Skip to content

fix(text): deduplicate model-card indicators - #1631

Merged
mldangelo-oai merged 27 commits into
mainfrom
mdangelo/codex/hf-fp-t04-model-card-finding-dedup-20260610
Jun 12, 2026
Merged

mldangelo-oai merged 27 commits into
mainfrom
mdangelo/codex/hf-fp-t04-model-card-finding-dedup-20260610

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • correlate same-span model-card URL, domain, cloud-storage, and git-clone evidence into one normalized fingerprinted finding
  • keep distinct executable indicators, nested/encoded URLs, suspicious ports, credentials, locations, code examples, and malicious controls separate
  • keep passive Markdown/table documentation links informational and feed evidence fingerprints into SARIF deduplication

Validation

  • uv run ruff format modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • uv run ruff check --fix modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • uv run ruff check modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • uv run ruff format --check modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • uv run mypy modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/
  • git diff --check
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/integrations/test_sarif_formatter.py -q (510 passed)
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/detectors/test_network_comm_detector.py tests/integrations/test_sarif_formatter.py tests/test_network_comm_integration.py -q (1043 passed, 9 skipped)
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1 (17379 passed, 1292 skipped, 39 warnings)
  • pinned Hugging Face cards: sentence-transformers/all-MiniLM-L6-v2@1110a243fdf4706b3f48f1d95db1a4f5529b4d41, openai/clip-vit-base-patch32@3d74acf9a28c67741b2f4f2ea7635f0aaf6f0268, microsoft/resnet-50@34c2154c194f829b11125337b98c8f5f9965ff19; doc-only cards exit 0, CLIP code example remains actionable, and paired malicious controls retain one grouped git-clone finding plus separate requests.get control

@github-actions

github-actions Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 1.459s -> 1.459s (+0.1%).

Workload Benchmark Target Size Files Baseline Current Change Status
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 104.80ms 111.36ms +6.3% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 115.49ms 111.78ms -3.2% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 118.95ms 115.29ms -3.1% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 463.2us 473.6us +2.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 520.0us 511.5us -1.6% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 587.1us 578.3us -1.5% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 518.7us 512.3us -1.2% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 144.44ms 145.47ms +0.7% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 548.0us 550.3us +0.4% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 74.19ms 73.92ms -0.4% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 488.33ms 489.24ms +0.2% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 409.71ms 409.59ms -0.0% stable

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4c6f571434

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai requested a review from mldangelo June 11, 2026 01:24
@mldangelo-oai
mldangelo-oai enabled auto-merge (squash) June 11, 2026 01:24
@mldangelo-oai
mldangelo-oai disabled auto-merge June 11, 2026 06:23
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 444d0c3e73

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/integrations/sarif_formatter.py
Comment thread modelaudit/scanners/text_scanner.py
Comment thread modelaudit/scanners/text_scanner.py
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Updated head: e208fb4.

Addressed the three prior P2 findings:

  • SARIF primary fingerprints now combine evidence fingerprint, redacted artifact path, and severity, while preserving the scanner evidence fingerprint in properties.
  • Model-card evidence line/column lookup is precomputed for finding positions so dedup no longer counts newlines from the start for every finding.
  • Passive Markdown-link suppression now excludes code contexts such as endpoint assignments; added regression for endpoint = "[download](https://evil.example/payload.sh)".

Validation on this head:

  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/integrations/test_sarif_formatter.py -q -> 512 passed
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/detectors/test_network_comm_detector.py tests/integrations/test_sarif_formatter.py tests/test_network_comm_integration.py -q -> 1045 passed, 9 skipped
  • uv run ruff check --fix ..., uv run ruff check ..., uv run ruff format --check ..., uv run mypy ..., git diff --check all clean
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1 -> 17380 passed, 1292 skipped
  • Pinned HF README cards at exact revisions: MiniLM and ResNet doc-only cards exit 0, CLIP code example remains actionable, injected git-clone/requests controls retained separately through JSON and SARIF.

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

Pinned real-model-card QA from Hugging Face rank 255 exposes an additional benign coverage failure on current main.

  • Model/revision: openai/whisper-large-v2@ae4642769ce2ad8fc292556ccea8e901f1530655
  • ModelAudit: 8d6c4864fe2ea833ceaef1b9803d225afb1e8d69
  • Result: 40 informational S309 README URL/domain findings, then Text Content Security Coverage fails because endpoint redaction classification exceeds max_classifications=32.
  • Outcome: analysis_incomplete=true, text_content_security_finding_limit; the overall model scan exits 2.

The model card is benign documentation. Please use this immutable revision as real-world QA for dedup/calibration and prove the exact PR head does not exhaust the classification budget merely because the README contains many ordinary documentation links. The fix must preserve actionable code-context/network findings and bounded work rather than simply raising the cap.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e208fb43b5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Updated head: bfad694.

Addressed the new Whisper real-card QA comment:

  • Documentation-only endpoint-redaction classification exhaustion is now reported as an informational reporting limit when the inspected README contains only passive documentation network-token lines.
  • Actionable code/network token lines still keep the detector limit fail-closed.
  • BibTeX bibliography fields such as url = {https://arxiv.org/...} and citation copyright domains are treated as passive documentation, while normal code assignments remain actionable.

Validation on this head:

  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py -q -> 446 passed
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/integrations/test_sarif_formatter.py -q -> 515 passed
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/detectors/test_network_comm_detector.py tests/integrations/test_sarif_formatter.py tests/test_network_comm_integration.py -q -> 1048 passed, 9 skipped
  • uv run ruff check ..., uv run ruff format --check ..., uv run mypy ..., git diff --check all clean
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1 -> 17383 passed, 1292 skipped
  • Pinned HF README cards at exact revisions: MiniLM and ResNet doc-only cards exit 0; CLIP real code example remains actionable; Whisper doc-only README now exits 0; injected git-clone/requests controls are retained through JSON/SARIF on all four cards, with Whisper+controls failing closed due actionable code after the redaction budget.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Updated head: eb2acc8734fb17b5797c08e6a80ce9cd43f7850d.

Addressed the new P2 return-context finding:

  • Markdown links inside returned/yielded strings are now treated as code context instead of passive documentation.
  • Added regression for return "[download](https://evil.example/payload.sh)"; it stays actionable and exits 1.

Validation on this head:

  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py -q -> 447 passed
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/detectors/test_network_comm_detector.py tests/integrations/test_sarif_formatter.py tests/test_network_comm_integration.py -q -> 1049 passed, 9 skipped
  • uv run ruff check ..., uv run ruff format --check ..., uv run mypy ..., git diff --check all clean
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1 -> 17384 passed, 1292 skipped
  • Pinned HF README matrix still passes: MiniLM/ResNet/Whisper doc-only exit 0; CLIP code example remains actionable; injected git-clone/requests controls retained through JSON/SARIF on all four cards.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eb2acc8753

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated
Comment thread modelaudit/scanners/text_scanner.py Outdated
Comment thread modelaudit/scanners/text_scanner.py Outdated
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Updated head: 541911d.

Addressed the three fresh review findings:

  • Parenthesized returned/yielded Markdown-link strings now stay in code context, e.g. return ("[download](https://evil.example/payload.sh)") remains actionable.
  • BibTeX passive-field handling now only suppresses recognized passive bibliography fields, so an unclosed @misc{... no longer downgrades endpoint = "https://evil.example/payload.sh".
  • Model-card evidence columns now count decoded text characters rather than UTF-8 bytes before the evidence span.

Validation on this head:

  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py -q -k 'unicode_characters or parenthesized_markdown_link_return or unclosed_bibliography' -> 3 passed, 447 deselected
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/detectors/test_network_comm_detector.py tests/integrations/test_sarif_formatter.py tests/test_network_comm_integration.py -q -> 1052 passed, 9 skipped
  • uv run ruff format modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> 2 files reformatted before commit
  • uv run ruff check --fix modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> all checks passed
  • uv run ruff check modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> all checks passed
  • uv run ruff format --check modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> 419 files already formatted
  • uv run mypy modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> success, no issues in 474 source files
  • git diff --check -> clean
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1 -> 17387 passed, 1292 skipped
  • Pinned real-card matrix (--scanners text --no-cache, JSON and SARIF for benign/control variants): MiniLM benign 0/control 2, CLIP benign 1/control 1, ResNet benign 0/control 1, Whisper benign 0/control 2; all controlled variants retained evil.example evidence in JSON and SARIF.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 541911d973

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated
Comment thread modelaudit/scanners/text_scanner.py
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Updated head: 8dea686.

Addressed the two fresh P1 findings:

  • Quoted url = "https://..." assignments are no longer treated as passive BibTeX fields under an unclosed @misc{...; brace-style bibliography URL fields remain informational.
  • URLs in indented multiline return/yield values, including returned Markdown links split after return (, are now treated as code context before passive Markdown-link downgrading and before documentation-only reporting-limit handling.

Validation on this head:

  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py -q -k 'multiline_markdown_link_return or quoted_url_code or unclosed_bibliography or bibliography_url_field' -> 4 passed, 448 deselected
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest tests/scanners/test_text_scanner.py tests/detectors/test_network_comm_detector.py tests/integrations/test_sarif_formatter.py tests/test_network_comm_integration.py -q -> 1054 passed, 9 skipped
  • uv run ruff format modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> 419 files left unchanged
  • uv run ruff check --fix modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> all checks passed
  • uv run ruff check modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> all checks passed
  • uv run ruff format --check modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> 419 files already formatted
  • uv run mypy modelaudit/ packages/modelaudit-picklescan/src packages/modelaudit-picklescan/tests tests/ -> success, no issues in 474 source files
  • git diff --check -> clean
  • PROMPTFOO_DISABLE_TELEMETRY=1 uv run pytest -n auto -m "not slow and not integration" --maxfail=1 -> 17389 passed, 1292 skipped
  • Pinned real-card matrix (--scanners text --no-cache, JSON and SARIF for benign/control variants, with quoted url = ... and multiline return controls): MiniLM benign 0/control 2, CLIP benign 1/control 1, ResNet benign 0/control 1, Whisper benign 0/control 2; all controlled variants retained evil.example evidence in JSON and SARIF.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8dea686941

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated
Comment thread modelaudit/scanners/text_scanner.py
Comment thread modelaudit/scanners/text_scanner.py Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Fixed
Comment thread modelaudit/scanners/text_scanner.py Fixed
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Head: cd43020

Addressed the two code-quality redundant-comparison threads:

  • Direct parent-line branch now returns True after the existing line_indent < value_indent guard.
  • List-object parent lookup now returns only the meaningful parent-line pattern check.

Validation on this head:

  • focused endpoint-redaction/nested-config subset: 6 passed
  • affected text/network/SARIF suite: 1061 passed, 9 skipped
  • ruff check and ruff format --check
  • mypy over modelaudit, picklescan src/tests, tests
  • git diff --check
  • full fast lane: 17396 passed, 1292 skipped
  • pinned real-model-card JSON/SARIF matrix with plain nested config, YAML list-item config, YAML list-object config, encoded nested URL, returned/wrapped markdown links, redacted credential, and controlled malicious URLs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cd430203b4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated
Comment thread modelaudit/scanners/text_scanner.py Outdated
Comment thread modelaudit/scanners/text_scanner.py Outdated
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Head: e3b265e

Validation run on this head:

  • Focused text-scanner regressions: 13 passed
  • Affected scanner/network/SARIF suite: 1065 passed, 9 skipped
  • Ruff format, Ruff check, mypy, and git diff --check: clean
  • Full fast lane: 17400 passed, 1292 skipped
  • Pinned real-model-card JSON/SARIF matrix: passed (MiniLM 0/1, CLIP 1/1, ResNet 0/1, Whisper 0/2 expected exits)

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Fixed
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Head: 254b6a5e8619f0f057f5e9e7aca1cf8a80ff7c9e

Addressed the code-quality cleanup on the previous head by removing the now-dead absolute_position assignment in the domain-token branch.

Validation run on this head:

  • Focused text-scanner regressions: 13 passed
  • Affected scanner/network/SARIF suite: 1065 passed, 9 skipped
  • Ruff format, Ruff check, mypy, and git diff --check: clean
  • Pinned real-model-card JSON/SARIF matrix: passed (MiniLM 0/1, CLIP 1/1, ResNet 0/1, Whisper 0/2 expected exits)
  • Full fast lane: 17400 passed, 1292 skipped

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai enabled auto-merge (squash) June 11, 2026 12:56

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6ed93d9505

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7c28e9a2b3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 771d073b17

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread modelaudit/scanners/text_scanner.py Outdated
@mldangelo-oai
mldangelo-oai merged commit 5ff4247 into main Jun 12, 2026
29 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/hf-fp-t04-model-card-finding-dedup-20260610 branch June 12, 2026 03:35
@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant