4 min read

TRELLIS.2: Turn One Image Into a 3D Model (GitHub, Scanned)

Microsoft's open 4B model that turns a single image into a detailed, textured 3D asset.

TRELLIS.2 logo
✅
Scan: safe. Nothing malicious. One thing to know: setup.sh builds two CUDA extensions straight from the lead author's GitHub repositories at whatever their default branch holds, rather than at pinned versions, and runs one sudo apt install. Scanned Jun 5, 2026; the full report is below.

TRELLIS.2 takes one picture of an object and returns a 3D model of it, with full physically based materials: base color, roughness, metallic and opacity, so the result renders realistically and supports transparency. It exports a standard GLB file ready for Blender, a game engine or a web viewer, and renders a turntable video. A separate pipeline paints PBR textures onto a 3D shape you already have.

It is on this list for quality and openness. Its O-Voxel representation handles shapes that older image-to-3D models struggle with, such as open surfaces like clothing and leaves, non-manifold geometry and enclosed internal structures, and it generates at up to 1536 cubed resolution: about 3 seconds at 512 and about a minute at 1536 on an NVIDIA H100. The weights, inference code, a Gradio web demo and the full training code are all released.

TRELLIS.2 is from Microsoft Research, the successor to the original TRELLIS. The repository has about 11,000 stars, and both the code and the TRELLIS.2-4B weights on Hugging Face are MIT-licensed. There are no tagged releases; the commit scanned here, the latest on main, is from June 2026.

Who it is for

Game developers, 3D artists and product designers who need assets fast, and researchers in 3D generation, provided they have a large NVIDIA GPU on Linux.

Getting started

1. Clone the repository with its submodules

git clone -b main https://github.com/microsoft/TRELLIS.2.git --recursive && cd TRELLIS.2

2. Create the trellis2 conda environment and build the dependencies (this takes a while)

. ./setup.sh --new-env --basic --flash-attn --nvdiffrast --nvdiffrec --cumesh --o-voxel --flexgemm

3. Start the web demo, then open the address it prints

python app.py

4. Or run the example script to write sample.glb and a preview video

python example.py

Requirements are steep: Linux (the only tested system), an NVIDIA GPU with at least 24 GB of memory, and the CUDA Toolkit (12.4 recommended) to compile several packages. The 4B model downloads from Hugging Face on first run. Without that hardware, the Hugging Face Spaces demo linked from the README is the easier way to try it.

Safety scan

We cloned microsoft/TRELLIS.2 at commit 75fbf01 on Jun 5, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no pattern hits, no bare-IP URLs and no committed binaries across 271 files and about 26,600 lines (20,000 Python, the rest C++ and CUDA).
  • setup.sh (140 lines) installs PyTorch 2.6.0 from download.pytorch.org, utils3d pinned to a commit and nvdiffrast at tag v0.4.0, but clones CuMesh and FlexGEMM from JeffreyXiang's repositories, and nvdiffrec from a branch, without pinning, so a later push changes what you compile. Its one sudo call is apt install -y libjpeg-dev. o-voxel/setup.py uses a custom build command, the usual way PyTorch CUDA extensions are compiled.
  • There is no lockfile, so no advisory count: dependencies resolve from the script and package metadata at install time. Model weights come from microsoft/TRELLIS.2-4B on Hugging Face.
  • Hosts in the code are GitHub, PyTorch, Microsoft's project page, Blender's download site and a university mirror; no telemetry.
  • One workflow and no third-party actions. Security policy, CodeQL and licence present; no contributing guide or Dependabot. Three contributors, no tagged releases, and the scanned commit is from June 2026.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 setup.py with custom install logic. 2 installer scripts (one can call sudo)
Committed binariesNone.
CI workflows1 workflow. None use pull_request_target. No third-party actions.
Network hosts6 distinct hosts referenced from source; most often github.com, microsoft.github.io, ftp.halifax.rwth-aachen.de, download.pytorch.org. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas security policy, CodeQL, licence file. Missing automated dependency updates, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Installer scripts (2)

By the numbers

Stars11.4K
Forks1,374
Contributors3
Commits11
Open issues128
Open pull requests28
Releases0
Latest releasenone tagged
LicenceMIT
Main languagePython
Project age10 months
Last pushJul 10, 2026
Tracked files271
Lines of code26.6K
Checkout size21 MB

Lines by language: Python 20.1K, C++ 2,170, CUDA 1,353, JSON 1,068, C/C++ header 991, Markdown 696.

Questions

Is TRELLIS.2 free?

Yes. The code and the TRELLIS.2-4B model weights are MIT-licensed, so you can use the generated models commercially. The cost is hardware: it needs an NVIDIA GPU with 24 GB or more, or rented cloud GPU time.

Can TRELLIS.2 run on a Mac or on Windows?

Not officially. The code is tested only on Linux with NVIDIA GPUs and depends on CUDA libraries such as flash-attn and nvdiffrast, so Macs are out and Windows is unsupported. The Hugging Face Spaces demo is the practical option on either.

What file format does TRELLIS.2 produce?

GLB, the binary form of glTF, with PBR textures up to 4096 pixels, which Blender, Unity, Unreal, Three.js and most 3D tools open directly. The GLB is exported in opaque mode; to use the transparency it generated, connect the texture's alpha channel to the material's opacity in your 3D software.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.