Skip to content

fix: preserve active HF findings - #1601

Merged
mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/fix-hf-whitelist-active-followup
Jun 9, 2026
Merged

mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/fix-hf-whitelist-active-followup

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Contributor

Summary

  • follow up on fix: preserve active HF correlation findings #1551's whitelist review by preserving additional concrete CRITICAL execution and runtime-extension findings
  • keep explicit blacklist hits, direct command payloads, embedded PE files, custom runtime hooks, Python operators, and handler execution from being downgraded solely by trusted Hugging Face provenance
  • scope exemptions to exact check names at CRITICAL severity so warning, documentation, operational, and near-match findings remain whitelist-eligible
  • retain fix: preserve active HF correlation findings #1551's producer-supplied same_fragment_correlation requirement unchanged

False-positive / false-negative audit

  • malicious positives remain CRITICAL for LightGBM, Torch7, R serialization, TensorRT PE, CoreML custom code, OpenVINO runtime extensions, ONNX Python operators, TorchServe handlers, TensorFlow protobuf command injection, and explicit blacklist findings
  • warning variants of shared check names still downgrade to INFO
  • benign OpenVINO, TorchServe, TensorFlow protobuf, blacklist-boundary, and correlation near matches remain clean

Validation

  • current main: 603c782fb8d4b0120be430589a4a1ca046b76709
  • head: 7daac2107a37bc8ea030005bf1e86e715ce05400
  • exact verified tree: a6bc9004a0a56b170422221b7ae94a2af5afcbcd
  • associated scanner/base/cache tests: 781 passed
  • scoped Ruff check/format, mypy, and git diff --check: clean
  • local ONNX producer tests were unavailable because the optional onnx package is not installed; the exact-name whitelist behavior is covered in the base-scanner regression and CI owns the optional-dependency lane
  • full suite intentionally left to CI per review workflow

@mldangelo-oai
mldangelo-oai merged commit 29af2de into main Jun 9, 2026
24 of 25 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/fix-hf-whitelist-active-followup branch June 9, 2026 13:10
@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 1.372s -> 1.368s (-0.3%).

Workload Benchmark Target Size Files Baseline Current Change Status
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 527.9us 513.8us -2.7% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 84.95ms 86.56ms +1.9% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 425.1us 417.2us -1.9% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 473.2us 479.9us +1.4% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 121.72ms 120.72ms -0.8% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 459.9us 456.9us -0.7% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 71.41ms 70.97ms -0.6% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 477.07ms 474.91ms -0.5% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 390.89ms 389.53ms -0.3% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 110.28ms 109.95ms -0.3% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 113.53ms 113.19ms -0.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 451.5us 452.1us +0.1% stable

@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant