pypi
transformers
1 versiondiscovered · its AI-security audit & verification record by name.
4.47.0auditedresolved-commitattested-tag
coverage →huggingface/transformers @ 3a4b5c6d7e8f9012…
AI security assessmentfindingsrisk: highqwen2.5-7b-instruct
Model loading can deserialize attacker-supplied pickle when safetensors is bypassed.
- hightorch.load fallback deserializes untrusted checkpointsCWE-502src/transformers/modeling_utils.py:3480
- mediumtrust_remote_code imports repository-supplied PythonCWE-94src/transformers/dynamic_module_utils.py:190
Methodology
Sources @ 3a4b5c6d7e
README.md, src/transformers/modeling_utils.py, src/transformers/utils/hub.py, src/transformers/pipelines/base.py, src/transformers/dynamic_module_utils.py, src/transformers/configuration_utils.py
Parts 6 files, 14100 bytes (truncated)
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
classes examined: CWE-502
Independently verified by
Gate this package in CI
Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.
signet gate --purl pkg:pypi/transformers@4.47.0 --registry https://signet.seekerslab.com
README badge
Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.
