Lincoln Stein ba89444e36 scan legacy checkpoint models in converter script prior to unpickling
Two related security fixes:

1. Port #2946 from main to 2.3.2 branch - this closes a hole that
   allows a pickle checkpoint file to masquerade as a safetensors
   file.

2. Add pickle scanning to the checkpoint to diffusers conversion
   script. This will be ported to main in a separate PR.
2023-03-23 13:44:08 -04:00
..
2023-03-13 10:15:33 -04:00
2023-03-09 22:35:43 -05:00
2023-03-13 09:35:25 -04:00
2023-03-13 12:51:27 -04:00
2023-03-09 22:35:43 -05:00
2022-12-20 15:32:35 -08:00
2023-02-20 07:33:19 -05:00
2023-01-15 09:22:46 -05:00
2023-02-03 17:35:35 -05:00