Repository navigation
feat: scan the release image and model artifacts before release - #39
Merged
Merged
Conversation
Gate the image on a Trivy scan and a start-up check, and fix what the scan found by taking distribution security updates and dropping pip from the runtime image. Add an artifact scanner that refuses pickle weights, shipped code, malformed safetensors and digests the catalog does not record. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Closes the spec's §14 requirement to "scan container and model artifacts before release".
Container
/healthz. The job already gates merges, and only merges are released.libpcre2from the base image, andmsgpack,urllib3andsetuptoolsvendored insidepip. The Dockerfile now applies the distribution's security updates and removespipfrom the runtime image. The rebuilt image scans clean and still serves/healthz.Models and adapters
llm_router.artifact_scaninspects an artifact directory without loading anything from it and refuses:auto_map,trust_remote_code);python -m llm_router.artifact_scan <dir> --subject <id>exits 1 on any finding.Tests
tests/unit/test_artifact_scan.py(25 tests): sound artifacts pass; each rule is triggered by a crafted artifact, including a pickle that would callos.system(serialized only, never loaded) and eight malformed safetensors headers; digest gating; CLI.Local: ruff and mypy clean, full suite passes; Trivy 0.75 reports 0 findings on the rebuilt image.
Limits
governance sync.🤖 Generated with Claude Code