You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An unpinned git dependency.Dockerfile.gpu runs pip install git+https://github.com/fbcotter/pytorch_wavelets.git, which installs whatever is on the default branch at build time. That is a reproducibility risk and a supply-chain risk.
The PyTorch pin may no longer be needed. The Dockerfile comment pins pytorch/pytorch:2.1.2-cuda12.1 because pytorch_wavelets "uses old-style autograd.Function". In this audit, current pytorch_wavelets HEAD imported and ran extract_audio_gpu correctly on torch 2.14 (CPU). So the pin (a 2023 base image) may be removable. Please confirm on CUDA.
Inconsistent requirements.requirements-gpu.txt pins numpy<2, while requirements.txt allows <3. PyWavelets has no upper bound. There's no lock file. The CPU image uses opencv-python (needs libgl1/libglib2.0-0), while the GPU image uses the headless build.
The builder's UID is baked into the image. Both Dockerfiles need UID/GID/UNAME build args: a plain docker build . fails, building as root fails, and the images can't be published for other users.
Base image and workflow.python:3.11-slim isn't pinned to a patch release. The workflow has no permissions: block, and actions aren't SHA-pinned.
Suggested fix
Install pytorch_wavelets @ git+…@<commit-sha>, or vendor the DTCWT forward pass: only DTCWTForward is used, about 300 lines under MIT licence.
Test a current PyTorch base (2.4+), and drop the 2.1.2 pin and numpy<2 if they pass.
Keep version ranges in pyproject.toml, generate lock files with uv pip compile, and install from them in Docker and CI.
Use opencv-python-headless everywhere.
Use a fixed non-root user and document docker run --user "$(id -u):$(id -g)".
Add permissions: contents: read, pin actions by SHA, and enable Dependabot.
Severity: Medium.
Problems
Dockerfile.gpurunspip install git+https://github.com/fbcotter/pytorch_wavelets.git, which installs whatever is on the default branch at build time. That is a reproducibility risk and a supply-chain risk.pytorch/pytorch:2.1.2-cuda12.1because pytorch_wavelets "uses old-style autograd.Function". In this audit, current pytorch_wavelets HEAD imported and ranextract_audio_gpucorrectly on torch 2.14 (CPU). So the pin (a 2023 base image) may be removable. Please confirm on CUDA.requirements-gpu.txtpinsnumpy<2, whilerequirements.txtallows<3.PyWaveletshas no upper bound. There's no lock file. The CPU image usesopencv-python(needslibgl1/libglib2.0-0), while the GPU image uses the headless build.UID/GID/UNAMEbuild args: a plaindocker build .fails, building as root fails, and the images can't be published for other users.python:3.11-slimisn't pinned to a patch release. The workflow has nopermissions:block, and actions aren't SHA-pinned.Suggested fix
pytorch_wavelets @ git+…@<commit-sha>, or vendor the DTCWT forward pass: onlyDTCWTForwardis used, about 300 lines under MIT licence.numpy<2if they pass.pyproject.toml, generate lock files withuv pip compile, and install from them in Docker and CI.opencv-python-headlesseverywhere.docker run --user "$(id -u):$(id -g)".permissions: contents: read, pin actions by SHA, and enable Dependabot.Acceptance criteria
docker build .works with no build args.