Files
ModelForge/docs/security/MODEL_SUPPLY_CHAIN_POLICY.md

1.5 KiB

Model Supply-Chain Policy

Policy defaults

  • Downloaded model repositories are untrusted.
  • Exact revisions must be resolved and pinned.
  • Safe tensor formats are preferred where supported.
  • Pickle-derived artifacts require stricter handling and may be prohibited by policy.
  • trust_remote_code=false by default.
  • Upstream security scanner results are evidence, not absolute proof of safety.
  • License metadata must be captured and evaluated before production approval.
  • Inference workers receive approved artifacts read-only.
  • Internet egress is disabled for inference workers by default.
  • Tokens used for model acquisition remain downloader/control-plane secrets only.

Candidate admission sequence

  1. register upstream source;
  2. snapshot upstream metadata;
  3. resolve exact revision;
  4. download to quarantine/cache;
  5. inventory all files;
  6. calculate/record digests;
  7. collect upstream scanner/security metadata;
  8. evaluate serialization/custom-code requirements;
  9. evaluate license/gating restrictions;
  10. run local static/security checks;
  11. mark verified or blocked;
  12. only verified artifacts can enter runtime compatibility testing.

Remote code exception

If an artifact requires custom repository code:

  • default state: production blocked;
  • optional lab execution requires explicit operator approval;
  • sandbox restrictions must be stricter than normal approved models;
  • exception reason and review evidence are audited;
  • promotion to stable requires a separate production security decision.