quandao92 commited on
Commit
a481b99
ยท
verified ยท
1 Parent(s): 3213a6e

Update README.md

Browse files
Files changed (1) hide show
  1. README.md +12 -9
README.md CHANGED
@@ -343,14 +343,17 @@ pip install torch torchvision matplotlib opencv-python
343
  - `deps(upgrade): pandas 2.2.1 โ†’ 2.2.2 (CVE-XXXX fix)`
344
  - `deps(revert): rollback to deps-v1.3.0 due to perf regression`
345
 
346
- ### 3) ์ด๋ ฅ(CHANGELOG) ํ‘œ๊ธฐ ์˜ˆ์‹œ
347
  `/configs/dependency/CHANGELOG_requirements.md` ์— ๊ธฐ๋ก:
348
 
349
- | ๋‚ ์งœ | ํƒœ๊ทธ | ๋ณ€๊ฒฝ ์œ ํ˜• | ์ฃผ์š” ๋ณ€๊ฒฝ | ๊ทผ๊ฑฐ/๋งํฌ | ์˜ํ–ฅ |
350
- |-----:|:----:|:---------|:---------|:----------|:-----|
351
- | 2025-10-21 | deps-v1.4.0 | upgrade | TF 2.15.0 ์œ ์ง€, pandas 2.2.1โ†’2.2.2, sklearn 1.5.0โ†’1.5.1 | SCA ๋ณด๊ณ ์„œ 2025-10 | CVE ํŒจ์น˜, ํ•™์Šต OK |
352
- | 2025-09-03 | deps-v1.3.0 | pin | ์ตœ์ดˆ ํ•ด์‹œ ๊ณ ์ •(`--generate-hashes`) | ๋ณด์•ˆ ์ •์ฑ… rev.3 | ์žฌํ˜„์„ฑ ํ™•๋ณด |
353
- | 2025-08-18 | deps-v1.2.1 | revert | numpy 2.xโ†’1.26.4 ํšŒ๊ท€ | ์„ฑ๋Šฅ ํšŒ๊ท€(ํ›ˆ๋ จ ์‹œ๊ฐ„โ†‘) | ์•ˆ์ •ํ™” |
 
 
 
354
 
355
  > **์›์น™:** ๋ชจ๋“  ๋ณ€๊ฒฝ์€ **์™œ ๋ฐ”๊พธ์—ˆ๋Š”์ง€(๊ทผ๊ฑฐ)** ์™€ **์˜ํ–ฅ๋„** ๋ฅผ ๊ฐ™์ด ๋‚จ๊น๋‹ˆ๋‹ค.
356
 
@@ -395,9 +398,9 @@ pip install torch torchvision matplotlib opencv-python
395
 
396
  ```
397
 
398
- ## 5. SBOM ๋ฐ NOTICE ์˜ˆ์‹œ
399
 
400
- ### ๐Ÿ“˜ SBOM ํ•„๋“œ ์˜ˆ์‹œ
401
  | ํ•ญ๋ชฉ | ์˜ˆ์‹œ |
402
  |------|------|
403
  | Name | torch |
@@ -407,7 +410,7 @@ pip install torch torchvision matplotlib opencv-python
407
  | Supplier | PyTorch Foundation |
408
  | Source URL | https://pypi.org/project/torch/ |
409
 
410
- ### ๐Ÿ“œ THIRD_PARTY_NOTICES.txt ์˜ˆ์‹œ
411
  This product includes the following open-source components:
412
  - Ultralytics 8.x - AGPL-3.0
413
  - PyTorch 2.1.2 โ€” BSD-3-Clause
 
343
  - `deps(upgrade): pandas 2.2.1 โ†’ 2.2.2 (CVE-XXXX fix)`
344
  - `deps(revert): rollback to deps-v1.3.0 due to perf regression`
345
 
346
+ ### 3) ์ด๋ ฅ(CHANGELOG) ํ‘œ๊ธฐ
347
  `/configs/dependency/CHANGELOG_requirements.md` ์— ๊ธฐ๋ก:
348
 
349
+ | ๋‚ ์งœ | ํƒœ๊ทธ | ๋ณ€๊ฒฝ ์œ ํ˜• | ์ฃผ์š” ๋ณ€๊ฒฝ | ๊ทผ๊ฑฐ/๋งํฌ | ์˜ํ–ฅ |
350
+ | -----------------: | :---------: | :------------------: | ----------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- | ------------------------------------------------ |
351
+ | **2024-09-25 (์ˆ˜)** | deps-v0.1.0 | initial / pin | ์ดˆ๊ธฐ ์ž ๊ธˆ: `requirements.in` โ†’ `requirements.txt` ์ƒ์„ฑ (`--generate-hashes`) โ€” torch==1.13.1, torchvision, opencv-python, numpy, pandas ๋“ฑ ๊ธฐ๋ณธ ์˜์กด์„ฑ ๊ณ ์ • ๋ฐ ํ•ด์‹œ ํฌํ•จ | ์ดˆ๊ธฐ ๋ณด์•ˆ์ •์ฑ…ยทํ”„๋กœ์ ํŠธ ์…‹์—… | ์˜์กด์„ฑ ์žฌํ˜„์„ฑ ํ™•๋ณด, ์‹ ๊ทœ ํ™˜๊ฒฝ ์„ค์น˜ ์‹œ ๋™์ผ์„ฑ ๋ณด์žฅ |
352
+ | **2024-11-18 (์›”)** | deps-v0.2.0 | security upgrade | SCA ๋Œ€์‘: OpenCV / urllib3 / PyYAML ๋ณด์•ˆ ํŒจ์น˜ ๋ฐ˜์˜(๋ฒ„์ „ ์—…) ๋ฐ pip-compile ์žฌ์ƒ์„ฑ. Ultralytics/YOLO ๊ด€๋ จ ์ข…์†์„ฑ ๋ผ์ด์„ ์Šค(AGPL ์—ฌ๋ถ€) ๊ฒ€ํ†  ๊ธฐ๋ก ์ถ”๊ฐ€ | SCA ๋ฆฌํฌํŠธ 2024-11 (OSV/Trivy) | ๊ณ ์œ„ํ—˜ CVE ์™„ํ™”, ๋ผ์ด์„ ์Šค ๋ฆฌ์Šคํฌ ๊ฒ€ํ†  ํ•„์š”(AGPL ๋Œ€์‘) |
353
+ | **2025-01-14 (ํ™”)** | deps-v0.3.0 | policy / constraints | `constraints.txt` ๋„์ž… (protobuf, grpcio ๋“ฑ ์ƒยทํ•˜ํ•œ ์ œ์•ฝ), `requirements-dev.txt` ๋ถ„๋ฆฌ, THIRD_PARTY_NOTICES.txt ํ…œํ”Œ๋ฆฟ ์ถ”๊ฐ€ ๋ฐ ๊ฐ€์ค‘์น˜(.pt) ํ•ด์‹œ ์ •์ฑ… ๋ช…๋ฌธํ™” | ๋‚ด๋ถ€ ๊ฑฐ๋ฒ„๋„Œ์Šค ํšŒ์˜ 2025-01 | Dev/Staging ์ผ๊ด€์„ฑ ๊ฐ•ํ™”, ๋ฒ•์  ์ฆ๋น™ ์ค€๋น„ |
354
+ | **2025-04-15 (ํ™”)** | deps-v1.0.0 | upgrade (major) | PyTorch ๋ฒ„์ „(1.x โ†’ 2.1.x ๊ณ„์—ด) ๋ฐ ๊ด€๋ จ CUDA ํˆด์ฒด์ธ ์—…๋ฐ์ดํŠธ ๋ฐ˜์˜; SBOM(CycloneDX) ์ž๋™์ƒ์„ฑ ํŒŒ์ดํ”„๋ผ์ธ ์ถ”๊ฐ€; SCA ์žฌ๊ฒ€์ฆ(๊ณ ์œ„ํ—˜ CVE ํŒจ์น˜) | OSV/Trivy 2025-04 ๋ณด๊ณ ์„œ | ์„ฑ๋Šฅยท๋ณด์•ˆ ๊ฐœ์„ , Staging์—์„œ ์žฌํ›ˆ๋ จยท๊ฒ€์ฆ ํ•„์š” (GPU ๋“œ๋ผ์ด๋ฒ„/์ปจํ…Œ์ด๋„ˆ ์˜ํ–ฅ) |
355
+ | **2025-07-23 (์ˆ˜)** | deps-v1.1.0 | stabilization / pin | ์•ˆ์ •ํ™” ์กฐ์น˜: ์ผ๋ถ€ ํŒจํ‚ค์ง€(์˜ˆ: numpy, torchvision) ๋ฒ„์ „ ์žฌํ•€ ๋ฐ ํ•ด์‹œ ์žฌ์ƒ์„ฑ; THIRD_PARTY_NOTICES ์—…๋ฐ์ดํŠธ(AGPL ํ‘œ๊ธฐ ํฌํ•จ); ๋ฐฐํฌ์šฉ ์ปจํ…Œ์ด๋„ˆ์— LICENSE/NOTICE ๋™๋ด‰ ๊ทœ์ • ํ™•์ • | ์„ฑ๋Šฅ/๋ผ์ด์„ ์Šค ๊ฒ€์ฆ ๊ฒฐ๊ณผ(2025-06~07) | ํ”„๋กœ๋•์…˜ ๋ฐฐํฌ ์ค€๋น„ ์™„๋ฃŒ, ๋ฒ•๋ฌดยท๋ณด์•ˆ ๊ฐ์‚ฌ ๋Œ€์‘ ์ฒด๊ณ„ ๋งˆ๋ จ |
356
+
357
 
358
  > **์›์น™:** ๋ชจ๋“  ๋ณ€๊ฒฝ์€ **์™œ ๋ฐ”๊พธ์—ˆ๋Š”์ง€(๊ทผ๊ฑฐ)** ์™€ **์˜ํ–ฅ๋„** ๋ฅผ ๊ฐ™์ด ๋‚จ๊น๋‹ˆ๋‹ค.
359
 
 
398
 
399
  ```
400
 
401
+ ## 5. SBOM ๋ฐ NOTICE
402
 
403
+ ### ๐Ÿ“˜ SBOM ํ•„๋“œ
404
  | ํ•ญ๋ชฉ | ์˜ˆ์‹œ |
405
  |------|------|
406
  | Name | torch |
 
410
  | Supplier | PyTorch Foundation |
411
  | Source URL | https://pypi.org/project/torch/ |
412
 
413
+ ### ๐Ÿ“œ THIRD_PARTY_NOTICES.txt
414
  This product includes the following open-source components:
415
  - Ultralytics 8.x - AGPL-3.0
416
  - PyTorch 2.1.2 โ€” BSD-3-Clause