Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RFC: security policy - disallow requests or similar for code downloads in modules #12

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

teward
Copy link

@teward teward commented Jan 14, 2025

Add RFC0005 to RFCs

Summary

Updates the Registry policies to prohibit separate downloading of Python code for 'inclusion' in a module's dependencies.

Links

Comfy-Org/docs PR that adds this to the Policy: Comfy-Org/docs#50

Third party repository doing unsafe behaviors, hence the writing of this policy: https://github.com/1038lab/ComfyUI-OmniGen/blob/4f9d6a945e3fa7aaf4485c4e7c5292c9b4826ab7/ailab_OmniGen.py

Third party repository issue regarding unsafe behavior: 1038lab/ComfyUI-OmniGen#38


Important: Do NOT comment on this PR. Please use the discussion thread linked above to provide feedback, as it provides branched discussions that are easier to follow. This also makes the edit history of the PR clearer.

@teward teward changed the title RFC-0005 rfc-05: security policy - disallow requests or similar for code downloads in modules Jan 14, 2025
@gremlation
Copy link

gremlation commented Jan 14, 2025

The discussion thread link points back to the PR by mistake. I created a discussion thread for this RFC here:

#13

…o rfcs/0005-security-policy-disallow-requests-for-code-downloads.md
@Comfy-Org Comfy-Org locked and limited conversation to collaborators Jan 14, 2025
@christian-byrne christian-byrne added rfc pending When the RFC is still in comments phase labels Jan 14, 2025
@huchenlei huchenlei changed the title rfc-05: security policy - disallow requests or similar for code downloads in modules RFC: security policy - disallow requests or similar for code downloads in modules Jan 16, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
pending When the RFC is still in comments phase rfc
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants