Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
4f5a4dd
fix(security): floor litellm/wandb/lxml past known CVEs; relax stale …
nicgupta-nvidia Jul 9, 2026
e3a32c0
📝 CodeRabbit Chat: Add unit tests for PR changes
coderabbitai[bot] Jul 9, 2026
eefcb35
test: consolidate generated dependency-pin tests into one suite
nicgupta-nvidia Jul 9, 2026
9390f35
test(security): functional tests that NeMo-Skills works with the bump…
nicgupta-nvidia Jul 13, 2026
2143dfc
fix(security): remediate nemo-skills high findings
nicgupta-nvidia Jul 30, 2026
5672da1
chore: satisfy requirements sorting hook
nicgupta-nvidia Jul 30, 2026
90da975
fix(container): validate patched wandb core help output
nicgupta-nvidia Jul 30, 2026
888bd64
fix(container): remove uv Git cache from runtime image
nicgupta-nvidia Jul 30, 2026
579c6d6
fix(security): floor msgpack and setuptools
nicgupta-nvidia Jul 31, 2026
b90f977
fix(container): remediate aiohttp Trivy high
nicgupta-nvidia Aug 6, 2026
91ef6b6
fix(container): update wandb core for go-git CVE
nicgupta-nvidia Aug 10, 2026
1417837
fix(container): narrowly backport go-git update
nicgupta-nvidia Aug 10, 2026
d8118a1
fix: update Go and GitPython security floors
nicgupta-nvidia Aug 19, 2026
03a4dba
fix(security): refresh container dependency floors
nicgupta-nvidia Sep 3, 2026
775d208
fix(container): pin resolved W&B text module
nicgupta-nvidia Sep 3, 2026
fb683b6
fix(container): remove non-runtime scan inputs
nicgupta-nvidia Sep 3, 2026
ee1eb08
fix(container): avoid caching uv build metadata
nicgupta-nvidia Sep 3, 2026
d3eef3e
fix(container): isolate uv build metadata
nicgupta-nvidia Sep 3, 2026
9ef38fc
fix(container): accept uv build metadata
nicgupta-nvidia Sep 3, 2026
8c43f55
fix(container): exclude uv from runtime layers
nicgupta-nvidia Sep 3, 2026
baee6bd
fix(container): drop pip build BOM
nicgupta-nvidia Sep 3, 2026
c315300
fix(container): cross-compile W&B core for target arch
nicgupta-nvidia Sep 4, 2026
da8459a
test: replace retired NVIDIA API model
nicgupta-nvidia Sep 11, 2026
ef58ed3
test: use accessible NVIDIA API model
nicgupta-nvidia Sep 11, 2026
59dadf5
test: use durable NVIDIA API endpoint
nicgupta-nvidia Sep 11, 2026
87367bb
test: use entitled NVIDIA API endpoint
nicgupta-nvidia Sep 11, 2026
b7e957b
fix(security): raise transitive web dependency floors
nicgupta-nvidia Oct 2, 2026
5eb62de
fix(security): pin gradio and repair policy tests
nicgupta-nvidia Oct 6, 2026
1b61b89
fix(security): backport NLTK path containment
nicgupta-nvidia Oct 6, 2026
73dda20
fix(ci): keep requirements sorted
nicgupta-nvidia Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@

*.json
!greptile.json
!security/nltk-cve-2026-81726.openvex.json
!tests/data/dummy_external_benchmark/benchmark_map.json
!nemo_skills/mcp/servers/exclude_domains_hle_opus.json
*.tar.gz
Expand Down
2 changes: 1 addition & 1 deletion core/pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@

[build-system]
requires = [
"setuptools",
"setuptools>=78.1.1",
"wheel"
]
build-backend = "setuptools.build_meta"
Expand Down
15 changes: 11 additions & 4 deletions core/requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,18 @@
bs4
compute-eval @ git+https://github.com/NVIDIA/compute-eval.git@e01a5d2
contractions
# Fixes eight High findings through CVE-2026-55415.
datamodel-code-generator>=0.64.0
datasets
editdistance
evalplus @ git+https://github.com/evalplus/evalplus@c91370f
faiss-cpu
fire
flask
func-timeout
gradio
# Fixes all High GitPython advisories reported through GHSA-wvpp-8hx9-p66j.
GitPython>=3.1.58
gradio>=6.16.0 # CVE-2026-49119
httpx
huggingface_hub
hydra-core
Expand All @@ -30,6 +34,9 @@ math-verify[antlr4_9_3]
# mcp 2.0 removed the streamablehttp_client alias that nemo_skills/mcp/clients.py imports.
# Unpin once those call sites move to streamable_http_client and the 2.0 API is verified.
mcp<2.0
# CVE-2026-81726 is fixed upstream but has no release yet. Pin the first
# immutable upstream merge containing all model-artifact pathsec fixes.
nltk @ git+https://github.com/nltk/nltk.git@574270e2ad368c8816976e584da56ddfb3fefbad # CVE-2026-81726
numpy
openai
openpyxl>=3.1.0
Expand All @@ -47,6 +54,6 @@ sympy
torchcodec
tqdm
transformers
# Floors click to >=8.2 (wandb 0.26.x only requires click>=8.0.1, so the resolver
# was settling on click 8.1.8). Taken from #1507.
wandb>=0.27.1
# 0.28.1 is paired with the patched wandb-core built in Dockerfile.nemo-skills.
# Pinning keeps the Python/core protocol pair deterministic.
wandb==0.28.1
130 changes: 122 additions & 8 deletions dockerfiles/Dockerfile.nemo-skills
Original file line number Diff line number Diff line change
@@ -1,5 +1,62 @@
# W&B 0.28.1 still bundles Go 1.26.4, grpc-go 1.82.0, x/text 0.38.0, and
# go-git 5.19.1. Keep the qualified W&B dependency-update commit and raise only
# the modules with fixable Critical/High findings. Go 1.26.6 also clears the
# reported Go standard-library findings. Build only wandb-core so the final
# image does not retain the Go toolchain or source.
ARG WANDB_CORE_COMMIT=e1184091520c9b44aa1096fdb27b2f4bf52f26d7
ARG WANDB_GO_GIT_VERSION=5.19.2
ARG WANDB_GO_CRYPTO_VERSION=0.55.0
ARG WANDB_GO_IMAGE_VERSION=0.45.0
ARG WANDB_GO_TEXT_VERSION=0.41.0
ARG WANDB_GRPC_VERSION=1.83.1
FROM --platform=$BUILDPLATFORM golang:1.26.6 AS wandb-core-builder
ARG WANDB_CORE_COMMIT
ARG WANDB_GO_GIT_VERSION
ARG WANDB_GO_CRYPTO_VERSION
ARG WANDB_GO_IMAGE_VERSION
ARG WANDB_GO_TEXT_VERSION
ARG WANDB_GRPC_VERSION
ARG TARGETARCH
RUN git init /src/wandb && \
cd /src/wandb && \
git remote add origin https://github.com/wandb/wandb.git && \
git sparse-checkout init --cone && \
git sparse-checkout set core && \
git fetch --depth 1 origin "${WANDB_CORE_COMMIT}" && \
git checkout --detach FETCH_HEAD
RUN cd /src/wandb/core && \
go get \
"github.com/go-git/go-git/v5@v${WANDB_GO_GIT_VERSION}" \
"golang.org/x/crypto@v${WANDB_GO_CRYPTO_VERSION}" \
"golang.org/x/image@v${WANDB_GO_IMAGE_VERSION}" \
"golang.org/x/text@v${WANDB_GO_TEXT_VERSION}" \
"google.golang.org/grpc@v${WANDB_GRPC_VERSION}" && \
go mod vendor && \
grep -E "^[[:space:]]*github\.com/go-git/go-git/v5[[:space:]]+v${WANDB_GO_GIT_VERSION}([[:space:]]|$)" go.mod && \
grep -E "^# github\.com/go-git/go-git/v5[[:space:]]+v${WANDB_GO_GIT_VERSION}([[:space:]]|$)" vendor/modules.txt && \
CGO_ENABLED=0 GOOS=linux GOARCH=${TARGETARCH} go build \
-tags "disable_grpc_modules parquet_read_only" \
-ldflags "-s -w -X main.commit=${WANDB_CORE_COMMIT}" \
-mod=vendor \
-o /wandb-core \
./cmd/wandb-core && \
go version -m /wandb-core | grep -F "go1.26.6" && \
go version -m /wandb-core | grep -E "build[[:space:]]+GOOS=linux([[:space:]]|$)" && \
go version -m /wandb-core | grep -E "build[[:space:]]+GOARCH=${TARGETARCH}([[:space:]]|$)" && \
go version -m /wandb-core | grep -E "github\.com/go-git/go-git/v5[[:space:]]+v${WANDB_GO_GIT_VERSION}([[:space:]]|$)" && \
go version -m /wandb-core | grep -E "golang\.org/x/crypto[[:space:]]+v${WANDB_GO_CRYPTO_VERSION}([[:space:]]|$)" && \
go version -m /wandb-core | grep -E "golang\.org/x/image[[:space:]]+v${WANDB_GO_IMAGE_VERSION}([[:space:]]|$)" && \
go version -m /wandb-core | grep -E "google\.golang\.org/grpc[[:space:]]+v${WANDB_GRPC_VERSION}([[:space:]]|$)" && \
go version -m /wandb-core | grep -E "golang\.org/x/text[[:space:]]+v${WANDB_GO_TEXT_VERSION}([[:space:]]|$)"

# Keep uv's Python wheel and its build-environment SBOM out of the runtime
# image. Only the standalone, version-pinned executable crosses this stage.
FROM ghcr.io/astral-sh/uv:0.12.9 AS uv-installer

# using ubuntu instead of debian for easier apptainer installation on arm64
FROM ubuntu:22.04
FROM ubuntu:22.04 AS runtime-base
ARG WANDB_CORE_COMMIT
ARG NLTK_SECURITY_COMMIT=574270e2ad368c8816976e584da56ddfb3fefbad

# Install Python and other dependencies
RUN apt-get update && \
Expand All @@ -14,7 +71,8 @@ RUN apt-get update && \
ln -s /usr/bin/python3 /usr/bin/python && \
rm -rf /var/cache/apt/archives /var/lib/apt/lists/*

RUN pip install --upgrade pip setuptools "uv>=0.11.10"
RUN pip install --no-cache-dir --upgrade pip "setuptools>=78.1.1" && \
rm -f /usr/local/lib/python3*/dist-packages/pip/_vendor/bom.cdx.json

# Update package lists and install apptainer for arm64
# https://apptainer.org/docs/admin/1.1/installation.html
Expand All @@ -36,10 +94,13 @@ RUN apt-get update && \
gir1.2-packagekitglib-1.0 && \
rm -rf /var/cache/apt/archives /var/lib/apt/lists/*

# for ifeval benchmark
# TODO: can we get just a single dir?
# IFEval imports this module from the repository root. Retain only the benchmark
# it executes; unrelated manifests elsewhere in google-research describe Julia
# and Rust projects that are neither installed nor used by this image.
RUN mkdir /opt/benchmarks
RUN git clone https://github.com/google-research/google-research.git /opt/benchmarks/google-research --depth=1
RUN git clone https://github.com/google-research/google-research.git /opt/benchmarks/google-research --depth=1 && \
cd /opt/benchmarks/google-research && \
find . -mindepth 1 -maxdepth 1 ! -name instruction_following_eval -exec rm -rf {} +

RUN git clone https://github.com/ShishirPatil/gorilla.git /opt/gorilla
RUN cd /opt/gorilla && git checkout 86d0374d0db52623c5092a73f82c22b87b7e9a25
Expand All @@ -59,7 +120,8 @@ RUN cd ${IFBENCH_DIR} && pip install -r requirements.txt
COPY dockerfiles/ifbench.patch /opt/benchmarks/IFBench/ifbench.patch
RUN cd /opt/benchmarks/IFBench && git apply ifbench.patch

RUN pip install langdetect absl-py immutabledict nltk ipython && \
RUN pip install langdetect absl-py immutabledict \
"nltk @ git+https://github.com/nltk/nltk.git@${NLTK_SECURITY_COMMIT}" ipython && \
python -c "import nltk; from spacy.cli import download; nltk.download('punkt'); nltk.download('punkt_tab'); \
nltk.download('stopwords'); nltk.download('averaged_perceptron_tagger_eng'); download('en_core_web_sm')"

Expand All @@ -73,9 +135,61 @@ COPY core/requirements.txt /opt/NeMo-Skills/core/requirements.txt
RUN pip install git+https://github.com/NVIDIA/NeMo-speech-data-processor@29b9b1ec0ceaf3ffa441c1d01297371b3f8e11d2
ARG CACHEBUST=4
# Install via `uv pip` from the project directory so [tool.uv].override-dependencies
# in pyproject.toml (which relaxes leptonai's httpx==0.27.2 pin so litellm 1.83.x
# in pyproject.toml (which relaxes leptonai's httpx==0.27.2 pin so litellm 1.84.x
# can be installed) is picked up. Plain pip ignores [tool.uv] and the resolver fails.
FROM runtime-base AS dependency-installer
COPY --from=uv-installer /uv /usr/local/bin/uv
RUN uv --version | grep -E '^uv 0\.12\.9([[:space:]]|$)'
RUN cd /opt/NeMo-Skills && uv pip install --system --no-cache-dir \
-r core/requirements.txt -r requirements/pipeline.txt
-r core/requirements.txt -r requirements/pipeline.txt && \
rm -f /usr/local/bin/uv && rm -rf /root/.cache/uv

# Replace /usr/local with the resolved environment, not the uv layer that
# created it. Replacement prevents metadata from older pre-resolution packages
# from surviving alongside the resolved versions.
FROM runtime-base
ARG NLTK_SECURITY_COMMIT
RUN rm -rf /usr/local
COPY --from=dependency-installer /usr/local/ /usr/local/
# Replace W&B's vulnerable release binary with the source-compatible patched core
# built and module-verified above. The copy preserves its executable mode.
COPY --from=wandb-core-builder /wandb-core /usr/local/lib/python3.10/dist-packages/wandb/bin/wandb-core
RUN /usr/local/lib/python3.10/dist-packages/wandb/bin/wandb-core --help 2>&1 | \
grep -F "Commit SHA: ${WANDB_CORE_COMMIT}"
# Fix http mismatch between lepton and dggs by manually downloading dggs here
RUN pip install ddgs

# Ray's runtime-env agent prepends its bundled aiohttp 3.14.1 over the fixed
# environment package. Replace that private copy with the resolved 3.14.3 files
# from the same architecture (CVE-2026-69244).
RUN site_packages="$(python -c "import sysconfig; print(sysconfig.get_paths()['purelib'])")" && \
ray_thirdparty="${site_packages}/ray/_private/runtime_env/agent/thirdparty_files" && \
rm -rf "${ray_thirdparty}/aiohttp" "${ray_thirdparty}"/aiohttp-*.dist-info && \
cp -a "${site_packages}/aiohttp" "${ray_thirdparty}/" && \
cp -a "${site_packages}"/aiohttp-*.dist-info "${ray_thirdparty}/"

# Guard the final resolved environment and Ray's private import path against the
# High findings seen in the multi-architecture image scans.
RUN python -c "import json; from importlib.metadata import distribution as d, version as v; from packaging.version import Version as V; \
assert V(v('aiohttp')) >= V('3.14.3'), v('aiohttp'); \
assert V(v('msgpack')) >= V('1.2.1'), v('msgpack'); \
assert V(v('nltk')) >= V('3.10.3'), v('nltk'); \
direct = json.loads(d('nltk').read_text('direct_url.json')); expected = '${NLTK_SECURITY_COMMIT}'; \
assert direct['vcs_info']['requested_revision'] == expected, direct; \
assert direct['vcs_info']['commit_id'] == expected, direct; \
assert V(v('starlette')) >= V('1.3.1'), v('starlette'); \
assert V(v('setuptools')) >= V('78.1.1'), v('setuptools'); \
print('aiohttp/msgpack/nltk/starlette/setuptools security floors OK')" && \
python -c "from fastapi import FastAPI; FastAPI(); print('FastAPI/Starlette compatibility OK')" && \
python -c "import sys; from importlib.util import find_spec; from pathlib import Path; from packaging.version import Version; thirdparty = Path(find_spec('ray').submodule_search_locations[0]) / '_private/runtime_env/agent/thirdparty_files'; sys.path.insert(0, str(thirdparty)); import aiohttp, ray; assert Path(aiohttp.__file__).is_relative_to(thirdparty), aiohttp.__file__; assert Version(aiohttp.__version__) >= Version('3.14.3'), aiohttp.__version__; print('Ray private aiohttp OK:', ray.__version__, aiohttp.__version__)" && \
[ ! -e /usr/local/bin/uv ] && \
[ ! -e /usr/local/lib/python3.10/dist-packages/pip/_vendor/bom.cdx.json ] && \
[ -z "$(find /usr/local/lib/python3*/dist-packages -maxdepth 1 -type d -name 'uv-*.dist-info' 2>/dev/null)" ]

# nSpect's global policy flags Git metadata left by uv's source-distribution
# cache. Ray's Java runtime is not used by the Python jobs in this image, and
# linux-libc-dev provides build-only headers. Remove all three after builds.
RUN apt-get purge -y linux-libc-dev && \
rm -rf /usr/local/lib/python3*/dist-packages/ray/jars && \
rm -rf /var/cache/apt/archives /var/lib/apt/lists/* && \
[ -z "$(find /usr/local/lib/python3*/dist-packages -path '*/ray/jars/*' -type f 2>/dev/null)" ]
1 change: 1 addition & 0 deletions dockerfiles/Dockerfile.sandbox
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@
# To regenerate after changing code_execution.txt or stem.txt:
# uv pip compile requirements/code_execution.txt requirements/stem.txt \
# --extra-index-url https://download.pytorch.org/whl/cpu \
# --index-strategy unsafe-best-match \
# --universal -p 3.10 -o requirements/sandbox.lock
# =============================================================================

Expand Down
5 changes: 3 additions & 2 deletions docs/evaluation/external-benchmarks.md
Original file line number Diff line number Diff line change
Expand Up @@ -307,10 +307,11 @@ Run evaluation (using an API model as an example):
ns eval \
--cluster=local \
--server_type=openai \
--model=nvidia/nemotron-3-nano-30b-a3b \
--model=openai/gpt-oss-20b \
--server_address=https://integrate.api.nvidia.com/v1 \
--benchmarks=word_count \
--output_dir=/workspace/test-eval
--output_dir=/workspace/test-eval \
++inference.temperature=1.0
```

View results:
Expand Down
3 changes: 2 additions & 1 deletion nemo_skills/inference/eval/bfcl.py
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,8 @@
"cohere==5.18.0",
"typer>=0.12.5",
"tabulate>=0.9.0",
"datamodel-code-generator==0.25.7",
# 0.64.0 fixes eight High findings through CVE-2026-55415.
"datamodel-code-generator==0.64.0",
"google-genai>=1.52.0",
# "qwen-agent", # disabling due to some issues (and shouldn't be needed)
"mpmath==1.3.0",
Expand Down
24 changes: 23 additions & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@

[build-system]
requires = [
"setuptools",
"setuptools>=78.1.1",
"wheel"
]
build-backend = "setuptools.build_meta"
Expand Down Expand Up @@ -80,6 +80,28 @@ override-dependencies = [
# 0.7.0 (a transitive dep of nemo_run) pins urllib3<1.27, but in practice
# urllib3>=2 works at runtime, so override the constraint.
"urllib3>=2.6.3",
# LeptonAI 0.27.3 caps AnyIO at <=4.9.0. Override that cap for the
# certificate-validation fix in CVE-2026-63374.
"anyio>=4.14.2",
# LeptonAI 0.27.3 pins instrumentator==7.0.0, which requires Starlette<1.0.
# Override it with the first release compatible with Starlette 1.x.
"prometheus-fastapi-instrumentator>=8.1.0",
# Container scans found vulnerable transitive versions. Keep the complete
# environment above the first fixed releases.
"aiohttp>=3.14.3",
"msgpack>=1.2.1",
# CVE-2026-81726 has no fixed release. This is the first exact upstream
# merge containing the complete TransitionParser, MaxEnt, and tagger fixes.
"nltk @ git+https://github.com/nltk/nltk.git@574270e2ad368c8816976e584da56ddfb3fefbad",
"setuptools>=78.1.1",
]

constraint-dependencies = [
# Fix CVE-2026-84381/CVE-2026-84382 in the HTTPX2 stack and
# CVE-2026-48818/CVE-2026-54283 in Starlette.
"httpcore2>=2.10.0",
"httpx2>=2.12.0",
"starlette>=1.3.1",
]

[tool.pytest.ini_options]
Expand Down
3 changes: 2 additions & 1 deletion recipes/data-integrity/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,8 @@ scripts/

1. **Basic Requirements**
```bash
pip install pandas numpy matplotlib seaborn scikit-learn nltk spacy \
pip install pandas numpy matplotlib seaborn scikit-learn \
"nltk @ git+https://github.com/nltk/nltk.git@574270e2ad368c8816976e584da56ddfb3fefbad" spacy \
sentence-transformers umap-learn plotly textstat textblob rouge \
datasets tqdm openai
```
Expand Down
2 changes: 1 addition & 1 deletion recipes/data-integrity/model_comparison/requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ matplotlib>=3.4.0
nbformat>=4.2.0

# NLP and text processing
nltk>=3.6.0
nltk @ git+https://github.com/nltk/nltk.git@574270e2ad368c8816976e584da56ddfb3fefbad # CVE-2026-81726 unreleased upstream fix
numpy>=1.21.0

# Additional dependencies that may be needed
Expand Down
2 changes: 2 additions & 0 deletions requirements/common-tests.txt
Original file line number Diff line number Diff line change
Expand Up @@ -20,3 +20,5 @@ pytest-timeout
# ray.job_submission, which lives in the [default] extras.
ray[default]>=2.43,<3.0
soundfile
# TOML parsing in tests/test_requirements_versions.py on Python 3.10 (tomllib is stdlib only from 3.11)
tomli; python_version < '3.11'
Loading
Loading