You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
validate manual release versions before outputs (#1794) (13431f6)
Avoid incomplete ONNX weight analysis when Gather nodes read dimensions from Shape outputs.
Avoid incomplete ONNX weight analysis when large runtime-activation fanout only adds dynamic bookkeeping lineage.
Treat documentation, license, and repository links in verified pickle and ONNX metadata as informational across supported Python versions while preserving active and unknown network destinations.
Preserve incomplete-scan diagnostics for malformed or unsupported ZIP data in GGUF/GGML files, including cached scans.
Report incomplete coverage when a GGUF/GGML source changes during scanning.
Preserve caller-owned Hugging Face cache sidecars during streaming cleanup.
Keep incomplete Joblib NumPy-wrapper scans failed closed when embedded pickle analysis also reports warnings.
Upgrade XGBoost to 3.4 on Python 3.12+ while retaining XGBoost 3.2 on Python 3.10 and 3.11.
Restore SQL-backed MLflow model registries and upgrade their vulnerable SQL parser.
Remove tensor_name_count as a retention budget dimension for remote SafeTensors streaming; the result_bytes cap already bounds aggregate serialized size, so large multi-shard models (e.g. 141 shards) no longer fail closed prematurely.
Avoid false-positive urllib network findings for model cards whose only urlopen use is the documented Image.open(urlopen(...)) sample-image example.
Upgrade vulnerable locked dependencies, use the hardened MLflow tracking client, and audit all installed CI extras.
Avoid network false positives for bounded README examples that download sample images over HTTPS from Hugging Face.
Preserve network security findings in README-named environment files.
Preserve README network detections when Transformers examples enable or dynamically configure remote code execution, including through generate(custom_generate=...).
Avoid ONNX network false positives from tensor payload bytes while preserving metadata URL/IP ownership and fail-closed coverage for truncated structured extraction or unknown protobuf fields.
Preserve Windows source-fingerprint cache hits while continuing to reject swapped or modified files.
Prevent Windows cache identity probes from creating locked temporary files inside scanned directories.
Preserve locked Windows cache probes reached through directory aliases while clearing stale scan results.
Place cross-volume Windows cache identity probes near the volume root instead of the nearest ancestor of the scanned path, so a probe can no longer appear inside a directory tree that a concurrent scan is walking.
Keep published scan-result cache entries readable when concurrent or interrupted hits update access metadata.
Preserve macOS scan-result cache entries during unrelated temporary-file churn while rejecting replaced source files and directories.
Keep macOS scan-result caching enabled when hashing updates a model file's access time.
Keep scanning referenced PyTorch storage members when hidden pickle, encoded literal, frame-first, or malformed-separator payloads cross trusted probe boundaries.
Preserve call-graph coverage for source-backed builtin aliases and non-canonical stdlib mailbox constructors.
Scan all bounded encoded pickle metadata that fits the decoded-byte budget, avoiding incomplete PyTorch ZIP coverage on harmless small encoded tokens.
Install tomli for Python 3.10 runtime environments so no-default-groups scanner installs can read ModelAudit TOML configuration.
Avoid command-and-control false positives for generated TorchScript _check_input_dim identifiers while preserving actionable check_in detections.
Avoid incomplete legacy PyTorch storage-layout findings after validating storage bytes when separate source-backed rebuild warnings remain.
Treat passive built-in CoreML license-reference URLs as informational while preserving active metadata URL and command detections.
Require modelaudit-picklescan>=0.1.11 so root upgrades receive the released scanner fixes.