Skip to content

Improve ONNX bundle runtime evidence gates#2183

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/onnx-bundle-runtime-fixtures-1385
Open

Improve ONNX bundle runtime evidence gates#2183
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/onnx-bundle-runtime-fixtures-1385

Conversation

@DENGXUELIN

Copy link
Copy Markdown

/claim #1385

Summary

  • Adds an ONNX bundle and runtime-provider evidence gate to model-supply-chain.
  • Requires reviewers to bind the full .onnx/.ort bundle, external tensor files, conversion provenance, parity validation, provider fallback policy, effective provider logs, and custom operator provenance.
  • Adds skill-local JSON fixtures for both a vulnerable .onnx-only digest/provider-fallback case and a benign complete bundle/runtime-policy case.

Validation

  • git diff --cached --check
  • git diff --check origin/main...HEAD
  • Parsed both JSON fixtures with ConvertFrom-Json
  • Verified Markdown fence balance
  • Verified MSC-ONNX-01 through MSC-ONNX-08 markers
  • Added-line sensitive-pattern scan
  • git merge-tree --write-tree origin/main HEAD matched HEAD^{tree}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant