Settings

Theme

Data shows public AI repos may be quietly becoming a supply chain risk

blog.ramalama.com

7 points by ersatz_username 5 months ago · 1 comment

Reader

ersatz_usernameOP 5 months ago

We analyzed over 1.8 million Hugging Face model repositories and found widespread licensing ambiguity, risky serialization formats, and subtle file-level inconsistencies—including drift between declared and actual artifact content. Even among the most-downloaded models, a surprising number are missing licenses or contain flagged files. Curious how others are thinking about model integrity and compliance in production.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection