payload indicators (#1545) (c37246d)
  • scan model links in oci layers (#1567) (f85e0ef)
  • scripts: contain corpus QA output paths (#1618) (a33b710)
  • scripts: quote whitelist model ids safely (#1616) (8f57897)
  • sniff Hugging Face selective downloads (#1412) (9576eb7)
  • stream Flax msgpack analysis (#1589) (0c13d9e)
  • stream Hugging Face SafeTensors shard headers (#1667) (e6186dc)
  • stream large Flax MessagePack tensors (16e1bec)
  • stream large Keras HDF5 inspection (0ff7b62)
  • strictly pin picklescan maturin backend (#1531) (ac07522)
  • text: contextualize tokenizer vocabulary indicators (#1653) (13431e4)
  • text: deduplicate model-card indicators (#1631) (5ff4247)
  • text: ignore pip version pins in documentation (#1630) (45e6d62)
  • text: validate basic auth credential context (#1669) (a675581)
  • tolerate picklescan reports without private metadata (cdc8b8b)
  • validate hf direct url paths (#1550) (def9169)
  • validate OCI layer member metadata (#1444) (a7235e1)
  • validate pickle getattr reconstruction (c6c4713)
  • verify rustup installer in docker builds (#1529) (51f2336)

Performance Improvements

  • hashing: read in 8 MB chunks instead of 8 KB (#1709) (6caa259)

Documentation