Skip to content

docs(security): use standard NVIDIA policy - #534

Merged
ayushag-nv merged 1 commit into
mainfrom
codex/switch-1320-standard-security-policy
Aug 24, 2026
Merged

docs(security): use standard NVIDIA policy#534
ayushag-nv merged 1 commit into
mainfrom
codex/switch-1320-standard-security-policy

Conversation

@ayushag-nv

@ayushag-nv ayushag-nv commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Why

The existing security policy publishes Switchyard-specific disclosure timelines that NVIDIA Product Security did not approve. SWITCH-1320 asks us to use the standard NVIDIA policy.

What

Replace the repository-root SECURITY.md with the current policy from NVIDIA/TensorRT-LLM.

This does not change product behavior or address NVBugs 6648053 or 6648081.

How

Copied the approved policy verbatim, including its SPDX header, reporting channels, PGP guidance, and requested report fields.

Where to Start Review

SECURITY.md is the only changed file.

Test Plan

  • Confirmed SECURITY.md matches the TensorRT-LLM source byte-for-byte.
  • git diff --check
  • uv run ruff check .
  • uv run pytest tests/ -v — 115 passed

Summary by CodeRabbit

  • Documentation
    • Updated security reporting guidance with NVIDIA’s standard vulnerability submission process.
    • Added web and email reporting options, PGP encryption requirements, and requested report details.
    • Added links to NVIDIA security bulletins and removed previous policy-specific guidance.

Signed-off-by: ayushag <ayushag@nvidia.com>
@ayushag-nv
ayushag-nv requested a review from a team as a code owner August 24, 2026 18:55
@coderabbitai

coderabbitai Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 496dcaf0-779a-4807-ab00-543b6311a367

📥 Commits

Reviewing files that changed from the base of the PR and between 140ce2d and a73cb2d.

📒 Files selected for processing (1)
  • SECURITY.md

Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review.


Walkthrough

Changes

Security Policy

Layer / File(s) Summary
Vulnerability reporting guidance
SECURITY.md
Replaces the Switchyard-specific policy with NVIDIA reporting channels, PGP encryption guidance, required vulnerability details, and security bulletin links.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to a73cb

This change updates repository security-policy documentation only and does not alter product behavior; no actionable merge-blocking risk remains after normal checks and review.

Poem

A rabbit guards the reporting door
With PGP keys upon the floor
Web forms guide each careful note
Clear details help the message float
Security blooms in every byte

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the replacement of the repository security policy with NVIDIA's standard policy.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@ayushag-nv
ayushag-nv enabled auto-merge (squash) August 24, 2026 18:58
@ayushag-nv
ayushag-nv merged commit cef4231 into main Aug 24, 2026
12 checks passed
@ayushag-nv
ayushag-nv deleted the codex/switch-1320-standard-security-policy branch August 24, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants