chore(audit): refresh the minimum version table - #26
Merged
Merged
Conversation
github-actions
Bot
requested review from
JordanNanos,
Prathmesh234,
functionstackx and
samharshe
as code owners
September 25, 2026 03:31
github-actions
Bot
force-pushed
the
automation/minimum-versions
branch
from
September 25, 2026 03:45
1f02d03 to
e682a01
Compare
The daily refresh job read the upstream advisory feeds and wrote the new minimums.
github-actions
Bot
force-pushed
the
automation/minimum-versions
branch
from
September 25, 2026 04:06
e682a01 to
98ac5f3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
The audit compares each cluster component against a minimum safe
version, which this repository calls a minimum. The upstream vendors
publish new advisories, and the minimums must follow them. The daily
refresh job made this pull request.
What changed
cmax/scripts/1-audit/minimum-versions.json: 2 values changed in 1 component.nvhpc
currentminimumUpstream sources:
New upstream bulletins
The generator found relevant bulletins that the table does not track. A new bulletin is a human decision, so this job does not add it. Track each NVIDIA bulletin in BULLETINS in
cmax/minimum_refresh.py, or record the reason to defer it in DEFERRED_BULLETINS. Track each Docker Engine major in DOCKER_ENGINE_MAJORS. Track each AMD GPU bulletin in AMD_BULLETINS, or record the reason to defer it in AMD_DEFERRED_BULLETINS. Do that in a separate pull request.Effect
that did not change. Read each source link above before you
approve this change.
stay unchanged. The table keeps schema version 1.
Technical terms
minimum: the lowest version of a component that has no knownapplicable vulnerability.
CVE: Common Vulnerabilities and Exposures. A public identifierfor one vulnerability.
CSAF: Common Security Advisory Framework. The machine-readableadvisory format that NVIDIA publishes.
fix availability: the confirmed date when the exact fixedrelease became available from the upstream vendor.
Validation
python3 -m cmax.minimum_refresh --write cmax/scripts/1-audit/minimum-versions.json: pass. Thegenerator stops with an error and writes nothing if a populated
component extracts empty. It also records confirmed or
unconfirmed availability for every generated minimum.
python3 -m pytest -q tests/audit/: pass. The policytests grade each minimum at the minimum and below the minimum.
Merge plan
Design decisions for approval
and correct the generator.
upstream source link above, including the fixed-release link.
Automation notes:
minimum-versions-refreshworkflow made this pull requestfrom run https://github.com/SemiAnalysisAI/ClusterMAX/actions/runs/36092850829.
masterand force-pushes it. Do not add commits to this branch.To change the table, change the generator
cmax/minimum_refresh.py.a workflow token created. Close and reopen this pull request to
start the usual checks.
Note
Low Risk
Data-only bump to audit thresholds in generated JSON; no application code changes, but operators may see new audit failures for older nvhpc installs.
Overview
Refreshes the automated minimum-versions audit table in
cmax/scripts/1-audit/minimum-versions.jsonand updates the file’sgeneratedtimestamp.For NVIDIA HPC SDK (
nvhpc), thereleaseWindowentries move tocurrent26.9 (was 26.5) andminimum26.5 (was 26.3), per the NVIDIA HPC SDK releases feed and the existingcurrent-or-previouspolicy. Clusters below the new minimum may start failing the audit (or see upgrade guidance during the grace window) even if nothing else changed on the cluster.Reviewed by Cursor Bugbot for commit 98ac5f3. Bugbot is set up for automated code reviews on this repo. Configure here.