Skip to content

Comments

[None][fix] Fix vulnerability urllib3 and nbconvert#10551

Merged
yiqingy0 merged 7 commits intoNVIDIA:mainfrom
yiqingy0:fix_vulnerabilities
Jan 20, 2026
Merged

[None][fix] Fix vulnerability urllib3 and nbconvert#10551
yiqingy0 merged 7 commits intoNVIDIA:mainfrom
yiqingy0:fix_vulnerabilities

Conversation

@yiqingy0
Copy link
Collaborator

@yiqingy0 yiqingy0 commented Jan 8, 2026

Summary by CodeRabbit

  • Security Updates

    • Updated urllib3 dependency to patch version 2.6.3.
    • Mitigated vulnerability in deployment image by removing problematic package.
  • Chores

    • Refreshed deployment image tag versions.

✏️ Tip: You can customize this high-level summary in your review settings.

Description

Test Coverage

PR Checklist

Please review the following before submitting your PR:

  • PR description clearly explains what and why. If using CodeRabbit's summary, please make sure it makes sense.

  • PR Follows TRT-LLM CODING GUIDELINES to the best of your knowledge.

  • Test cases are provided for new code paths (see test instructions)

  • Any new dependencies have been scanned for license and vulnerabilities

  • CODEOWNERS updated if ownership changes

  • Documentation updated as needed

  • Update tava architecture diagram if there is a significant design change in PR.

  • The reviewers assigned automatically/manually are appropriate for the PR.

  • Please check this after reviewing the above items as appropriate for this PR.

GitHub Bot Help

/bot [-h] ['run', 'kill', 'skip', 'reuse-pipeline'] ...

Provide a user friendly way for developers to interact with a Jenkins server.

Run /bot [-h|--help] to print this help message.

See details below for each supported subcommand.

Details

run [--reuse-test (optional)pipeline-id --disable-fail-fast --skip-test --stage-list "A10-PyTorch-1, xxx" --gpu-type "A30, H100_PCIe" --test-backend "pytorch, cpp" --add-multi-gpu-test --only-multi-gpu-test --disable-multi-gpu-test --post-merge --extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx" --detailed-log --debug(experimental)]

Launch build/test pipelines. All previously running jobs will be killed.

--reuse-test (optional)pipeline-id (OPTIONAL) : Allow the new pipeline to reuse build artifacts and skip successful test stages from a specified pipeline or the last pipeline if no pipeline-id is indicated. If the Git commit ID has changed, this option will be always ignored. The DEFAULT behavior of the bot is to reuse build artifacts and successful test results from the last pipeline.

--disable-reuse-test (OPTIONAL) : Explicitly prevent the pipeline from reusing build artifacts and skipping successful test stages from a previous pipeline. Ensure that all builds and tests are run regardless of previous successes.

--disable-fail-fast (OPTIONAL) : Disable fail fast on build/tests/infra failures.

--skip-test (OPTIONAL) : Skip all test stages, but still run build stages, package stages and sanity check stages. Note: Does NOT update GitHub check status.

--stage-list "A10-PyTorch-1, xxx" (OPTIONAL) : Only run the specified test stages. Examples: "A10-PyTorch-1, xxx". Note: Does NOT update GitHub check status.

--gpu-type "A30, H100_PCIe" (OPTIONAL) : Only run the test stages on the specified GPU types. Examples: "A30, H100_PCIe". Note: Does NOT update GitHub check status.

--test-backend "pytorch, cpp" (OPTIONAL) : Skip test stages which don't match the specified backends. Only support [pytorch, cpp, tensorrt, triton]. Examples: "pytorch, cpp" (does not run test stages with tensorrt or triton backend). Note: Does NOT update GitHub pipeline status.

--only-multi-gpu-test (OPTIONAL) : Only run the multi-GPU tests. Note: Does NOT update GitHub check status.

--disable-multi-gpu-test (OPTIONAL) : Disable the multi-GPU tests. Note: Does NOT update GitHub check status.

--add-multi-gpu-test (OPTIONAL) : Force run the multi-GPU tests in addition to running L0 pre-merge pipeline.

--post-merge (OPTIONAL) : Run the L0 post-merge pipeline instead of the ordinary L0 pre-merge pipeline.

--extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx" (OPTIONAL) : Run the ordinary L0 pre-merge pipeline and specified test stages. Examples: --extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx".

--detailed-log (OPTIONAL) : Enable flushing out all logs to the Jenkins console. This will significantly increase the log volume and may slow down the job.

--debug (OPTIONAL) : Experimental feature. Enable access to the CI container for debugging purpose. Note: Specify exactly one stage in the stage-list parameter to access the appropriate container environment. Note: Does NOT update GitHub check status.

For guidance on mapping tests to stage names, see docs/source/reference/ci-overview.md
and the scripts/test_to_stage_mapping.py helper.

kill

kill

Kill all running builds associated with pull request.

skip

skip --comment COMMENT

Skip testing for latest commit on pull request. --comment "Reason for skipping build/test" is required. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

reuse-pipeline

reuse-pipeline

Reuse a previous pipeline to validate current commit. This action will also kill all currently running builds associated with the pull request. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

@yiqingy0
Copy link
Collaborator Author

yiqingy0 commented Jan 8, 2026

/bot run --stage-list "Build-Docker-Images"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #31077 [ run ] triggered by Bot. Commit: 352b9e3

@tensorrt-cicd
Copy link
Collaborator

PR_Github #31077 [ run ] completed with state DISABLED
CI server is currently disabled for scheduled maintenance. Estimated completion time: 9 AM PST on 1/8.

@yiqingy0 yiqingy0 force-pushed the fix_vulnerabilities branch from 352b9e3 to e93de22 Compare January 12, 2026 02:58
@yiqingy0
Copy link
Collaborator Author

/bot run --stage-list "Build-Docker-Images"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #31460 [ run ] triggered by Bot. Commit: e93de22

@yiqingy0 yiqingy0 changed the title [None][fix] Fix vulnerabilities of gpg and nbconvert [None][fix] Fix vulnerability nbconvert Jan 12, 2026
@tensorrt-cicd
Copy link
Collaborator

PR_Github #31460 [ run ] completed with state SUCCESS. Commit: e93de22
/LLM/main/L0_MergeRequest_PR pipeline #24320 (Partly Tested) completed with status: 'SUCCESS'

@yiqingy0 yiqingy0 force-pushed the fix_vulnerabilities branch from e93de22 to b5d0b48 Compare January 15, 2026 09:56
@yiqingy0
Copy link
Collaborator Author

/bot run --stage-list "Build-Docker-Images"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32116 [ run ] triggered by Bot. Commit: b5d0b48

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32116 [ run ] completed with state FAILURE. Commit: b5d0b48
/LLM/main/L0_MergeRequest_PR pipeline #24896 (Partly Tested) completed with status: 'FAILURE'

⚠️ Action Required:

  • Please check the failed tests and fix your PR
  • If you cannot view the failures, ask the CI triggerer to share details
  • Once fixed, request an NVIDIA team member to trigger CI again

@yiqingy0
Copy link
Collaborator Author

/bot run --stage-list "Build-Docker-Images"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32245 [ run ] triggered by Bot. Commit: 8ef1175

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32245 [ run ] completed with state FAILURE. Commit: 8ef1175
/LLM/main/L0_MergeRequest_PR pipeline #24995 (Partly Tested) completed with status: 'FAILURE'

⚠️ Action Required:

  • Please check the failed tests and fix your PR
  • If you cannot view the failures, ask the CI triggerer to share details
  • Once fixed, request an NVIDIA team member to trigger CI again

Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
@yiqingy0 yiqingy0 force-pushed the fix_vulnerabilities branch from 8ef1175 to f3b69e1 Compare January 19, 2026 03:42
@yiqingy0
Copy link
Collaborator Author

/bot run --disable-fail-fast --post-merge

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32509 [ run ] triggered by Bot. Commit: f3b69e1

@yiqingy0 yiqingy0 changed the title [None][fix] Fix vulnerability nbconvert [None][fix] Fix vulnerability urllib3 and nbconvert Jan 19, 2026
@tensorrt-cicd
Copy link
Collaborator

PR_Github #32509 [ run ] completed with state SUCCESS. Commit: f3b69e1
/LLM/main/L0_MergeRequest_PR pipeline #25177 completed with status: 'FAILURE'

⚠️ Action Required:

  • Please check the failed tests and fix your PR
  • If you cannot view the failures, ask the CI triggerer to share details
  • Once fixed, request an NVIDIA team member to trigger CI again

@yiqingy0
Copy link
Collaborator Author

/bot run --disable-fail-fast

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32641 [ run ] triggered by Bot. Commit: f3b69e1

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32641 [ run ] completed with state SUCCESS. Commit: f3b69e1
/LLM/main/L0_MergeRequest_PR pipeline #25270 completed with status: 'SUCCESS'

This reverts commit b5d0b48.

Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
@yiqingy0 yiqingy0 force-pushed the fix_vulnerabilities branch from f3b69e1 to 5c04f67 Compare January 20, 2026 05:44
@yiqingy0 yiqingy0 marked this pull request as ready for review January 20, 2026 05:45
@yiqingy0 yiqingy0 requested review from a team as code owners January 20, 2026 05:45
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Jan 20, 2026

📝 Walkthrough

Walkthrough

This update addresses security concerns by bumping the urllib3 dependency floor version, removes a vulnerable package from Docker images via a post-installation step, and updates Docker image tag references to newer builds.

Changes

Cohort / File(s) Summary
Dependency Constraints
constraints.txt
Updated urllib3 lower bound from 2.6.0 to 2.6.3
Docker Build Configuration
docker/Dockerfile.multi
Added nbconvert uninstall step post-installation to mitigate vulnerability in base image
CI/CD Image Tags
jenkins/current_image_tags.properties
Updated four Docker image tag variables (LLM_DOCKER_IMAGE, LLM_SBSA_DOCKER_IMAGE, LLM_ROCKYLINUX8_PY310_DOCKER_IMAGE, LLM_ROCKYLINUX8_PY312_DOCKER_IMAGE) with new timestamp and build suffixes (202601191127-10551)

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~5 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1
❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Description check ⚠️ Warning The PR description is entirely the template with no additional context, issue explanation, solution details, test coverage, or checklist completion provided by the author. Fill in the Description section explaining the vulnerabilities, the Test Coverage section listing relevant tests, and complete the PR Checklist items to demonstrate review of guidelines and testing.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: fixing vulnerabilities in urllib3 and nbconvert, which matches the modifications in constraints.txt and Dockerfile.multi.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@constraints.txt`:
- Line 5: Update the urllib3 version constraint in constraints.txt from
"urllib3>=2.6.3" to "urllib3>=2.6.0" (or, if 2.6.3 was intentionally required,
add a brief comment next to the "urllib3" entry explaining why 2.6.3 is
preferred) so that the constraint reflects the minimal patched version that
addresses GHSA-gm62-xv2j-4w53 and GHSA-2xpw-w6gg-jr37; locate the "urllib3"
entry in constraints.txt and either relax the version bound to >=2.6.0 or
annotate why 2.6.3 must be enforced.

@yiqingy0
Copy link
Collaborator Author

/bot skip --comment "The tests are passed in /LLM/main/L0_MergeRequest_PR pipeline #25270"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32670 [ skip ] triggered by Bot. Commit: 5c04f67

Signed-off-by: Yiqing Yan <yiqingy@nvidia.com>
@yiqingy0
Copy link
Collaborator Author

/bot skip --comment "The tests are passed in /LLM/main/L0_MergeRequest_PR pipeline #25270"

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32673 [ skip ] triggered by Bot. Commit: 4403733

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32670 [ skip ] completed with state ABORTED. Commit: 5c04f67

@tensorrt-cicd
Copy link
Collaborator

PR_Github #32673 [ skip ] completed with state SUCCESS. Commit: 4403733
Skipping testing for commit 4403733

@yiqingy0 yiqingy0 enabled auto-merge (squash) January 20, 2026 06:51
@yiqingy0 yiqingy0 merged commit 99e8cb0 into NVIDIA:main Jan 20, 2026
4 of 5 checks passed
@yiqingy0 yiqingy0 deleted the fix_vulnerabilities branch January 20, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants