Vllm Ascend ReleaseSAFE
Community maintained hardware plugin for vLLM on Huawei Ascend
Overview
Community maintained hardware plugin for vLLM on Huawei Ascend
4e7ba390a37eOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
uv run python scripts/fetch_commits.py \
pip install vllm-ascend==${VERSION}git clone https://github.com/vllm-project/vllm-ascend.git
pip install -e .
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: vllm-ascend-release description: "End-to-end release management skill for vLLM Ascend. Creates release checklist issues, identifies critical bugs, runs functional tests, invokes release note generation, and guides through the complete release process." --- # vLLM Ascend Release Skill ## Overview This skill manages the complete end-to-end release process for vLLM Ascend, from creating the release checklist issue to final release announcement. It automates repetitive tasks while ensuring human oversight at critical decision points. ## When to Use This Skill Use this skill when: - Starting a new release cycle (RC or stable) - The release manager needs to track release progress - Preparing release artifacts (notes, documentation, tests) ## Prerequisites - GitHub CLI (`gh`) authenticated with write access to `vllm-project/vllm-ascend` - Access to Ascend NPU hardware for functional testing (or CI infrastructure) - Python environment with `uv` for running scripts ### Verify GitHub CLI Installation Before starting the release process, verify that `gh` CLI is installed and authenticated: ```bash # Check if gh is installed gh --version # If not installed, install gh CLI: # Ubuntu/Debian apt install gh -y # macOS brew install gh # OpenEuler yum install gh -y # Check authentication status gh auth status # If not authenticated, login with: gh auth login ``` Expected output for `gh auth status`: ``` github.com ✓ Logged in to github.com account <username> (keyring) - Active account: true - Git operations protocol: https - Token: gho_**** - Token scopes: 'gist', 'read:org', 'repo', 'workflow' ``` **Required scopes**: `repo` (for creating issues, PRs, releases) and `workflow` (for triggering CI workflows). ## Workflow Overview ``` ┌─────────────────────────────────────────────────────────────────────────────┐ │ vLLM Ascend Release Process │ ├─────────────────────────────────────────────────────────────────────────────┤ │ │ │ Phase 1: Initialization │ │ ├── Determine version & branch │ │ ├── Create feedback issue │ │ └── Create release checklist issue │ │ │ │ Phase 2: Bug Triage │ │ ├── Scan open bugs │ │ ├── Identify release-blocking bugs │ │ └── Update checklist with bug list │ │ │ │ Phase 3: PR Management │ │ ├── Identify must-merge PRs │ │ └── Update checklist with PR list │ │ │ │ Phase 4: Test Coverage Analysis │ │ ├── Scan PRs for features/models without tests │ │ ├── Check previous feedback issue status │ │ └── Update checklist with items needing manual testing │ │ │ │ Phase 5: Nightly Status │ │ ├── Get latest Nightly-A3 and Nightly-A2 runs │ │ ├── Analyze failures with extract_and_analyze.py │ │ └── Update checklist with nightly status table │ │ │ │ Phase 6: Release Notes (invoke existing skill) │ │ ├── Generate release notes via vllm-ascend-release-note-writer │ │ └── Create release notes PR │ │ │ │ Phase 7: Documentation & Artifacts │ │ └── Update version references (Docker/wheel built by CI automatically) │ │ │ │ Phase 8: Release Execution (requires human review) │ │ ├── Human review & approval │ │ ├── Merge release notes PR │ │ ├── Create GitHub release │ │ └── Verify automated pipelines (PyPI, Docker, ReadTheDocs) │ │ │ │ Phase 9: WeChat Article (微信公众号推文) │ │ ├── Collect release statistics (commits, contributors) │ │ ├── Generate WeChat article from template │ │ └── Review and publish to WeChat official account │ │ │ └─────────────────────────────────────────────────────────────────────────────┘ ``` ## Phase 1: Initialization ### 1.1 Gather Release Information Prompt the user for: - **Release Version**: e.g., `v0.15.0rc1`, `v0.15.0` - **Release Branch**: typically `main` - **Target Release Date**: e.g., `2026.03.15` - **Release Manager**: GitHub username ### 1.2 Determine Previous Version ```bash # Get the latest release tag gh release list --repo vllm-project/vllm-ascend --limit 5 # Or check existing tags git tag --sort=-creatordate | head -1
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4e7ba390a37efull audit observations/trust-audit/skill/vllm-project__vllm-ascend-release.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4e7ba390a37e | SAFE | B | 89 | first audit |
Questions
What does the Vllm Ascend Release skill do?
Community maintained hardware plugin for vLLM on Huawei Ascend
Is Vllm Ascend Release safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Vllm Ascend Release access on my machine?
The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.
How current is this page?
The grade is for one exact copy of the source (4e7ba390a37e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.