From 0b5b0de66f8db17f861a352b9b42b232dd1cd4c7 Mon Sep 17 00:00:00 2001 From: mskumar Date: Fri, 25 Sep 2026 08:08:47 +0530 Subject: [PATCH 1/3] fix: pin GitHub Actions to commit SHAs --- .github/workflows/ci.yml | 4 ++-- .github/workflows/release.yml | 4 ++-- .github/workflows/test.yml | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b285201..ead823e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,8 +13,8 @@ jobs: lint-and-test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: python-version: "3.11" - name: Install dev dependencies diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4e20ba3..58016bb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -13,8 +13,8 @@ jobs: build: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: python-version: "3.11" - name: Install build tools diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index fc111f1..b14e933 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -16,8 +16,8 @@ jobs: matrix: python-version: ["3.10", "3.11", "3.12"] steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: python-version: ${{ matrix.python-version }} - name: Install package From 3a5c3b981c8b4d588a3cb70e52bb8c50e8344eb8 Mon Sep 17 00:00:00 2001 From: mskumar Date: Fri, 25 Sep 2026 08:09:25 +0530 Subject: [PATCH 2/3] chore: add Dependabot config (weekly grouped uv updates) --- .github/dependabot.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..8d12525 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,10 @@ +version: 2 +updates: + - package-ecosystem: "uv" + directory: "/" + schedule: + interval: "weekly" + groups: + uv: + patterns: + - "*" From 84525b7225e503630b674a10651fb93fa77a4e7e Mon Sep 17 00:00:00 2001 From: mskumar Date: Fri, 25 Sep 2026 08:09:35 +0530 Subject: [PATCH 3/3] docs: add SECURITY.md vulnerability reporting policy --- SECURITY.md | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..5deae3d --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,31 @@ +# Security Policy + +## Supported Versions + +| Version | Supported | +| ------- | ------------------ | +| 0.1.x | :white_check_mark: | +| < 0.1 | :x: | + +## Reporting a Vulnerability + +Report vulnerabilities privately via +[private vulnerability reporting](https://github.com/ms-kumar/torml/security/advisories/new). +Do not open public issues for unpatched vulnerabilities. + +Please include: + +- Affected version(s) (`torml.__version__`, `uv.lock` entries if dependency-related) +- Steps to reproduce or proof of concept +- Impact assessment, if known + +Expect an initial response within 7 days. Fixes land as a patch release with +a `RELEASES.md` entry crediting the reporter (unless anonymity is requested). + +## Scope Notes + +- `torml` has one runtime dependency (`torch`); most advisories will concern + the lockfile (`uv.lock`) or CI tooling, and are fixed by version bumps. +- GitHub secret scanning and push protection are enabled; CI runs + CodeQL, Dependabot alerts, `pip-audit`-clean installs, and a pinned + (`pre-commit` + `uv.lock`) toolchain.