v0.2.48
0.2.48 (2026-06-24)
Bug Fixes
- accept gzip-framed NeMo archives (#1634) (7be6b46)
- audit dependencies for source changes (#1535) (bf1e109)
- avoid exact-budget cloud pickle false positives (#1595) (350baa0)
- bind direct shard cache to siblings (#1543) (45bf167)
- bound executorch zip scanning (#1546) (ff9e1ae)
- bound jinja scalar range render probes (#1553) (c00542e)
- bound joblib decompression output (#1522) (98f41b1)
- bound keras zip config traversal (#1555) (6e6ba57)
- bound manifest jinja collection traversal (#1561) (23b6ca2)
- bound OCI layer extraction budgets (#1566) (5f96b42)
- bound picklescan pytorch zip members (#1569) (322c01b)
- bound protocol0 line operands (#1534) (95e27df)
- bound sevenzip member name collection (#1574) (fb36ad8)
- bound stream analysis reads (#1525) (d44deb8)
- bound weight distribution tensor extraction (#1581) (dc0051c)
- calibrate legacy PyTorch storage persistent IDs (#1652) (4a28b7f)
- calibrate onnx custom domain findings (149cde4)
- calibrate validated ONNX alternate framing (59ec990)
- ci: raise test job timeout for instrumented main lane (#1625) (94e98ca)
- clarify and enforce telemetry privacy (#1592) (33186db)
- classify pytorch zip symlink targets (#1573) (c7e1699)
- classify tar link escapes as symlinks (#1578) (edb65b2)
- classify text sidecar security findings (#1465) (a3a561c)
- cli: make streaming dry runs non-executing (c0059d8)
- close authorization evidence redaction gaps (#1596) (4606b59)
- close JIT replay review gaps (#1519) (69928bc)
- close network redaction follow-up gaps (#1518) (c6fa017)
- cloud: bound directory analysis before download (#1621) (7bf4531)
- constrain direct sharded symlink expansion (#1463) (9a9f1df)
- contain cloud object download paths (#1541) (17efed9)
- contain mlflow download return paths (#1563) (4239134)
- contextualize SafeTensors license metadata (#1661) (0904a91)
- deduplicate onnx custom domain findings (#1656) (2bca0c0)
- deps: require msgpack 1.2.1 (#1705) (d028a15)
- deps: update rust crate pyo3 to 0.29.0 [security] (#1677) (a2fe49c)
- detect explicit keras get_file tar extraction (#1556) (e15963f)
- detect flax msgpack byte keys (#1548) (e640403)
- detect operator archive Python execution paths (#1538) (ae81048)
- detect pickle binunicode8 setitem abuse (#1524) (43d2fb8)
- disable unsafe metadata deserialization (#1523) (5cf4945)
- discover hidden executorch pickle members (#1547) (1f2059f)
- dispatch logical model directory scanners (45532e3)
- distrust Keras artifact runtime versions (#1559) (fd38c3b)
- docker: preserve native architecture fallback (#1690) (8a466f4)
- docker: update Python digest and honor target architecture (#1687) (303f7c1)
- enforce MLflow acquisition budgets (#1442) (0d38924)
- enforce MLflow artifact backend allowlist (#1564) (74ebeae)
- escape text output controls (#1580) (164bbb9)
- exclude Hugging Face cache sidecars (00dcc11)
- fail closed on capped DVC outputs (#1472) (f854808)
- fail closed on invalid joblib trusted tails (#1554) (4e957b0)
- fail closed on nested protocol0 operand limits (#1536) (c018c26)
- fail closed on raw detector errors (#1457) (85e7c8c)
- fail closed on unresolved DVC outputs (#1488) (d3dd63f)
- fail closed when keras h5 lacks h5py (#1432) (0e81de7)
- fail gated Hugging Face acquisitions honestly (#1646) (8192304)
- gguf: calibrate metadata string findings (f3e77e4)
- harden cloud acquisition routing budgets (#1540) (d958807)
- harden Flax regex streaming (#1600) (0c69e69)
- harden JFrog redirect targets (#1520) (ea54e39)
- harden Keras H5 CVE coverage (#1558) (54fd488)
- harden large tokenizer JSON EOF ownership proof (#1695) (9edbaba)
- harden NeMo Hydra helper arguments (#1565) (787a1ab)
- harden NeMo Hydra I/O analysis (#1426) (6670ad3)
- harden pickle CVE stream probing (#1603) (76352d7)
- harden picklescan spec resolution (#1568) (b5b1355)
- harden R named argument detection (#1510) (5c4c4ae)
- harden streamed TAR and NeMo inspection (#1665) (c52b914)
- harden telemetry privacy redaction (#1579) (532ae59)
- huggingface: avoid probes for selection-skipped shards (#1633) (94a89df)
- inspect large ONNX models without full reads (#1664) (5befbef)
- invalidate pickle cache on source changes (#1447) (beac45c)
- isolate legacy pytorch storage controls (#1699) (1a9b556)
- jinja: require executable SSTI context (#1647) (4cd9a18)
- jit: bound alias replay before safe runpy calls (#1685) (7bd62ec)
- jit: bound passive reference replay (#1681) (e542e54)
- keep sentencepiece tokenizers out of xgboost routing (5ac9efc)
- llamafile: stream executable runtime coverage (#1622) (8d6c486)
- manifest: fail closed on scan timeout (#1615) (c769097)
- onnx: classify custom operator domains (#1614) (d5a6ac2)
- onnx: reduce weight anomaly noise (#1608) (d5ae100)
- paginate large Hugging Face inventories (e393dc0)
- pickle: bound legacy PyTorch control streams (#1619) (e407fb4)
- pickle: require source proof for framework metadata (bb38b74)
- picklescan: bound hidden ZIP probe bytes (#1624) (e8dc55e)
- picklescan: close encoded protocol0 probe gaps (#1594) (dfaedd1)
- picklescan: fail closed at nested depth limits (#1583) (5eb7390)
- picklescan: fail closed on unverifiable stream boundaries (#1521) (9cd9e67)
- picklescan: harden encoded byte probes (#1604) (f8192be)
- picklescan: ignore short base64 collisions (#1617) (1d1a93d)
- picklescan: mirror cached path importer semantics (#1683) (b948f8c)
- picklescan: preserve nested INST limit findings (#1585) (68d1d19)
- picklescan: reject padded short payload bypasses (#1626) (4edcac0)
- picklescan: resolve loaded extension exports directly (#1620) (ab6e58e)
- picklescan: safely filter inert URL metadata (#1658) (8a55653)
- picklescan: scan encoded byte literals (#1602) (21956ab)
- picklescan: validate canonical PyTorch ZIP tensor rebuilds (#1680) (2f188ad)
- preflight generic zip entry limits (#1549) (9da67c9)
- preserve active HF correlation findings (#1551) (603c782)
- preserve active HF findings (#1601) (29af2de)
- preserve default scanner read caps (#1542) (c55de21)
- preserve ONNX external data in HF streaming (#1635) (67fd0d4)
- preserve OpenVINO companions in HF streaming (#1642) (2a2aebc)
- preserve unusual docs filenames in formatter (#1533) (e1b066d)
- prevent CatBoost credential-redaction ReDoS (#1584) (493436e)
- preview Hugging Face dry-run scans (#1645) (fd40a81)
- pytorch: aggregate exact pickle opcodes (#1611) (3728964)
- pytorch: distinguish producer metadata from runtime CVEs (#1643) (beb34c6)
- pytorch: stream bounded analysis of large legacy shards (93c0e5b)
- pytorch: trust referenced storage members (#1654) (3a4f64b)
- recognize GGUF BF16 tensor type (#1632) (05443d2)
- reconcile cross-directory model shards (#1587) (b143688)
- redact authorization evidence variants (#1544) (f3ad852)
- redact CatBoost evidence secrets (#1428) (5e56d8a)
- redact exported source identifiers (#1530) (6f4407d)
- redact Keras and TensorFlow scanner evidence (#1560) (8e9d119)
- redact keras h5 lambda previews (#1435) (9830ef6)
- redact mlflow download errors (#1562) (5067f88)
- redact network finding snippets (#1438) (36f26f0)
- redact stream source urls (#1429) (77b2295)
- reduce JIT script detector false positives and negatives (#1513) (0984542)
- reject cleartext remote model sources (#1527) (6524032)
- reject jfrog folder local path collisions (#1552) (e22f4e1)
- reject symlinked CLI report outputs (#1485) (d4003a6)
- reject undersized nested pickle budgets (#1532) (0ce9bf3)
- report complete Hugging Face inventory capabilities (#1648) (d8888d1)
- require defusedxml for pmml parsing (#1570) (b8053d6)
- require explicit opt-in for PyTorch weight loading (#1582) (067dcba)
- restore cross-platform scanner baselines (#1597) (2484ac7)
- restore main CI coverage (#1606) (c81db69)
- restrict auth bearer token hosts (#1539) (838f250)
- restrict manual docker publish tags (#1526) (1abc856)
- restrict progress hook egress (#1571) (bc9419e)
- results: isolate nested member integrity hashes (#1666) (50e2df3)
- results: propagate inconclusive file coverage (#1672) (4ab592f)
- route protocol-less binary pickles (#1577) (ff68cb0)
- routing: bound tokenizer json scanner selection (#1638) (e47be19)
- routing: classify tokenizer text before binary formats (#1629) (067717d)
- routing: keep media out of serialized scanners (0a65650)
- routing: keep text assets out of Flax MessagePack (34cad20)
- routing: prefer validated safetensors framing (#1612) (2f782ba)
- rules: attribute format mismatches to s901 (#1613) (22bc654)
- safetensors: accept current tensor dtypes (#1610) (fd6f0ea)
- safetensors: accept empty tensor offsets (#1607) (9d547bb)
- safetensors: prefer bounded framing over zlib magic (#1623) (54b01e1)
- scan ExecuTorch raw payload indicators (#1545) (c37246d)
- scan model links in oci layers (#1567) (f85e0ef)
- scripts: contain corpus QA output paths (#1618) (a33b710)
- scripts: quote whitelist model ids safely (#1616) (8f57897)
- sniff Hugging Face selective downloads (#1412) (9576eb7)
- stream Flax msgpack analysis (#1589) (0c13d9e)
- stream Hugging Face SafeTensors shard headers (#1667) (e6186dc)
- stream large Flax MessagePack tensors (16e1bec)
- stream large Keras HDF5 inspection (0ff7b62)
- strictly pin picklescan maturin backend (#1531) (ac07522)
- text: contextualize tokenizer vocabulary indicators (#1653) (13431e4)
- text: deduplicate model-card indicators (#1631) (5ff4247)
- text: ignore pip version pins in documentation (#1630) (45e6d62)
- text: validate basic auth credential context (#1669) (a675581)
- tolerate picklescan reports without private metadata (cdc8b8b)
- validate hf direct url paths (#1550) (def9169)
- validate OCI layer member metadata (#1444) (a7235e1)
- validate pickle getattr reconstruction (c6c4713)
- verify rustup installer in docker builds (#1529) (51f2336)