{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Model Reference","siteUrl":"https://docs.hiddenlayer.ai"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"model-reference","__idx":0},"children":["Model Reference"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"advisory-summary","__idx":1},"children":["Advisory Summary"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The container references external model artifacts or requires model selection at runtime. NIM container scans (Supply Chain version 26.6.0 and later) emit advisory ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CONTAINER_0001_202606"]}]}," with manifest evidence (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["default_model"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["model_manifest"]},") and list external artifact URIs in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["summary.referenced_models"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"security-impact","__idx":2},"children":["Security Impact"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Understanding which models a container references helps inventory supply chain dependencies and deployment configuration. Misconfigured or unexpected model references may indicate an incomplete deployment or an opportunity to scan referenced artifacts for security issues."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Referenced model weights are not scanned during the container scan itself. Deploying the container without scanning those artifacts leaves a gap in supply chain visibility."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"false-positive-considerations","__idx":3},"children":["False Positive Considerations"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This advisory is informational. Containers commonly reference external models by design, and runtime model selection is expected behavior for some deployment configurations."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"recommended-remediation","__idx":4},"children":["Recommended Remediation"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Review the referenced model URIs in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["summary.referenced_models"]}," and the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["default_model"]}," value in advisory evidence to confirm they match expected deployment intent."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Download referenced NGC artifacts and scan them for security issues before deploying the container to production. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/products/supply-chain/cli/ngc_cli_download"},"children":["Download with NGC CLI"]}," for download steps and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/products/supply-chain/cli/nim_container"},"children":["NIM Container Scanning"]}," for the full follow-up workflow."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Ensure runtime model selection requirements are documented for operators deploying the container."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If referenced artifacts cannot be validated as legitimate or scan results raise concerns, remove the container from the deployment pipeline until the issue is resolved."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If the container is already deployed, escalate according to established security and incident response procedures to assess impact and determine appropriate containment or remediation actions."]}]}]},"headings":[{"value":"Model Reference","id":"model-reference","depth":1},{"value":"Advisory Summary","id":"advisory-summary","depth":2},{"value":"Security Impact","id":"security-impact","depth":2},{"value":"False Positive Considerations","id":"false-positive-considerations","depth":2},{"value":"Recommended Remediation","id":"recommended-remediation","depth":2}],"frontmatter":{"seo":{"title":"Model Reference"}},"lastModified":"2026-06-30T21:42:46.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/products/supply-chain/remediation-guide/model_reference","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}