Securing the PyTorch Model Supply Chain: safetensors, Sandboxed Loading, Pinning and Model SBOMs
September 17, 2026 · IntelliSensei Team
Checkpoints are executable code. How pickle-based .pt files execute on load, why weights_only=True is not enough, and a practical hardening path: safetensors, sandboxed conversion, pickle scanning, immutable revision pinning, signing and a model SBOM.
Read more