Skip to content

feat: scan the release image and model artifacts before release - #39

Merged
github-actions[bot] merged 1 commit into
mainfrom
feat/26-artifact-scanning
Oct 4, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
feat/26-artifact-scanning

Conversation

@Yash-Chindam

Copy link
Copy Markdown
Owner

What

Closes the spec's §14 requirement to "scan container and model artifacts before release".

Container

  • CI's image job now scans the built image with Trivy and fails on any critical or high vulnerability that has a fix, then starts the image and waits for /healthz. The job already gates merges, and only merges are released.
  • Turning the scan on found five fixable HIGH findings in the current image: libpcre2 from the base image, and msgpack, urllib3 and setuptools vendored inside pip. The Dockerfile now applies the distribution's security updates and removes pip from the runtime image. The rebuilt image scans clean and still serves /healthz.

Models and adapters

llm_router.artifact_scan inspects an artifact directory without loading anything from it and refuses:

  • pickle-capable weights, by extension or by content under any name (including torch zip archives), naming what the pickle would import;
  • shipped code, and configurations that ask the loader to import it (auto_map, trust_remote_code);
  • safetensors files whose header does not account for exactly the bytes in the file;
  • links out of the artifact, artifacts with no weights, adapters the engine could not serve;
  • a digest other than the one the catalog records.

python -m llm_router.artifact_scan <dir> --subject <id> exits 1 on any finding.

Tests

tests/unit/test_artifact_scan.py (25 tests): sound artifacts pass; each rule is triggered by a crafted artifact, including a pickle that would call os.system (serialized only, never loaded) and eight malformed safetensors headers; digest gating; CLI.

Local: ruff and mypy clean, full suite passes; Trivy 0.75 reports 0 findings on the rebuilt image.

Limits

  • The scanner checks formats and provenance. It does not detect a model trained to misbehave.
  • The catalog's checksums are placeholders, so no real artifact has been scanned against them.
  • Nothing calls the artifact scanner automatically yet: there is no artifact store in this repository for a pipeline to scan. It is the gate to run in the deploy step before governance sync.
  • A newly published CVE with a fix will fail CI on unrelated PRs until the image is rebuilt or the dependency bumped. That is intended.

🤖 Generated with Claude Code

Gate the image on a Trivy scan and a start-up check, and fix what the scan
found by taking distribution security updates and dropping pip from the
runtime image. Add an artifact scanner that refuses pickle weights, shipped
code, malformed safetensors and digests the catalog does not record.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added documentation Improvements or additions to documentation area/api area/tests area/ci-cd labels Oct 4, 2026
@github-actions
github-actions Bot merged commit f099351 into main Oct 4, 2026
6 checks passed
@github-actions
github-actions Bot deleted the feat/26-artifact-scanning branch October 4, 2026 06:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/api area/ci-cd area/tests documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant