Skip to content

chore(audit): refresh the minimum version table - #26

Merged
JordanNanos merged 1 commit into
masterfrom
automation/minimum-versions
Sep 25, 2026
Merged

JordanNanos merged 1 commit into
masterfrom
automation/minimum-versions

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Purpose

The audit compares each cluster component against a minimum safe
version, which this repository calls a minimum. The upstream vendors
publish new advisories, and the minimums must follow them. The daily
refresh job made this pull request.

What changed

  • cmax/scripts/1-audit/minimum-versions.json: 2 values changed in 1 component.
  • A component version below its new minimum reports a pass with an upgrade recommendation until the fixed release is confirmed, then during the three-calendar-day grace period. The grace clock starts on the later of bulletin publication and fix availability.

nvhpc

Item Before After
current 26.5 26.9
minimum 26.3 26.5

Upstream sources:

New upstream bulletins

The generator found relevant bulletins that the table does not track. A new bulletin is a human decision, so this job does not add it. Track each NVIDIA bulletin in BULLETINS in cmax/minimum_refresh.py, or record the reason to defer it in DEFERRED_BULLETINS. Track each Docker Engine major in DOCKER_ENGINE_MAJORS. Track each AMD GPU bulletin in AMD_BULLETINS, or record the reason to defer it in AMD_DEFERRED_BULLETINS. Do that in a separate pull request.

Deferred bulletins (a recorded decision, reviewed every run):
  5744  Security Bulletin: NVIDIA Networking SNAP4 - March 2026  https://github.com/NVIDIA/product-security/blob/main/2026/5744/5744.json
      reason: Networking SNAP4 publishes two fixed trains in one phrase, such as 'SNAP-4.9.1, SNAP4 4.5.5'. The current single-version grammar keeps 4.9.1 and drops the 4.5.5 LTS train, so tracking it needs parser work first.
  amd-sb-1000  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-1000.html
      reason: Windows 10 graphics driver bulletin for client GPUs. It names no ROCm release.
  amd-sb-1029  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-1029.html
      reason: Client graphics driver bulletin from November 2022. It names no ROCm release.
  amd-sb-6003  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6003.html
      reason: Client graphics driver bulletin from November 2023. It names no ROCm release.
  amd-sb-6005  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html
      reason: Consolidated bulletin from August 2024 in the older transposed table format. Its highest ROCm release is 6.3.2, below the tracked minimums.
  amd-sb-6007  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6007.html
      reason: Radeon Software Crimson bulletin for client GPUs. It names no ROCm release.
  amd-sb-6008  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6008.html
      reason: Consolidated bulletin from February 2025. It names no ROCm release.
  amd-sb-6009  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6009.html
      reason: Radeon kernel driver bulletin for client GPUs. It names no ROCm release.
  amd-sb-6010  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6010.html
      reason: GPU memory leak bulletin in the older per-environment table format. Its highest ROCm release is 6.3.1, below the tracked minimums.
  amd-sb-6011  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6011.html
      reason: WebGPU browser side-channel note. It names no ROCm release.
  amd-sb-6012  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6012.html
      reason: Radeon DirectX 11 shader bulletin for client GPUs. It names no ROCm release.
  amd-sb-6013  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6013.html
      reason: Uninitialized GPU register bulletin in the older per-environment table format. Its highest ROCm release is 6.3.1, below the tracked minimums.
  amd-sb-6015  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6015.html
      reason: Graphics driver installer bulletin for client GPUs. It names no ROCm release.
  amd-sb-6016  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6016.html
      reason: Client GPU bulletin. It names no ROCm release.
  amd-sb-6019  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6019.html
      reason: Cross-process GPU memory disclosure note. It names no ROCm release.
  amd-sb-6021  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6021.html
      reason: Linux graphics driver bulletin in the older format. Its highest ROCm release is 6.2, below the tracked minimums.
  amd-sb-6026  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6026.html
      reason: GPU timing side-channel research note. It names no ROCm release.
  amd-sb-6031  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6031.html
      reason: Device Metrics Exporter bulletin. The fix is an exporter release, and the audit does not grade the exporter version.
  amd-sb-7049  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7049.html
      reason: GPUHammer research note. It names no ROCm release.

Untracked bulletins that match a graded product line:
  amd-sb-6034  AMD Instinct GPU: Linux GPU Driver NULL Pointer Dereference  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6034.html
1 unknown bulletin(s) match a graded product line. Track each NVIDIA bulletin in BULLETINS in cmax/minimum_refresh.py, or record the reason to defer it in DEFERRED_BULLETINS. Track each Docker Engine major in DOCKER_ENGINE_MAJORS. Track each AMD GPU bulletin in AMD_BULLETINS, or record the reason to defer it in AMD_DEFERRED_BULLETINS.

Effect

  • Users: None.
  • Operators: The audit can give a new fail result for a cluster
    that did not change. Read each source link above before you
    approve this change.
  • Developers: None.
  • Data and compatibility: Audit results that are already committed
    stay unchanged. The table keeps schema version 1.

Technical terms

  • minimum: the lowest version of a component that has no known
    applicable vulnerability.
  • CVE: Common Vulnerabilities and Exposures. A public identifier
    for one vulnerability.
  • CSAF: Common Security Advisory Framework. The machine-readable
    advisory format that NVIDIA publishes.
  • fix availability: the confirmed date when the exact fixed
    release became available from the upstream vendor.

Validation

  • python3 -m cmax.minimum_refresh --write cmax/scripts/1-audit/minimum-versions.json: pass. The
    generator stops with an error and writes nothing if a populated
    component extracts empty. It also records confirmed or
    unconfirmed availability for every generated minimum.
  • python3 -m pytest -q tests/audit/: pass. The policy
    tests grade each minimum at the minimum and below the minimum.
  • Not run: an audit on a live cluster. This job has no cluster.

Merge plan

  • Merge order: None. This PR can merge independently.
  • Dependency: None.
  • Release step: None.

Design decisions for approval

  • Approval required: Yes.
  • Decision: accept the new minimums and fix availability evidence.
  • Options: merge the refreshed table, or keep the current table
    and correct the generator.
  • Recommendation: merge the refreshed table after you check each
    upstream source link above, including the fixed-release link.
  • Approver: the ClusterMAX security reviewer.

Automation notes:

  • The minimum-versions-refresh workflow made this pull request
    from run https://github.com/SemiAnalysisAI/ClusterMAX/actions/runs/36092850829.
  • The workflow owns the branch. Each run rebuilds the branch from
    master and force-pushes it. Do not add commits to this branch.
    To change the table, change the generator cmax/minimum_refresh.py.
  • GitHub does not start the other workflows for a pull request that
    a workflow token created. Close and reopen this pull request to
    start the usual checks.

Note

Low Risk
Data-only bump to audit thresholds in generated JSON; no application code changes, but operators may see new audit failures for older nvhpc installs.

Overview
Refreshes the automated minimum-versions audit table in cmax/scripts/1-audit/minimum-versions.json and updates the file’s generated timestamp.

For NVIDIA HPC SDK (nvhpc), the releaseWindow entries move to current 26.9 (was 26.5) and minimum 26.5 (was 26.3), per the NVIDIA HPC SDK releases feed and the existing current-or-previous policy. Clusters below the new minimum may start failing the audit (or see upgrade guidance during the grace window) even if nothing else changed on the cluster.

Reviewed by Cursor Bugbot for commit 98ac5f3. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions
github-actions Bot force-pushed the automation/minimum-versions branch from 1f02d03 to e682a01 Compare September 25, 2026 03:45
Base automatically changed from fix/minimum-refresh-timeout to master September 25, 2026 04:03
The daily refresh job read the upstream advisory feeds and wrote the new minimums.
@github-actions
github-actions Bot force-pushed the automation/minimum-versions branch from e682a01 to 98ac5f3 Compare September 25, 2026 04:06
@JordanNanos JordanNanos reopened this Sep 25, 2026
@JordanNanos
JordanNanos merged commit 50ecb6f into master Sep 25, 2026
5 checks passed
@JordanNanos
JordanNanos deleted the automation/minimum-versions branch September 25, 2026 05:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant