Skip to content

v0.2.53

Choose a tag to compare

@github-actions github-actions released this 03 Oct 02:08
01273a4

0.2.53 (2026-10-03)

Security

  • Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes.
  • Upgrade locked AnyIO to 4.15.1 and GitPython to 3.1.62 to address dependency audit advisories.
  • Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants.
  • Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature.
  • Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615.
  • Preserve model-card network alerts when documented image examples contain code outside the reviewed generated forms.

Bug Fixes

  • avoid C&C signal for check_input_dim identifiers (#1847) (f906f9a)
  • cache: ignore macOS file access-time events (#1821) (b5341b5)
  • cache: isolate Windows probes and stabilize nightly checks (#1782) (47f94ee)
  • cache: keep Windows probes out of concurrently scanned trees (#1795) (c29586b)
  • cache: preserve locked probes under directory aliases (#1787) (caa2afe)
  • cache: preserve macOS entries during ancestor churn (#1800) (2c3512b)
  • cache: preserve Windows source fingerprint cache hits (#1793) (f27ebac)
  • cache: update scan-result entries atomically on hits (#1809) (a9720c0)
  • ci: accept rotated pinned checkout digests (#1799) (704e070)
  • ci: increase nightly correctness shard capacity (#1866) (7bb0378)
  • ci: route hash timing test to performance lane (#1824) (b4c10f2)
  • compact ONNX runtime lineage fanout (#1845) (4b7ebbc)
  • deps: bump anyio from 4.13.0 to 4.14.2 (#1855) (e635b8a)
  • deps: bump gitpython from 3.1.51 to 3.1.54 (#1786) (32de965)
  • deps: bump oauthlib from 3.3.1 to 4.0.0 (#1860) (72d3777)
  • deps: harden audit coverage and vulnerable packages (#1808) (995767e)
  • deps: prevent incompatible XGBoost Renovate upgrades (#1810) (ee2025e)
  • deps: update dependency xgboost to >=3.4,<3.5 (#1805) (e84cf95)
  • docker: upgrade vulnerable runtime Debian packages (#1849) (fafb9fb)
  • docker: upgrade vulnerable util-linux runtime packages (#1813) (521e941)
  • downgrade passive model metadata URLs (#1837) (de299cf)
  • ggml: detect embedded ZIP polyglot payloads (#1780) (9631527)
  • ignore ONNX tensor bytes for network text (#1840) (12c6287)
  • install tomli for Python 3.10 runtime (#1843) (242e08b)
  • joblib: fail closed on inconclusive warning scans (#1796) (a54bddc)
  • mlflow: restore SQL-backed registry support (#1818) (3e4e3c9)
  • network: block README remote-code trust bypasses (#1788) (65111fe)
  • network: preserve detections in README environment files (#1790) (5c1b267)
  • network: reject side-effectful model-card image examples (#1825) (56417b8)
  • picklescan: avoid scalar storage pickle false positives (#1842) (7408ed1)
  • picklescan: diagnose Windows call-graph source-stability failures (#1789) (89b5024)
  • picklescan: preserve nested storage probe coverage (#1846) (28ad1c9)
  • picklescan: safely parse bounded PyTorch tensor batches (#1783) (705059c)
  • preserve caller-owned Hugging Face cache sidecars (#1792) (eeb0be6)
  • preserve ONNX shape provenance during weight analysis (#1838) (54d14c3)
  • preserve PyTorch storage import trust (#1841) (a2f040e)
  • recognize bounded official image downloads in model cards (#1784) (64d4f52)
  • remove tensor_name_count retention budget dimension for remote SafeTensors (#1822) (4c24e17)
  • safely suppress verified Hugging Face model-card image examples (#1791) (6ee2b36)
  • scan encoded pickle metadata within byte budget (#1839) (169cd17)
  • tests: preserve fail-closed multi-array Joblib scans (#1819) (217f127)
  • treat CoreML license references as informational (#1852) (604bed5)
  • trust complete legacy PyTorch storage layout (#1850) (08d9fee)
  • validate manual release versions before outputs (#1794) (13431f6)
  • Avoid incomplete ONNX weight analysis when Gather nodes read dimensions from Shape outputs.
  • Avoid incomplete ONNX weight analysis when large runtime-activation fanout only adds dynamic bookkeeping lineage.
  • Treat documentation, license, and repository links in verified pickle and ONNX metadata as informational across supported Python versions while preserving active and unknown network destinations.
  • Preserve incomplete-scan diagnostics for malformed or unsupported ZIP data in GGUF/GGML files, including cached scans.
  • Report incomplete coverage when a GGUF/GGML source changes during scanning.
  • Preserve caller-owned Hugging Face cache sidecars during streaming cleanup.
  • Keep incomplete Joblib NumPy-wrapper scans failed closed when embedded pickle analysis also reports warnings.
  • Upgrade XGBoost to 3.4 on Python 3.12+ while retaining XGBoost 3.2 on Python 3.10 and 3.11.
  • Restore SQL-backed MLflow model registries and upgrade their vulnerable SQL parser.
  • Remove tensor_name_count as a retention budget dimension for remote SafeTensors streaming; the result_bytes cap already bounds aggregate serialized size, so large multi-shard models (e.g. 141 shards) no longer fail closed prematurely.
  • Avoid false-positive urllib network findings for model cards whose only urlopen use is the documented Image.open(urlopen(...)) sample-image example.
  • Upgrade vulnerable locked dependencies, use the hardened MLflow tracking client, and audit all installed CI extras.
  • Avoid network false positives for bounded README examples that download sample images over HTTPS from Hugging Face.
  • Preserve network security findings in README-named environment files.
  • Preserve README network detections when Transformers examples enable or dynamically configure remote code execution, including through generate(custom_generate=...).
  • Avoid ONNX network false positives from tensor payload bytes while preserving metadata URL/IP ownership and fail-closed coverage for truncated structured extraction or unknown protobuf fields.
  • Preserve Windows source-fingerprint cache hits while continuing to reject swapped or modified files.
  • Prevent Windows cache identity probes from creating locked temporary files inside scanned directories.
  • Preserve locked Windows cache probes reached through directory aliases while clearing stale scan results.
  • Place cross-volume Windows cache identity probes near the volume root instead of the nearest ancestor of the scanned path, so a probe can no longer appear inside a directory tree that a concurrent scan is walking.
  • Keep published scan-result cache entries readable when concurrent or interrupted hits update access metadata.
  • Preserve macOS scan-result cache entries during unrelated temporary-file churn while rejecting replaced source files and directories.
  • Keep macOS scan-result caching enabled when hashing updates a model file's access time.
  • Keep scanning referenced PyTorch storage members when hidden pickle, encoded literal, frame-first, or malformed-separator payloads cross trusted probe boundaries.
  • Preserve call-graph coverage for source-backed builtin aliases and non-canonical stdlib mailbox constructors.
  • Scan all bounded encoded pickle metadata that fits the decoded-byte budget, avoiding incomplete PyTorch ZIP coverage on harmless small encoded tokens.
  • Install tomli for Python 3.10 runtime environments so no-default-groups scanner installs can read ModelAudit TOML configuration.
  • Avoid command-and-control false positives for generated TorchScript _check_input_dim identifiers while preserving actionable check_in detections.
  • Avoid incomplete legacy PyTorch storage-layout findings after validating storage bytes when separate source-backed rebuild warnings remain.
  • Treat passive built-in CoreML license-reference URLs as informational while preserving active metadata URL and command detections.
  • Require modelaudit-picklescan>=0.1.11 so root upgrades receive the released scanner fixes.