Skip to content

chore(audit): refresh the minimum version table - #12

Merged
JordanNanos merged 2 commits into
masterfrom
automation/minimum-versions
Aug 30, 2026
Merged

chore(audit): refresh the minimum version table#12
JordanNanos merged 2 commits into
masterfrom
automation/minimum-versions

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Purpose

The audit compares each cluster component against a minimum safe
version, which this repository calls a minimum. The upstream vendors
publish new advisories, and the minimums must follow them. The daily
refresh job made this pull request.

What changed

  • cmax/scripts/1-audit/minimum-versions.json: 74 values changed in 2 components.
  • A component version below its new minimum reports a pass with an upgrade recommendation until the fixed release is confirmed, then during the three-calendar-day grace period. The grace clock starts on the later of bulletin publication and fix availability.

docker

Item Before After
advisories (none) GHSA-hfg8-hc9c-6c3h
source.feed manual docker-release-notes
source.majors (none) 29
source.reason Docker publishes no machine-readable feed that maps advisories to Engine releases (none)
source.released (none) 2026-07-30T00:00:00Z
source.url https://docs.docker.com/security/security-announcements/ https://docs.docker.com/engine/release-notes/29/

Upstream sources:

rocm

Item Before After
advisory (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html
cves (none) CVE-2025-21940, CVE-2025-66660, CVE-2025-66664, CVE-2026-0428
floorAvailability.MI210.aId (none) AMD-SB-6027
floorAvailability.MI210.available (none) 2025-09-15T00:00:00Z
floorAvailability.MI210.bulletinReleased (none) 2026-05-12T00:00:00Z
floorAvailability.MI210.feed (none) amd-security-bulletin
floorAvailability.MI210.status (none) confirmed
floorAvailability.MI210.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html
floorAvailability.MI210.version (none) 7.0.1
floorAvailability.MI250.aId (none) AMD-SB-6027
floorAvailability.MI250.available (none) 2025-09-15T00:00:00Z
floorAvailability.MI250.bulletinReleased (none) 2026-05-12T00:00:00Z
floorAvailability.MI250.feed (none) amd-security-bulletin
floorAvailability.MI250.status (none) confirmed
floorAvailability.MI250.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html
floorAvailability.MI250.version (none) 7.0.1
floorAvailability.MI300A.aId (none) AMD-SB-6027
floorAvailability.MI300A.available (none) 2025-10-06T00:00:00Z
floorAvailability.MI300A.bulletinReleased (none) 2026-05-12T00:00:00Z
floorAvailability.MI300A.feed (none) amd-security-bulletin
floorAvailability.MI300A.status (none) confirmed
floorAvailability.MI300A.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html
floorAvailability.MI300A.version (none) 7.0.1
floorAvailability.MI300X.aId (none) AMD-SB-6024
floorAvailability.MI300X.available (none) 2025-07-21T00:00:00Z
floorAvailability.MI300X.bulletinReleased (none) 2026-02-10T00:00:00Z
floorAvailability.MI300X.feed (none) amd-security-bulletin
floorAvailability.MI300X.status (none) confirmed
floorAvailability.MI300X.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6024.html
floorAvailability.MI300X.version (none) 6.4.2
floorAvailability.MI308X.aId (none) AMD-SB-6027
floorAvailability.MI308X.available (none) 2025-06-09T00:00:00Z
floorAvailability.MI308X.bulletinReleased (none) 2026-05-12T00:00:00Z
floorAvailability.MI308X.feed (none) amd-security-bulletin
floorAvailability.MI308X.status (none) confirmed
floorAvailability.MI308X.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html
floorAvailability.MI308X.version (none) 6.4.2
floorAvailability.MI325X.aId (none) AMD-SB-6024
floorAvailability.MI325X.available (none) 2025-07-21T00:00:00Z
floorAvailability.MI325X.bulletinReleased (none) 2026-02-10T00:00:00Z
floorAvailability.MI325X.feed (none) amd-security-bulletin
floorAvailability.MI325X.status (none) confirmed
floorAvailability.MI325X.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6024.html
floorAvailability.MI325X.version (none) 6.4.2
kind (none) programMap
programCves.MI210 (none) CVE-2025-66660
programCves.MI250 (none) CVE-2025-66660
programCves.MI300A (none) CVE-2025-66664
programCves.MI300X (none) CVE-2025-21940
programCves.MI308X (none) CVE-2025-66660, CVE-2025-66664, CVE-2026-0428
programCves.MI325X (none) CVE-2025-21940
programSources.MI210 (none) AMD-SB-6027
programSources.MI250 (none) AMD-SB-6027
programSources.MI300A (none) AMD-SB-6027
programSources.MI300X (none) AMD-SB-6024
programSources.MI308X (none) AMD-SB-6027
programSources.MI325X (none) AMD-SB-6024
programs.MI210 (none) 7.0.1
programs.MI250 (none) 7.0.1
programs.MI300A (none) 7.0.1
programs.MI300X (none) 6.4.2
programs.MI308X (none) 6.4.2
programs.MI325X (none) 6.4.2
source.aId (none) AMD-SB-6027
source.feed (none) amd-security-bulletin
source.released (none) 2026-05-12T00:00:00Z
source.url (none) https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html
sources (none) {'aId': 'AMD-SB-6018', 'feed': 'amd-security-bulletin', 'released': '2025-08-12T00:00:00Z', 'url': 'https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6018.html'}, {'aId': 'AMD-SB-6024', 'feed': 'amd-security-bulletin', 'released': '2026-02-10T00:00:00Z', 'url': 'https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6024.html'}, {'aId': 'AMD-SB-6027', 'feed': 'amd-security-bulletin', 'released': '2026-05-12T00:00:00Z', 'url': 'https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6027.html'}

Upstream sources:

New upstream bulletins

The generator found no new bulletin. It reports each deferred bulletin and its written reason on every run, so the decision stays visible.

Deferred bulletins (a recorded decision, reviewed every run):
  5744  Security Bulletin: NVIDIA Networking SNAP4 - March 2026  https://github.com/NVIDIA/product-security/blob/main/2026/5744/5744.json
      reason: Networking SNAP4 publishes two fixed trains in one phrase, such as 'SNAP-4.9.1, SNAP4 4.5.5'. The current single-version grammar keeps 4.9.1 and drops the 4.5.5 LTS train, so tracking it needs parser work first.
  amd-sb-1000  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-1000.html
      reason: Windows 10 graphics driver bulletin for client GPUs. It names no ROCm release.
  amd-sb-1029  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-1029.html
      reason: Client graphics driver bulletin from November 2022. It names no ROCm release.
  amd-sb-6003  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6003.html
      reason: Client graphics driver bulletin from November 2023. It names no ROCm release.
  amd-sb-6005  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html
      reason: Consolidated bulletin from August 2024 in the older transposed table format. Its highest ROCm release is 6.3.2, below the tracked minimums.
  amd-sb-6007  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6007.html
      reason: Radeon Software Crimson bulletin for client GPUs. It names no ROCm release.
  amd-sb-6008  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6008.html
      reason: Consolidated bulletin from February 2025. It names no ROCm release.
  amd-sb-6009  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6009.html
      reason: Radeon kernel driver bulletin for client GPUs. It names no ROCm release.
  amd-sb-6010  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6010.html
      reason: GPU memory leak bulletin in the older per-environment table format. Its highest ROCm release is 6.3.1, below the tracked minimums.
  amd-sb-6011  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6011.html
      reason: WebGPU browser side-channel note. It names no ROCm release.
  amd-sb-6012  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6012.html
      reason: Radeon DirectX 11 shader bulletin for client GPUs. It names no ROCm release.
  amd-sb-6013  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6013.html
      reason: Uninitialized GPU register bulletin in the older per-environment table format. Its highest ROCm release is 6.3.1, below the tracked minimums.
  amd-sb-6015  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6015.html
      reason: Graphics driver installer bulletin for client GPUs. It names no ROCm release.
  amd-sb-6016  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6016.html
      reason: Client GPU bulletin. It names no ROCm release.
  amd-sb-6019  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6019.html
      reason: Cross-process GPU memory disclosure note. It names no ROCm release.
  amd-sb-6021  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6021.html
      reason: Linux graphics driver bulletin in the older format. Its highest ROCm release is 6.2, below the tracked minimums.
  amd-sb-6026  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6026.html
      reason: GPU timing side-channel research note. It names no ROCm release.
  amd-sb-6031  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6031.html
      reason: Device Metrics Exporter bulletin. The fix is an exporter release, and the audit does not grade the exporter version.
  amd-sb-7049  title unavailable  https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7049.html
      reason: GPUHammer research note. It names no ROCm release.

no unknown bulletins for the graded product lines

Effect

  • Users: None.
  • Operators: The audit can give a new fail result for a cluster
    that did not change. Read each source link above before you
    approve this change.
  • Developers: None.
  • Data and compatibility: Audit results that are already committed
    stay unchanged. The table keeps schema version 1.

Technical terms

  • minimum: the lowest version of a component that has no known
    applicable vulnerability.
  • CVE: Common Vulnerabilities and Exposures. A public identifier
    for one vulnerability.
  • CSAF: Common Security Advisory Framework. The machine-readable
    advisory format that NVIDIA publishes.
  • fix availability: the confirmed date when the exact fixed
    release became available from the upstream vendor.

Validation

  • python3 -m cmax.minimum_refresh --write cmax/scripts/1-audit/minimum-versions.json: pass. The
    generator stops with an error and writes nothing if a populated
    component extracts empty. It also records confirmed or
    unconfirmed availability for every generated minimum.
  • python3 -m pytest -q tests/audit/: pass. The policy
    tests grade each minimum at the minimum and below the minimum.
  • Not run: an audit on a live cluster. This job has no cluster.

Merge plan

  • Merge order: None. This PR can merge independently.
  • Dependency: None.
  • Release step: None.

Design decisions for approval

  • Approval required: Yes.
  • Decision: accept the new minimums and fix availability evidence.
  • Options: merge the refreshed table, or keep the current table
    and correct the generator.
  • Recommendation: merge the refreshed table after you check each
    upstream source link above, including the fixed-release link.
  • Approver: the ClusterMAX security reviewer.

Automation notes:

  • The minimum-versions-refresh workflow made this pull request
    from run https://github.com/SemiAnalysisAI/ClusterMAX/actions/runs/33299141202.
  • The workflow owns the branch. Each run rebuilds the branch from
    master and force-pushes it. Do not add commits to this branch.
    To change the table, change the generator cmax/minimum_refresh.py.
  • GitHub does not start the other workflows for a pull request that
    a workflow token created. Close and reopen this pull request to
    start the usual checks.

Note

Medium Risk
Updates audit policy data for Docker Engine and ROCm by GPU program; operators may see new fail or upgrade recommendations without any cluster change.

Overview
Automated daily refresh of cmax/scripts/1-audit/minimum-versions.json so cluster audits track current vendor security floors.

Docker now records GHSA-hfg8-hc9c-6c3h and switches provenance from a manual source to the docker-release-notes feed (Engine 29 release notes), with source.majors set to 29. Minimum 29.7.0 and fix metadata for CVE-2026-17106 are unchanged in substance; attribution and advisory linkage are updated.

ROCM gains a full programMap entry: per-accelerator minimum ROCm versions (MI210MI325X), mapped CVEs, floorAvailability with confirmed AMD bulletin evidence, and sources spanning AMD-SB-6018, 6024, and 6027. Clusters below these program-specific floors can start failing audit after the grace window.

The file generated timestamp moves to 2026-08-30; nvhpc appears only as JSON reordering alongside the new rocm block.

Reviewed by Cursor Bugbot for commit d712484. Bugbot is set up for automated code reviews on this repo. Configure here.

The daily refresh job read the upstream advisory feeds and wrote the new minimums.
@JordanNanos
JordanNanos merged commit 3f426ba into master Aug 30, 2026
5 checks passed
@JordanNanos
JordanNanos deleted the automation/minimum-versions branch August 30, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant