Skip to content

merge master changes into branch v1.4-2#267

Merged
jinyan-li1 merged 2 commits intov1.4-2from
master
Apr 9, 2026
Merged

merge master changes into branch v1.4-2#267
jinyan-li1 merged 2 commits intov1.4-2from
master

Conversation

@jinyan-li1
Copy link
Copy Markdown
Contributor

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Jyothirmaikottu and others added 2 commits March 24, 2026 10:33
Patch sagemaker-inference decoder.py at Docker build time to change
allow_pickle=True to allow_pickle=False, preventing pickle
deserialization RCE via malicious NPY payloads.

sim: https://t.corp.amazon.com/P398172182
…ialization

fix: set allow_pickle=False in NPY decoder for CWE-502
@jinyan-li1 jinyan-li1 merged commit 68db4df into v1.4-2 Apr 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants