Hub rules-diffusers

rules-diffusers

v5 public Verified

Diffusers

Hugging Face Diffusers is a library for state-of-the-art pretrained diffusion models. These rules govern the configuration and optimization of diffusion pipelines for AI-driven creative and generative image/audio tasks.

@sigmashakeinc 2 pulls 4 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-diffusers →
Severity
3 error 1 warn 0 info
demo.cast
Hugging Face Diffusers is a library for state-of-the-art pretrained diffusion models. These rules govern the configuration and optimization of diffusion pipelines for AI-driven creative and generative image/audio tasks.

Rules index

4 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

diffusers

diffusers-from-pretrained-local-unsafe warning log

local_files_only=False (the default) causes from_pretrained() to fetch model weights from the HuggingFace Hub at runtime. In production inference environments this adds an uncontrolled external network dependency and bypasses any supply-chain review. FIX: Set local_files_only=True and pre-download approved model artifacts to an internal registry or filesystem.

Rule source requires an active Pro or Enterprise subscription.
diffusers-path-traversal-save error block

RISK: Passing a user-controlled or concatenated path to save_pretrained() enables path traversal — an attacker can write model weights to arbitrary filesystem locations (CWE-22). FIX: Validate and canonicalize the output path against an allowlisted base directory before passing it to save_pretrained().

Rule source requires an active Pro or Enterprise subscription.
diffusers-pickle-load error block

RISK: torch.load() on a .pt/.bin file uses Python's pickle protocol by default, enabling arbitrary code execution when loading a malicious checkpoint (CVE-2024-5480 and related). FIX: Use torch.load(..., weights_only=True) (PyTorch ≥ 2.0) or load from .safetensors format via from_pretrained() with the safetensors extra. Never load .pkl/.pt checkpoints from untrusted sources.

Rule source requires an active Pro or Enterprise subscription.
diffusers-trust-remote-code error block

RISK: trust_remote_code=True allows the model card or pipeline to execute arbitrary Python code downloaded from a HuggingFace Hub repository at load time — a malicious or compromised model can achieve full RCE (CWE-94). FIX: Audit the model's modeling_*.py files before enabling this; prefer models that do not require it. Never enable in production inference servers.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
f7193dd2c3bac00412b7db890908d9ca92919e06e8e3b0b7057319c77b17987d
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-diffusers/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-diffusers. The published version only bumps when a maintainer resyncs.

No commit history available.