KEMBAR78
This PR addresses to known security issues by Ssofja · Pull Request #13804 · NVIDIA-NeMo/NeMo · GitHub
Skip to content

Conversation

@Ssofja
Copy link
Collaborator

@Ssofja Ssofja commented Jun 2, 2025

Important

The Update branch button must only be pressed in very rare occassions.
An outdated branch is never blocking the merge of a PR.
Please reach out to the automation team before pressing that button.

What does this PR do ?

This PR addresses known security issues. For the latest NVIDIA Vulnerability Disclosure Information visit https://www.nvidia.com/en-us/security/, for acknowledgement please reach out to the NVIDIA PSIRT team at PSIRT@nvidia.com
Collection: [Note which collection this PR will affect]

PR Type:

  • New Feature
  • Bugfix
  • Documentation

@github-actions github-actions bot added the ASR label Jun 2, 2025
Ssofja and others added 3 commits June 2, 2025 19:04
Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>
@Ssofja Ssofja force-pushed the joblib_security_fix branch from 4d7219c to 7e66238 Compare June 2, 2025 15:05
@Ssofja Ssofja requested a review from nithinraok June 2, 2025 15:05
@Ssofja Ssofja added the Run CICD label Jun 2, 2025
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
@github-actions github-actions bot removed the Run CICD label Jun 3, 2025
@github-actions
Copy link
Contributor

github-actions bot commented Jun 3, 2025

[🤖]: Hi @Ssofja 👋,

We wanted to let you know that a CICD pipeline for this PR just finished successfully.

So it might be time to merge this PR or get some approvals.

//cc @chtruong814 @ko3n1g @pablo-garay @thomasdhc

@nithinraok
Copy link
Collaborator

@chtruong814 can we merge this? It was reverted before

@chtruong814
Copy link
Collaborator

Thanks for fixing this.

@chtruong814 chtruong814 merged commit c0fd982 into main Jun 4, 2025
132 checks passed
@chtruong814 chtruong814 deleted the joblib_security_fix branch June 4, 2025 19:58
@Ssofja Ssofja changed the title decompressing joblib file before checking it This PR addresses to known security issues Jun 10, 2025
@chtruong814 chtruong814 added the r2.3.0 Pick this label for auto-cherrypicking into v2.3.0 label Jun 22, 2025
ko3n1g pushed a commit that referenced this pull request Jun 22, 2025
* decompressing joblib file before checking it

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Updated tests to create valid dummy files

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: artbataev <artbataev@users.noreply.github.com>

---------

Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
Co-authored-by: Ssofja <Ssofja@users.noreply.github.com>
Co-authored-by: artbataev <artbataev@users.noreply.github.com>
chtruong814 pushed a commit that referenced this pull request Jun 28, 2025
* decompressing joblib file before checking it

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Updated tests to create valid dummy files

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: artbataev <artbataev@users.noreply.github.com>

---------

Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
Co-authored-by: Ssofja <Ssofja@users.noreply.github.com>
Co-authored-by: artbataev <artbataev@users.noreply.github.com>
Signed-off-by: Charlie Truong <chtruong@nvidia.com>
chtruong814 pushed a commit that referenced this pull request Jun 29, 2025
* decompressing joblib file before checking it



* Apply isort and black reformatting




* Updated tests to create valid dummy files



* Apply isort and black reformatting



---------

Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
Co-authored-by: Ssofja <78349198+Ssofja@users.noreply.github.com>
Co-authored-by: Ssofja <Ssofja@users.noreply.github.com>
Co-authored-by: artbataev <artbataev@users.noreply.github.com>
AmirHussein96 pushed a commit to AmirHussein96/NeMo that referenced this pull request Aug 5, 2025
* decompressing joblib file before checking it

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Updated tests to create valid dummy files

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: artbataev <artbataev@users.noreply.github.com>

---------

Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
Co-authored-by: Ssofja <Ssofja@users.noreply.github.com>
Co-authored-by: artbataev <artbataev@users.noreply.github.com>
Signed-off-by: Amir Hussein <amhussein@nvidia.com>
AmirHussein96 pushed a commit to AmirHussein96/NeMo that referenced this pull request Aug 5, 2025
* decompressing joblib file before checking it

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Updated tests to create valid dummy files

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: artbataev <artbataev@users.noreply.github.com>

---------

Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
Co-authored-by: Ssofja <Ssofja@users.noreply.github.com>
Co-authored-by: artbataev <artbataev@users.noreply.github.com>
Signed-off-by: Amir Hussein <amhussein@nvidia.com>
nasretdinovr pushed a commit to nasretdinovr/NeMo that referenced this pull request Aug 8, 2025
* decompressing joblib file before checking it

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Updated tests to create valid dummy files

Signed-off-by: Ssofja <sofiakostandian@gmail.com>

* Apply isort and black reformatting

Signed-off-by: artbataev <artbataev@users.noreply.github.com>

---------

Signed-off-by: Ssofja <sofiakostandian@gmail.com>
Signed-off-by: Ssofja <Ssofja@users.noreply.github.com>
Signed-off-by: artbataev <artbataev@users.noreply.github.com>
Co-authored-by: Ssofja <Ssofja@users.noreply.github.com>
Co-authored-by: artbataev <artbataev@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ASR r2.3.0 Pick this label for auto-cherrypicking into v2.3.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants