{"id":808,"name":"transformers","ecosystem":"pip","repository_url":"https://github.com/huggingface/transformers","issues_count":6007,"created_at":"2025-06-06T15:01:37.702Z","updated_at":"2025-06-06T15:01:37.702Z","purl":"pkg:pypi/transformers","metadata":{"id":2952840,"name":"transformers","ecosystem":"pypi","description":"State-of-the-art Machine Learning for JAX, PyTorch and TensorFlow","homepage":"https://github.com/huggingface/transformers","licenses":"Apache 2.0 License","normalized_licenses":["Apache-1.1"],"repository_url":"https://github.com/huggingface/transformers","keywords_array":["NLP","vision","speech","deep","learning","transformer","pytorch","tensorflow","jax","BERT","GPT-2","Wav2Vec2","ViT"],"namespace":null,"versions_count":184,"first_release_published_at":"2016-08-17T06:13:16.000Z","latest_release_published_at":"2025-05-30T09:17:14.000Z","latest_release_number":"4.52.4","last_synced_at":"2025-06-06T05:01:09.709Z","created_at":"2022-04-10T12:53:29.327Z","updated_at":"2025-06-06T05:01:09.710Z","registry_url":"https://pypi.org/project/transformers/","install_command":"pip install transformers --index-url https://pypi.org/simple","documentation_url":"https://transformers.readthedocs.io/","metadata":{"funding":null,"documentation":null,"classifiers":["Development Status :: 5 - Production/Stable","Intended Audience :: Developers","Intended Audience :: Education","Intended Audience :: Science/Research","License :: OSI Approved :: Apache Software License","Operating System :: OS Independent","Programming Language :: Python :: 3","Programming Language :: Python :: 3.10","Programming Language :: Python :: 3.11","Programming Language :: Python :: 3.12","Programming Language :: Python :: 3.13","Programming Language :: Python :: 3.9","Topic :: Scientific/Engineering :: Artificial Intelligence"],"normalized_name":"transformers"},"repo_metadata":{"id":37241332,"uuid":"155220641","full_name":"huggingface/transformers","owner":"huggingface","description":"🤗 Transformers: State-of-the-art Machine Learning for Pytorch, TensorFlow, and JAX.","archived":false,"fork":false,"pushed_at":"2024-10-29T09:54:04.000Z","size":251176,"stargazers_count":134132,"open_issues_count":1460,"forks_count":26825,"subscribers_count":1124,"default_branch":"main","last_synced_at":"2024-10-29T09:55:08.916Z","etag":null,"topics":["bert","deep-learning","flax","hacktoberfest","jax","language-model","language-models","machine-learning","model-hub","natural-language-processing","nlp","nlp-library","pretrained-models","python","pytorch","pytorch-transformers","seq2seq","speech-recognition","tensorflow","transformer"],"latest_commit_sha":null,"homepage":"https://huggingface.co/transformers","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/huggingface.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-10-29T13:56:00.000Z","updated_at":"2024-10-29T09:49:04.000Z","dependencies_parsed_at":"2024-01-16T19:19:49.973Z","dependency_job_id":"cc91c66a-3299-4bd4-968b-8409891540d8","html_url":"https://github.com/huggingface/transformers","commit_stats":{"total_commits":16380,"total_committers":2809,"mean_commits":5.8312566749733,"dds":0.9381562881562882,"last_synced_commit":"be9cf070ee2cb6a9f0d162e5be32d9d68b9df3af"},"previous_names":["huggingface/pytorch-pretrained-bert","huggingface/pytorch-transformers"],"tags_count":175,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/huggingface","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":222092129,"owners_count":16929792,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"huggingface","name":"Hugging Face","uuid":"25720743","kind":"organization","description":"The AI community building the future.","email":null,"website":"https://huggingface.co/","location":"NYC + Paris","twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/25720743?v=4","repositories_count":123,"last_synced_at":"2023-04-09T14:51:31.532Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/huggingface","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-02T16:28:23.192Z","updated_at":"2023-04-09T14:51:32.411Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/huggingface","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/huggingface/repositories"},"tags":[{"name":"v4.45.0","sha":"2ef31dec1676249d26044a8aa8abe33dbecf0d10","kind":"tag","published_at":"2024-09-25T18:01:41.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.45.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.45.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.45.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.45.0/manifests"},{"name":"v4.44.2","sha":"174890280b340b89c5bfa092f6b4fb0e2dc2d7fc","kind":"tag","published_at":"2024-08-22T16:51:09.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.44.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.44.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.44.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.44.2/manifests"},{"name":"v4.44.1","sha":"ca56cd7b31b2e1691235dd7f273eb3db139498de","kind":"tag","published_at":"2024-08-20T17:45:17.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.44.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.44.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.44.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.44.1/manifests"},{"name":"v4.44.0","sha":"984bc11b0882ff1e5b34ba717ea357e069ceced9","kind":"tag","published_at":"2024-08-06T18:35:34.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.44.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.44.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.44.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.44.0/manifests"},{"name":"v4.43.4","sha":"868d36d29ec132deeaaf8571b25b6a1b911d0145","kind":"tag","published_at":"2024-08-05T10:51:46.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.43.4","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.43.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.4/manifests"},{"name":"v4.43.3","sha":"47c29ccfaf56947d845971a439cbe75a764b63d7","kind":"tag","published_at":"2024-07-26T15:22:41.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.43.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.43.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.3/manifests"},{"name":"v4.43.2","sha":"38d94bffa6bee2e72fb1d1d24cb9ef8e001b88d5","kind":"tag","published_at":"2024-07-24T15:43:05.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.43.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.43.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.2/manifests"},{"name":"v4.43.1","sha":"782bfffb2e4dfb5bbe7940429215d794f4434172","kind":"tag","published_at":"2024-07-23T15:47:10.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.43.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.43.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.1/manifests"},{"name":"v4.43.0","sha":"7fa7508dad2173bddd4818540868411b9bc41680","kind":"tag","published_at":"2024-07-23T15:00:12.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.43.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.43.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.43.0/manifests"},{"name":"v4.42.4","sha":"fc35907f95459d7a6c5281dfadd680b6f7b620e3","kind":"tag","published_at":"2024-07-11T16:56:01.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.42.4","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.42.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.4/manifests"},{"name":"v4.42.3","sha":"b7ee1e80b912c6cdd93b54dd77af061fde151d28","kind":"tag","published_at":"2024-06-28T15:26:33.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.42.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.42.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.3/manifests"},{"name":"v4.42.2","sha":"086c74efdf98b4e64ac40863ce190144316873a5","kind":"tag","published_at":"2024-06-28T06:34:02.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.42.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.42.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.2/manifests"},{"name":"v4.42.1","sha":"e3cb841ca8b8735193ce912e6cf42f413cefa87c","kind":"tag","published_at":"2024-06-27T17:42:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.42.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.42.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.1/manifests"},{"name":"v4.42.0","sha":"6c1d0b069de22d7ed8aa83f733c25045eea0585d","kind":"tag","published_at":"2024-06-27T15:40:39.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.42.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.42.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.42.0/manifests"},{"name":"v4.41.2","sha":"573565e35a5cc68f6cfb6337f5a93753ab16c65b","kind":"tag","published_at":"2024-05-24T09:04:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.41.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.41.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.41.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.41.2/manifests"},{"name":"v4.41.1","sha":"75f15f39a0434fe7a61385c4677f2700542a7ba6","kind":"tag","published_at":"2024-05-22T20:28:14.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.41.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.41.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.41.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.41.1/manifests"},{"name":"v4.41.0","sha":"4c6c45ba138202f42582b5cea98126af87195a95","kind":"tag","published_at":"2024-05-17T15:33:19.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.41.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.41.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.41.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.41.0/manifests"},{"name":"v4.40.2","sha":"4fdf58afb72b0754da30037fc800b6044e7d9c99","kind":"tag","published_at":"2024-05-06T15:43:57.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.40.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.40.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.40.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.40.2/manifests"},{"name":"v4.40.1","sha":"9fe3f585bb4ea29f209dc705d269fbe292e1128f","kind":"tag","published_at":"2024-04-23T21:37:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.40.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.40.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.40.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.40.1/manifests"},{"name":"v4.40.0","sha":"745bbfe4bb2b61491dedd56e1e8ee4af8ef1a9ec","kind":"tag","published_at":"2024-04-18T13:51:49.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.40.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.40.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.40.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.40.0/manifests"},{"name":"v4.39.3","sha":"09f9f566de83eef1f13ee83b5a1bbeebde5c80c1","kind":"tag","published_at":"2024-04-02T09:23:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.39.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.39.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.3/manifests"},{"name":"v4.39.2","sha":"97c00cdfe132164dbd793447a088432fa359fd36","kind":"tag","published_at":"2024-03-28T17:10:13.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.39.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.39.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.2/manifests"},{"name":"v4.39.1","sha":"cbe58b4269457a6ca66a556224b23f9ef246f905","kind":"tag","published_at":"2024-03-22T16:34:23.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.39.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.39.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.1/manifests"},{"name":"v4.39.0","sha":"f4364a6ff16e33186cb40f1d3fafd3792556d1b8","kind":"tag","published_at":"2024-03-21T01:13:37.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.39.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.39.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.39.0/manifests"},{"name":"v4.38.2","sha":"092f1fdaa4224fdd88c616dc9678e6fcb37bfffd","kind":"tag","published_at":"2024-03-01T02:03:27.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.38.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.38.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.38.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.38.2/manifests"},{"name":"v4.38.1","sha":"a0857740c0e6127485c11476650314df3accc2b6","kind":"tag","published_at":"2024-02-22T00:11:17.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.38.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.38.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.38.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.38.1/manifests"},{"name":"v4.38.0","sha":"08ab54ada594f8f4cc1e458b1217bf8c53f04dd8","kind":"tag","published_at":"2024-02-21T13:24:49.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.38.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.38.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.38.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.38.0/manifests"},{"name":"v4.37.2","sha":"345b9b1a6a308a1fa6559251eb33ead2211240ac","kind":"tag","published_at":"2024-01-28T16:28:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.37.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.37.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.37.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.37.2/manifests"},{"name":"list","sha":"345b9b1a6a308a1fa6559251eb33ead2211240ac","kind":"commit","published_at":"2024-01-28T16:19:29.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/list","html_url":"https://github.com/huggingface/transformers/releases/tag/list","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/list","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/list/manifests"},{"name":"v4.37.1","sha":"d02d006cf315cf91e3a470eb72b9a9a7d0ecaf90","kind":"tag","published_at":"2024-01-24T16:01:29.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.37.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.37.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.37.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.37.1/manifests"},{"name":"v4.37.0","sha":"8e3e145b427196e014f37aa42ba890b9bc94275e","kind":"tag","published_at":"2024-01-22T09:41:42.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.37.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.37.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.37.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.37.0/manifests"},{"name":"v4.36.2","sha":"a7cab3c283312b8d4de5df3bbe719971e24f4281","kind":"tag","published_at":"2023-12-18T17:17:39.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.36.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.36.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.36.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.36.2/manifests"},{"name":"v4.36.1","sha":"c48787f347bd604f656c2cfff730e029c8f8c1fe","kind":"tag","published_at":"2023-12-14T06:29:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.36.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.36.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.36.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.36.1/manifests"},{"name":"v4.36.0","sha":"14666775a296a76c88e1aa686a9547f393d322e2","kind":"tag","published_at":"2023-12-11T11:52:44.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.36.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.36.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.36.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.36.0/manifests"},{"name":"v4.35.2","sha":"514de24abfd4416aeba6a6455ad5920f57f3567d","kind":"tag","published_at":"2023-11-15T16:30:15.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.35.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.35.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.35.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.35.2/manifests"},{"name":"v4.35.1","sha":"10f3e7b31bef9b4c7508e328f65e1f7ef186f945","kind":"tag","published_at":"2023-11-14T14:38:13.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.35.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.35.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.35.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.35.1/manifests"},{"name":"v4.35.0","sha":"f1185a4a73a03d238afce1b40456588d22520dd2","kind":"tag","published_at":"2023-11-02T16:43:36.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.35.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.35.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.35.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.35.0/manifests"},{"name":"v4.34.1","sha":"acc394c4f5e1283c19783581790b3dc3105a3697","kind":"tag","published_at":"2023-10-18T15:03:33.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.34.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.34.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.34.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.34.1/manifests"},{"name":"v4.34.0","sha":"b71f20a7c9f3716d30f6738501559acf863e2c5c","kind":"tag","published_at":"2023-10-03T13:49:58.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.34.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.34.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.34.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.34.0/manifests"},{"name":"v4.33.3","sha":"bffac926ca6bc6c965a92bfbfd00c567a2c0fb90","kind":"tag","published_at":"2023-09-26T13:15:36.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.33.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.33.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.3/manifests"},{"name":"v4.33.2","sha":"6da93f5580e109fad5f7b523cf2b6e8a5bafb623","kind":"tag","published_at":"2023-09-15T19:59:32.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.33.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.33.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.2/manifests"},{"name":"v4.33.1","sha":"fa6107c97edf7cf725305a34735a57875b67d85e","kind":"commit","published_at":"2023-09-06T15:45:47.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.33.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.33.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.1/manifests"},{"name":"v4.33.0","sha":"5a4f340df74b42b594aedf60199eea95cdb9bed0","kind":"tag","published_at":"2023-09-04T19:54:19.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.33.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.33.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.33.0/manifests"},{"name":"v4.32.1","sha":"ccb92be23def445f2afdea94c31286f84b89eb5b","kind":"tag","published_at":"2023-08-28T12:34:34.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.32.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.32.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.32.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.32.1/manifests"},{"name":"v4.32.0","sha":"41aef33758ae166291d72bc381477f2db84159cf","kind":"tag","published_at":"2023-08-22T08:02:44.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.32.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.32.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.32.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.32.0/manifests"},{"name":"v4.31.0","sha":"e42587f596181396e1c4b63660abf0c736b10dae","kind":"tag","published_at":"2023-07-18T20:10:03.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.31.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.31.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.31.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.31.0/manifests"},{"name":"v4.30.2","sha":"66fd3a8d626a32989f4569260db32785c6cbf42a","kind":"tag","published_at":"2023-06-13T19:24:35.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.30.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.30.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.30.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.30.2/manifests"},{"name":"v4.30.1","sha":"65a1ec05cae6f3e06257c93685f60581ded44ea1","kind":"tag","published_at":"2023-06-09T15:53:06.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.30.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.30.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.30.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.30.1/manifests"},{"name":"v4.30.0","sha":"fe861e578f50dc9c06de33cd361d2f625017e624","kind":"tag","published_at":"2023-06-08T15:15:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.30.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.30.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.30.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.30.0/manifests"},{"name":"v4.29.2","sha":"ba7054533fa455e8b2dd35feb077e0c7aae646b3","kind":"tag","published_at":"2023-05-16T19:14:27.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.29.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.29.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.29.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.29.2/manifests"},{"name":"v4.29.1","sha":"118e9810687dd713b6be07af79e80eeb1d916908","kind":"tag","published_at":"2023-05-11T20:22:06.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.29.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.29.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.29.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.29.1/manifests"},{"name":"v4.29.0","sha":"15f260a82f98788354d55cb2788e9f0b5131fb77","kind":"tag","published_at":"2023-05-10T16:07:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.29.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.29.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.29.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.29.0/manifests"},{"name":"v4.28.1","sha":"04ab5605fbb4ef207b10bf2772d88c53fc242e83","kind":"tag","published_at":"2023-04-14T16:52:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.28.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.28.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.28.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.28.1/manifests"},{"name":"v4.28.0","sha":"9417c924af539be5f941c8a709a96b60dfe29eb3","kind":"tag","published_at":"2023-04-13T15:25:42.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.28.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.28.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.28.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.28.0/manifests"},{"name":"v4.27.4","sha":"4e9f6fc67ce6290b3ab6efe2ddb1fcfc3e554382","kind":"tag","published_at":"2023-03-29T17:02:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.27.4","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.27.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.4/manifests"},{"name":"v4.27.3","sha":"5e3b19a80512afd63b414745cd93f3acb584f47f","kind":"tag","published_at":"2023-03-23T18:53:27.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.27.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.27.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.3/manifests"},{"name":"v4.27.2","sha":"68287689f2f0d8b7063c400230b3766987abf18d","kind":"tag","published_at":"2023-03-20T16:04:02.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.27.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.27.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.2/manifests"},{"name":"v4.27.1","sha":"2355e463955a5392c1acf1964d89747e8b146a6f","kind":"tag","published_at":"2023-03-15T19:40:23.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.27.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.27.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.1/manifests"},{"name":"v4.27.0","sha":"d941f07a4e3bc7b61b7afbd25d6e2e8427fccc6d","kind":"tag","published_at":"2023-03-15T13:30:02.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.27.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.27.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.27.0/manifests"},{"name":"v4.26.1","sha":"ae54e3c3b18bac0832ad62ea9b896dfd52a09850","kind":"tag","published_at":"2023-02-09T19:23:59.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.26.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.26.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.26.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.26.1/manifests"},{"name":"v4.26.0","sha":"820c46a707ddd033975bc3b0549eea200e64c7da","kind":"tag","published_at":"2023-01-24T17:02:04.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.26.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.26.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.26.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.26.0/manifests"},{"name":"v4.25.1","sha":"31d452c68b34c2567b62924ee0df40a83cbc52d5","kind":"tag","published_at":"2022-12-01T21:14:48.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.25.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.25.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.25.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.25.1/manifests"},{"name":"v4.24.0","sha":"94b3f544a1f5e04b78d87a2ae32a7ac252e22e31","kind":"tag","published_at":"2022-11-01T13:55:19.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.24.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.24.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.24.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.24.0/manifests"},{"name":"v4.23.1","sha":"bd469c40659ce76c81f69c7726759d249b4aef49","kind":"tag","published_at":"2022-10-11T11:54:43.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.23.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.23.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.23.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.23.1/manifests"},{"name":"v4.23.0","sha":"9ae22fe3c1b81f99a764d382054b6ebe2b025bd4","kind":"tag","published_at":"2022-10-10T20:46:36.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.23.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.23.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.23.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.23.0/manifests"},{"name":"v4.22.2","sha":"bc21aaca789f1a366c05e8b5e111632944886393","kind":"tag","published_at":"2022-09-27T14:47:14.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.22.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.22.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.22.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.22.2/manifests"},{"name":"v4.22.1","sha":"2c8b508ccabea6638aa463a137852ff3b64be036","kind":"tag","published_at":"2022-09-16T21:58:51.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.22.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.22.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.22.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.22.1/manifests"},{"name":"v4.22.0","sha":"ad11b79e95acb3c89f994c725594ec52bd181fbf","kind":"tag","published_at":"2022-09-14T18:50:48.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.22.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.22.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.22.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.22.0/manifests"},{"name":"v4.21.3","sha":"983e40ac3b2af68fd6c927dce09324d54d023e54","kind":"tag","published_at":"2022-09-05T10:03:42.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.21.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.21.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.3/manifests"},{"name":"v4.21.2","sha":"b487096b02307cd6e0f132b676cdcc7255fe8e74","kind":"tag","published_at":"2022-08-24T13:54:13.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.21.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.21.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.2/manifests"},{"name":"v4.21.1","sha":"f0d496828d3da3bf1e3c8fbed394d7847e839fa6","kind":"tag","published_at":"2022-08-04T14:01:25.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.21.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.21.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.1/manifests"},{"name":"v4.21.0","sha":"a9eee2ffecc874df7dd635b2c6abb246fdb318cc","kind":"tag","published_at":"2022-07-27T13:09:51.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.21.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.21.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.21.0/manifests"},{"name":"v4.20.1","sha":"d0acc9537829e7d067edbb791473bbceb2ecf056","kind":"tag","published_at":"2022-06-21T19:23:11.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.20.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.20.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.20.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.20.1/manifests"},{"name":"v4.20.0","sha":"39b4aba54d349f35e2f0bd4addbe21847d037e9e","kind":"tag","published_at":"2022-06-16T16:14:06.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.20.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.20.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.20.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.20.0/manifests"},{"name":"v4.19.4","sha":"dcb08b99f44919425f8ba9be9ddcc041af8ec25e","kind":"tag","published_at":"2022-06-10T19:34:14.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.19.4","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.19.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.4/manifests"},{"name":"v4.19.3","sha":"a727db62f4f4e5cb15020fa5efa86ae559324616","kind":"tag","published_at":"2022-06-09T16:53:16.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.19.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.19.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.3/manifests"},{"name":"v4.19.2","sha":"6e535425feae20ca61a8b10ae5e8a7fab4d394ba","kind":"tag","published_at":"2022-05-16T18:23:53.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.19.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.19.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.2/manifests"},{"name":"v4.19.1","sha":"a1651b518e92d0b9d89478072ab54c8a39f09720","kind":"tag","published_at":"2022-05-13T18:15:59.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.19.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.19.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.1/manifests"},{"name":"v4.19.0","sha":"a22db885b41b3a1b302fc206312ee4d99cdf4b7c","kind":"tag","published_at":"2022-05-12T14:51:04.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.19.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.19.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.19.0/manifests"},{"name":"v4.18.0","sha":"31ec2cb2badfbdd4c1ac9c6c9b8a74e974984206","kind":"tag","published_at":"2022-04-06T15:02:20.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.18.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.18.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.18.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.18.0/manifests"},{"name":"v4.17.0","sha":"198c335d219a5eb4d3f124fdd1ce1a9cd9f78a9b","kind":"tag","published_at":"2022-03-03T15:06:27.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.17.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.17.0/manifests"},{"name":"v4.16.2","sha":"db7d6a80e82d66127b2a44b6e3382969fdc8b207","kind":"tag","published_at":"2022-01-31T16:41:09.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.16.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.16.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.16.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.16.2/manifests"},{"name":"v4.16.1","sha":"c4ad38e5ac69e6d96116f39df789a2369dd33c21","kind":"tag","published_at":"2022-01-28T17:20:09.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.16.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.16.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.16.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.16.1/manifests"},{"name":"v4.16.0","sha":"f87db5e412f561c089e70ab2b15bfa070c2b07f5","kind":"tag","published_at":"2022-01-27T18:06:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.16.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.16.0/manifests"},{"name":"v4.15.0","sha":"05fa1a7ac17bb7aa07b9e0c1e138ecb31a28bbfe","kind":"tag","published_at":"2021-12-22T19:01:36.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.15.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.15.0/manifests"},{"name":"v4.14.1","sha":"19e5ed736611227b004c6f55679ce3536db3c28d","kind":"tag","published_at":"2021-12-15T18:54:52.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.14.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.14.1/manifests"},{"name":"v4.14.0","sha":"960d8cb41d245b04e4c62279a17b065f1796ec92","kind":"tag","published_at":"2021-12-15T17:20:51.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.14.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.14.0/manifests"},{"name":"v4.13.0","sha":"4da3a696e4f208e59bd1fe6bf2e255b48a066597","kind":"tag","published_at":"2021-12-09T15:57:38.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.13.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.13.0/manifests"},{"name":"v4.12.5","sha":"ef3cec0ca577e5950e42e8de1a2991b5dc85dfa6","kind":"tag","published_at":"2021-11-17T16:36:19.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.12.5","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.12.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.5/manifests"},{"name":"v4.12.4","sha":"527c763ff6715c55dd2549d24a00faab095c67ee","kind":"tag","published_at":"2021-11-16T22:25:59.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.12.4","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.12.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.4/manifests"},{"name":"v4.12.3","sha":"3ea15d27832d47d44ad046c3a776c7b582b0984b","kind":"tag","published_at":"2021-11-03T12:57:53.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.12.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.12.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.3/manifests"},{"name":"v4.12.2","sha":"219137337f15c17cac2be37d9d5256c0613c5935","kind":"tag","published_at":"2021-10-29T18:48:15.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.12.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.12.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.2/manifests"},{"name":"v4.12.1","sha":"e0a515407518657e021b7f4547be83333b520932","kind":"tag","published_at":"2021-10-29T17:46:03.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.12.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.12.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.1/manifests"},{"name":"v4.12.0","sha":"62bf536631d22e28aaac4d19c4d0d901ebf015ad","kind":"tag","published_at":"2021-10-28T16:10:14.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.12.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.12.0/manifests"},{"name":"v4.11.3","sha":"65659a29cf5a079842e61a63d57fa24474288998","kind":"tag","published_at":"2021-10-06T16:48:36.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.11.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.11.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.3/manifests"},{"name":"v4.11.2","sha":"7655f11076cf953618848d8403dd167fd71d33b5","kind":"tag","published_at":"2021-09-30T15:55:05.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.11.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.11.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.2/manifests"},{"name":"v4.11.1","sha":"54f9d62c61f005c8dd06602207ed156ec482fef0","kind":"tag","published_at":"2021-09-29T16:05:08.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.11.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.11.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.1/manifests"},{"name":"v4.11.0","sha":"dc193c906dfb3b9663f8963735c46e030a15b914","kind":"tag","published_at":"2021-09-27T18:16:51.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.11.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.11.0/manifests"},{"name":"v4.10.3","sha":"7a0b9187f692392d74e453c014ee24ccc6ca58fb","kind":"tag","published_at":"2021-09-22T19:56:41.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.10.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.10.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.3/manifests"},{"name":"v4.10.2","sha":"a5fc34437dc2cfbd9e91f732820304c017b5525d","kind":"tag","published_at":"2021-09-10T16:21:33.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.10.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.2/manifests"},{"name":"v4.10.1","sha":"28e278728d48d9b7de163fc5e504e497fd209ac9","kind":"tag","published_at":"2021-09-10T14:20:42.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.10.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.1/manifests"},{"name":"v4.10.0","sha":"d12bbe494210ad2abbbcba0ce4734214fc7db758","kind":"commit","published_at":"2021-08-31T13:53:10.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.10.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.10.0/manifests"},{"name":"v4.9.2","sha":"41981a25cdd028007a7491d68935c8d93f9e8b47","kind":"tag","published_at":"2021-08-09T14:01:47.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.9.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.9.2/manifests"},{"name":"v4.9.1","sha":"bff1c71e84e392af9625c345f9ea71f7b6d75fb3","kind":"tag","published_at":"2021-07-26T14:22:17.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.9.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.9.1/manifests"},{"name":"v4.9.0","sha":"72aee83ced5f31302c5e331d896412737287f976","kind":"tag","published_at":"2021-07-22T10:12:14.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.9.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.9.0/manifests"},{"name":"v4.8.2","sha":"96d1cfb13db094d1468883060ec2d4471f63fd01","kind":"tag","published_at":"2021-06-30T12:27:44.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.8.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.8.2/manifests"},{"name":"v4.8.1","sha":"136617224b8fcde279410d8f09db98c67d1761bd","kind":"tag","published_at":"2021-06-24T14:12:35.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.8.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.8.1/manifests"},{"name":"v4.8.0","sha":"468cda20f2695336a0c0f73f5f93a26af0df414b","kind":"tag","published_at":"2021-06-23T17:25:15.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.8.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.8.0/manifests"},{"name":"v4.7.0","sha":"7a6c9fab8e2f740f013d89b99e635a9037f91d5d","kind":"tag","published_at":"2021-06-17T16:06:41.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.7.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.7.0/manifests"},{"name":"v4.6.1","sha":"fb27b276e7babc2249abbf79e6efb23b9611da10","kind":"tag","published_at":"2021-05-20T14:46:51.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.6.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.6.1/manifests"},{"name":"v4.6.0","sha":"64e78564a519cda2b4408803e2781c604e1e3bdd","kind":"tag","published_at":"2021-05-12T15:03:39.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.6.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.6.0/manifests"},{"name":"localattn1","sha":"8aa32719b2ec45ec02daa230ec3692cee0543db2","kind":"commit","published_at":"2021-04-23T20:46:21.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/localattn1","html_url":"https://github.com/huggingface/transformers/releases/tag/localattn1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/localattn1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/localattn1/manifests"},{"name":"v4.5.1","sha":"4bae96ec2bee265f938fc262201538819419089a","kind":"tag","published_at":"2021-04-13T15:18:35.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.5.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.5.1/manifests"},{"name":"v4.5.0","sha":"4906a29f7f3e6039ebfa6a9895e2b5b628eb6e6b","kind":"tag","published_at":"2021-04-06T16:38:03.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.5.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.5.0/manifests"},{"name":"v4.4.2","sha":"9f43a425fe89cfc0e9b9aa7abd7dd44bcaccd79a","kind":"tag","published_at":"2021-03-18T19:09:21.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.4.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.4.2/manifests"},{"name":"v4.4.1","sha":"f213d239417810c7dfca86593d16da129b761175","kind":"tag","published_at":"2021-03-16T19:58:59.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.4.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.4.1/manifests"},{"name":"v4.4.0","sha":"c988db5af2a5f1ccfcb5ad19bd735b6a77516637","kind":"tag","published_at":"2021-03-16T15:33:48.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.4.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.4.0/manifests"},{"name":"v4.3.3","sha":"bae0c79f6fab7b1156dbb769c5493d1b393d7fa6","kind":"tag","published_at":"2021-02-24T20:03:08.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.3.3","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.3/manifests"},{"name":"v4.3.2","sha":"cd48078ce59a195473729759c76d88ae612b0f7a","kind":"tag","published_at":"2021-02-09T19:08:29.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.3.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.2/manifests"},{"name":"v4.3.1","sha":"cc86472c78348e4ac7ee406b32375f2d2e1d1c66","kind":"commit","published_at":"2021-02-09T08:55:55.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.3.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.1/manifests"},{"name":"v4.3.0","sha":"800f385d7808262946987ce91c158186649ec954","kind":"tag","published_at":"2021-02-08T17:32:08.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.3.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.0/manifests"},{"name":"4.3.0.rc1","sha":"4cd22512deb036b37046bbbbc294e6d4c6b4b265","kind":"tag","published_at":"2021-02-04T20:41:47.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/4.3.0.rc1","html_url":"https://github.com/huggingface/transformers/releases/tag/4.3.0.rc1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/4.3.0.rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/4.3.0.rc1/manifests"},{"name":"v4.3.0.rc1","sha":"4cd22512deb036b37046bbbbc294e6d4c6b4b265","kind":"commit","published_at":"2021-02-04T20:41:19.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.3.0.rc1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.3.0.rc1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.0.rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.3.0.rc1/manifests"},{"name":"v4.2.2","sha":"98af96a156ff902ade48e778360658ad5b705641","kind":"tag","published_at":"2021-01-21T08:06:58.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.2.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.2.2/manifests"},{"name":"v4.2.1","sha":"236cc365aff2512ef773c6b1786555dab6fb182f","kind":"tag","published_at":"2021-01-14T13:18:18.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.2.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.2.1/manifests"},{"name":"v4.2.0","sha":"7d9a9d0c722a28cceeef7bfe117e5c9e44b82b18","kind":"tag","published_at":"2021-01-13T15:02:13.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.2.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.2.0/manifests"},{"name":"v4.1.1","sha":"bfa4ccf77d65d8899b01417bd9845b2e78bc0ec5","kind":"tag","published_at":"2020-12-17T16:26:00.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.1.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.1.1/manifests"},{"name":"v4.1.0","sha":"f5438ab8a220bb5d72cbbb6a50736daffc1ecc85","kind":"tag","published_at":"2020-12-17T15:05:24.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.1.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.1.0/manifests"},{"name":"v4.0.1","sha":"e20ac6611df97f66148ce8b7886f01ffe9d17484","kind":"tag","published_at":"2020-12-09T16:23:56.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.0.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.0.1/manifests"},{"name":"v4.0.0","sha":"c781171dfa187829e2a5ce33f805ac8bd561184f","kind":"tag","published_at":"2020-11-30T16:34:02.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.0.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.0.0/manifests"},{"name":"v4.0.0-rc-1","sha":"d86b5ffc6fb76e144d1cd4824e4937b83a09c52e","kind":"tag","published_at":"2020-11-19T17:00:32.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v4.0.0-rc-1","html_url":"https://github.com/huggingface/transformers/releases/tag/v4.0.0-rc-1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.0.0-rc-1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v4.0.0-rc-1/manifests"},{"name":"v3.5.1","sha":"d5b3e56de5376aa85ef46e7f0325139d9e299a41","kind":"tag","published_at":"2020-11-13T15:03:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.5.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.5.1/manifests"},{"name":"v3.5.0","sha":"818878dc881a32c949844f734af5a8ce25385660","kind":"tag","published_at":"2020-11-10T13:51:19.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.5.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.5.0/manifests"},{"name":"v3.4.0","sha":"eb0e0ce2adf66d2b1106b9e0852f6e063ab9ae7c","kind":"tag","published_at":"2020-10-20T14:23:24.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.4.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.4.0/manifests"},{"name":"v3.3.1","sha":"1ba08dc221ff101a751c16462c3a256d726e7c85","kind":"tag","published_at":"2020-09-29T18:18:15.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.3.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.3.1/manifests"},{"name":"v3.3.0","sha":"0613f052264f3ceb9c83ba19d59c18a818ff4dd9","kind":"tag","published_at":"2020-09-28T14:27:10.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.3.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.3.0/manifests"},{"name":"v3.2.0","sha":"3ebb1b3a2b7b7674ad179ef2c3cdeb9fbfeb023d","kind":"tag","published_at":"2020-09-22T15:38:26.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.2.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.2.0/manifests"},{"name":"v3.1.0","sha":"4b3ee9cbc53c6cf6cee6bfae86cc2c6ec0778ee5","kind":"tag","published_at":"2020-09-01T12:28:37.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.1.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.1.0/manifests"},{"name":"v3.0.2","sha":"b0892fa0e8df02d683e05e625b3903209bff362d","kind":"tag","published_at":"2020-07-06T22:50:18.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.0.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.0.2/manifests"},{"name":"v3.0.1","sha":"fedabcd1545839798004b2b468f191ec2244442f","kind":"tag","published_at":"2020-07-03T15:13:20.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.0.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.0.1/manifests"},{"name":"3.0.1","sha":"fedabcd1545839798004b2b468f191ec2244442f","kind":"tag","published_at":"2020-07-03T15:03:25.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/3.0.1","html_url":"https://github.com/huggingface/transformers/releases/tag/3.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/3.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/3.0.1/manifests"},{"name":"v3.0.0","sha":"b62ca59527de4e883fb8e91f02e97586115616b1","kind":"tag","published_at":"2020-06-29T14:41:04.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v3.0.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v3.0.0/manifests"},{"name":"v2.11.0","sha":"b42586ea560a20dcadb78472a6b4596f579e9043","kind":"tag","published_at":"2020-06-02T14:24:06.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.11.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.11.0/manifests"},{"name":"v2.10.0","sha":"10d72390c029b3f139639621fb9a3a264560e05b","kind":"tag","published_at":"2020-05-22T14:50:47.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.10.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.10.0/manifests"},{"name":"v2.9.1","sha":"7cb203fae4e7964e9e99400b375d660ebce765ee","kind":"tag","published_at":"2020-05-13T21:39:09.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.9.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.9.1/manifests"},{"name":"v2.9.0","sha":"e7cfc1a313cc928e962bb8699868f5dcf46f11eb","kind":"tag","published_at":"2020-05-07T18:15:39.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.9.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.9.0/manifests"},{"name":"v2.8.0","sha":"11c3257a18c4b5e1a3c1746eefd96f180358397b","kind":"tag","published_at":"2020-04-06T14:06:55.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.8.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.8.0/manifests"},{"name":"v2.7.0","sha":"6f5a12a5833d1e3783e4b8a42cb556b64085745e","kind":"tag","published_at":"2020-03-30T12:50:10.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.7.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.7.0/manifests"},{"name":"v2.6.0","sha":"fbc5bf10cfe4d4ca81f8daacc148b0abd51dda5a","kind":"tag","published_at":"2020-03-24T15:52:17.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.6.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.6.0/manifests"},{"name":"v2.5.1","sha":"b90745c5901809faef3136ed09a689e7d733526c","kind":"tag","published_at":"2020-02-24T23:47:05.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.5.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.5.1/manifests"},{"name":"v2.5.0","sha":"fb560dcb075497f61880010245192e7e1fdbeca4","kind":"tag","published_at":"2020-02-19T16:46:54.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.5.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.5.0/manifests"},{"name":"v2.4.1","sha":"d426b58b9e32a2ffc8c8a1196143270e22054a46","kind":"tag","published_at":"2020-01-31T19:56:41.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.4.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.4.1/manifests"},{"name":"v2.4.0","sha":"6664ea943d75e7ab2cc78e7d97bdf38d7a00acb4","kind":"tag","published_at":"2020-01-31T14:41:02.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.4.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.4.0/manifests"},{"name":"v2.3.0","sha":"a436574bfde4f75f518a107f45f987579d813ce5","kind":"tag","published_at":"2019-12-20T21:22:50.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.3.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.3.0/manifests"},{"name":"v2.2.2","sha":"7bd11dda6f43656cf0a3891b7f61a67196d233b4","kind":"tag","published_at":"2019-12-13T21:45:44.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.2.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.2.2/manifests"},{"name":"v2.2.1","sha":"8101924a6812ffb09c54c2af85d2182f9a81db20","kind":"tag","published_at":"2019-12-03T16:20:38.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.2.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.2.1/manifests"},{"name":"v2.2.0","sha":"ae98d4599179b299563b679dd33f8a86da12980d","kind":"tag","published_at":"2019-11-26T19:13:11.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.2.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.2.0/manifests"},{"name":"v2.1.1","sha":"3ddce1d74cda5be47704381e657ee22ce5a5fc7b","kind":"tag","published_at":"2019-10-11T10:38:32.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.1.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"9c2e0a4acfb0d6e5d448373fa3ce53a4ce3478ec","kind":"tag","published_at":"2019-10-09T16:14:38.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.1.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.1.0/manifests"},{"name":"v2.0.0","sha":"1d646badbb118cf126a1250b22b246572e07ac4c","kind":"commit","published_at":"2019-09-26T11:48:00.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v2.0.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v2.0.0/manifests"},{"name":"1.2.0","sha":"89fd3450a61b5efd76d2524df2454e0a0e4ca070","kind":"tag","published_at":"2019-09-04T11:33:15.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/1.2.0","html_url":"https://github.com/huggingface/transformers/releases/tag/1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/1.2.0/manifests"},{"name":"1.1.0","sha":"fe02e45e488a4f067605cf9768171358de9726d3","kind":"commit","published_at":"2019-08-15T15:15:08.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/1.1.0","html_url":"https://github.com/huggingface/transformers/releases/tag/1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/1.1.0/manifests"},{"name":"v1.0.0","sha":"b33a385091de604afb566155ec03329b84c96926","kind":"commit","published_at":"2019-07-16T14:18:37.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v1.0.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v1.0.0/manifests"},{"name":"1.0","sha":"ed7549bb1af73a90d70d302806cd343805471a58","kind":"tag","published_at":"2019-07-16T14:11:45.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/1.0","html_url":"https://github.com/huggingface/transformers/releases/tag/1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/1.0/manifests"},{"name":"v0.6.2","sha":"b832d5bb8a6dfc5965015b828e577677eace601e","kind":"commit","published_at":"2019-04-25T19:37:47.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.6.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"8f46cd105752c1f1218a2716ea423454273ff08b","kind":"commit","published_at":"2019-02-18T11:00:11.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.6.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"0856a231c0d6f3abb193e99ecf52ff76edb75fb8","kind":"commit","published_at":"2019-02-18T10:38:05.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.6.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.6.0/manifests"},{"name":"v0.5.1","sha":"4e56da38d9dacf9a480aaabfee4e3b8cf28e3735","kind":"commit","published_at":"2019-02-13T09:19:25.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.5.1","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.5.1/manifests"},{"name":"0.5.0","sha":"03cdb2a390f8bd18b0abb423dfb95556e5dabaef","kind":"tag","published_at":"2019-02-11T13:20:14.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/0.5.0","html_url":"https://github.com/huggingface/transformers/releases/tag/0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/0.5.0/manifests"},{"name":"v0.5.0","sha":"03cdb2a390f8bd18b0abb423dfb95556e5dabaef","kind":"commit","published_at":"2019-02-11T13:19:26.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.5.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.5.0/manifests"},{"name":"v0.4.0","sha":"e1bfad48464a716fc65eac1f89a9f4c4915fd6db","kind":"commit","published_at":"2018-12-14T14:15:47.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.4.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.4.0/manifests"},{"name":"v0.3.0","sha":"66d50ca6aed937b54e8c25c2794e7014bb3453d0","kind":"commit","published_at":"2018-11-30T22:10:30.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.3.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.3.0/manifests"},{"name":"v0.1.2","sha":"ce37b8e4819142171b61558e64f7dcb0286e9937","kind":"commit","published_at":"2018-11-26T09:45:48.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.1.2","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.1.2/manifests"},{"name":"v0.2.0","sha":"ce37b8e4819142171b61558e64f7dcb0286e9937","kind":"commit","published_at":"2018-11-26T09:45:48.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/v0.2.0","html_url":"https://github.com/huggingface/transformers/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/v0.2.0/manifests"},{"name":"0.1.2","sha":"4132a028af982e2ea41144835eef2118335144a7","kind":"commit","published_at":"2018-11-17T11:21:48.000Z","download_url":"https://codeload.github.com/huggingface/transformers/tar.gz/0.1.2","html_url":"https://github.com/huggingface/transformers/releases/tag/0.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/0.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/huggingface%2Ftransformers/tags/0.1.2/manifests"}]},"repo_metadata_updated_at":"2024-10-29T20:20:24.477Z","dependent_packages_count":2589,"downloads":60739582,"downloads_period":"last-month","dependent_repos_count":31800,"rankings":{"downloads":0.05080639096710057,"dependent_repos_count":0.038700897090462885,"dependent_packages_count":0.013756243041633729,"stargazers_count":0.011371827581083882,"forks_count":0.020359239701617918,"docker_downloads_count":0.5830812883913816,"average":0.11967931446221343},"purl":"pkg:pypi/transformers","advisories":[{"uuid":"GSA_kwCzR0hTQS13cmZjLXB2cDktbXI5Z84ABBsM","url":"https://github.com/advisories/GHSA-wrfc-pvp9-mr9g","title":"Deserialization of Untrusted Data in Hugging Face Transformers","description":"Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25191.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-23T03:31:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2024-11393","https://www.zerodayinitiative.com/advisories/ZDI-24-1514","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2024-228.yaml","https://github.com/huggingface/transformers/issues/34840","https://github.com/huggingface/transformers/pull/35296","https://github.com/advisories/GHSA-wrfc-pvp9-mr9g"],"source_kind":"github","identifiers":["GHSA-wrfc-pvp9-mr9g","CVE-2024-11393"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.48.0","vulnerable_version_range":"\u003e= 0, \u003c 4.48.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2025-02-11T16:07:55.442Z","updated_at":"2025-02-13T22:16:47.000Z","epss_percentage":0.36014,"epss_percentile":0.96836},{"uuid":"GSA_kwCzR0hTQS1xcTNqLTRmNGYtOTU4M84ABIEt","url":"https://github.com/advisories/GHSA-qq3j-4f4f-9583","title":"Hugging Face Transformers Regular Expression Denial of Service","description":"A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-05-19T12:30:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2025-2099","https://github.com/huggingface/transformers/commit/8cb522b4190bd556ce51be04942720650b1a3e57","https://huntr.com/bounties/97b780f3-ffca-424f-ad5d-0e1c57a5bde4","https://github.com/huggingface/transformers/pull/36648","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2025-40.yaml","https://github.com/advisories/GHSA-qq3j-4f4f-9583"],"source_kind":"github","identifiers":["GHSA-qq3j-4f4f-9583","CVE-2025-2099"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.50.0","vulnerable_version_range":"\u003c 4.50.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2025-05-19T22:07:59.207Z","updated_at":"2025-05-22T17:42:19.000Z","epss_percentage":0.00049,"epss_percentile":0.15343},{"uuid":"GSA_kwCzR0hTQS0yODJ2LTY2NmMtM2Z2Z84AAzZV","url":"https://github.com/advisories/GHSA-282v-666c-3fvg","title":"transformers has Insecure Temporary File","description":"Insecure Temporary File in GitHub repository huggingface/transformers 4.29.2 and prior. A fix is available at commit 80ca92470938bbcc348e2d9cf4734c7c25cb1c43 and has been released as part of version 4.30.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-05-18T18:30:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2023-2800","https://github.com/huggingface/transformers/commit/80ca92470938bbcc348e2d9cf4734c7c25cb1c43","https://huntr.dev/bounties/a3867b4e-6701-4418-8c20-3c6e7084a44a","https://github.com/huggingface/transformers/pull/23372","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2023-299.yaml","https://github.com/advisories/GHSA-282v-666c-3fvg"],"source_kind":"github","identifiers":["GHSA-282v-666c-3fvg","CVE-2023-2800"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.30.0","vulnerable_version_range":"\u003c 4.30.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2023-05-19T14:03:36.063Z","updated_at":"2024-11-22T20:34:49.000Z","epss_percentage":0.00015,"epss_percentile":0.01943},{"uuid":"GSA_kwCzR0hTQS1xeHJwLXZodm0tajc2Nc4ABBsZ","url":"https://github.com/advisories/GHSA-qxrp-vhvm-j765","title":"Deserialization of Untrusted Data in Hugging Face Transformers","description":"Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-24322.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-23T03:31:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2024-11392","https://www.zerodayinitiative.com/advisories/ZDI-24-1513","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2024-227.yaml","https://github.com/huggingface/transformers/issues/34840","https://github.com/huggingface/transformers/pull/35296","https://github.com/advisories/GHSA-qxrp-vhvm-j765"],"source_kind":"github","identifiers":["GHSA-qxrp-vhvm-j765","CVE-2024-11392"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.48.0","vulnerable_version_range":"\u003e= 0, \u003c 4.48.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2025-02-11T16:07:55.700Z","updated_at":"2025-02-13T22:15:59.000Z","epss_percentage":0.33774,"epss_percentile":0.96653},{"uuid":"GSA_kwCzR0hTQS1oeHhmLTIzNW0tNzJ2M84ABBsL","url":"https://github.com/advisories/GHSA-hxxf-235m-72v3","title":"Deserialization of Untrusted Data in Hugging Face Transformers","description":"Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25012.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-23T03:31:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2024-11394","https://www.zerodayinitiative.com/advisories/ZDI-24-1515","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2024-229.yaml","https://github.com/huggingface/transformers/issues/34840","https://github.com/huggingface/transformers/pull/35296","https://github.com/advisories/GHSA-hxxf-235m-72v3"],"source_kind":"github","identifiers":["GHSA-hxxf-235m-72v3","CVE-2024-11394"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.48.0","vulnerable_version_range":"\u003e= 0, \u003c 4.48.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2025-02-11T16:07:55.619Z","updated_at":"2025-02-13T22:13:52.000Z","epss_percentage":0.07191,"epss_percentile":0.91135},{"uuid":"GSA_kwCzR0hTQS0zODYzLTI0NDctNjY5cM4AA35m","url":"https://github.com/advisories/GHSA-3863-2447-669p","title":"transformers has a Deserialization of Untrusted Data vulnerability","description":"Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.0.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2023-12-19T15:30:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2023-6730","https://github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532ce","https://huntr.com/bounties/423611ee-7a2a-442a-babb-3ed2f8385c16","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2023-300.yaml","https://github.com/advisories/GHSA-3863-2447-669p"],"source_kind":"github","identifiers":["GHSA-3863-2447-669p","CVE-2023-6730"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.36.0","vulnerable_version_range":"\u003c 4.36.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2023-12-28T06:05:33.846Z","updated_at":"2024-11-22T20:44:49.000Z","epss_percentage":0.00161,"epss_percentile":0.38098},{"uuid":"GSA_kwCzR0hTQS12NjhnLXdtOGMtNng3as4AA38Z","url":"https://github.com/advisories/GHSA-v68g-wm8c-6x7j","title":"transformers has a Deserialization of Untrusted Data vulnerability","description":"Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-12-20T18:30:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2023-7018","https://github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532ce","https://huntr.com/bounties/e1a3e548-e53a-48df-b708-9ee62140963c","https://github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2023-301.yaml","https://github.com/advisories/GHSA-v68g-wm8c-6x7j"],"source_kind":"github","identifiers":["GHSA-v68g-wm8c-6x7j","CVE-2023-7018"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.36.0","vulnerable_version_range":"\u003c 4.36.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2023-12-20T21:05:55.348Z","updated_at":"2024-11-22T20:45:14.000Z","epss_percentage":0.00141,"epss_percentile":0.35477},{"uuid":"GSA_kwCzR0hTQS02cnZnLTZ2Mm0tNGo0Ns4ABFth","url":"https://github.com/advisories/GHSA-6rvg-6v2m-4j46","title":"Transformers Regular Expression Denial of Service (ReDoS) vulnerability","description":"A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. The issue stems from the regex exhibiting exponential time complexity under certain conditions, leading to excessive backtracking. This can result in significantly high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.46.3.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-03-20T12:32:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2024-12720","https://github.com/huggingface/transformers/commit/deac971c469bcbb182c2e52da0b82fb3bf54cccf","https://huntr.com/bounties/4bed1214-7835-4252-a853-22bbad891f98","https://github.com/advisories/GHSA-6rvg-6v2m-4j46"],"source_kind":"github","identifiers":["GHSA-6rvg-6v2m-4j46","CVE-2024-12720"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.48.0","vulnerable_version_range":"\u003c 4.48.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2025-03-21T18:08:05.520Z","updated_at":"2025-05-28T01:08:46.998Z","epss_percentage":0.00058,"epss_percentile":0.18304},{"uuid":"GSA_kwCzR0hTQS0zN3E1LXY1cW0tYzl2OM4AA649","url":"https://github.com/advisories/GHSA-37q5-v5qm-c9v8","title":"Transformers Deserialization of Untrusted Data vulnerability","description":"The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-04-10T18:30:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2024-3568","https://github.com/huggingface/transformers/commit/693667b8ac8138b83f8adb6522ddaf42fa07c125","https://huntr.com/bounties/b3c36992-5264-4d7f-9906-a996efafba8f","https://github.com/advisories/GHSA-37q5-v5qm-c9v8"],"source_kind":"github","identifiers":["GHSA-37q5-v5qm-c9v8","CVE-2024-3568"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.38.0","vulnerable_version_range":"\u003c 4.38.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2024-04-10T23:04:49.738Z","updated_at":"2024-04-10T22:20:57.000Z","epss_percentage":0.08957,"epss_percentile":0.92128},{"uuid":"GSA_kwCzR0hTQS1mcHdyLTY3cHgtM3FoeM4ABHQB","url":"https://github.com/advisories/GHSA-fpwr-67px-3qhx","title":"Transformers Regular Expression Denial of Service (ReDoS) vulnerability","description":"A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions process specially crafted inputs. The issue stems from a regex exhibiting exponential complexity under certain conditions, leading to excessive backtracking. This can result in high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.48.1 (latest).","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-04-29T12:30:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2025-1194","https://github.com/huggingface/transformers/commit/92c5ca9dd70de3ade2af2eb835c96215cc50e815","https://huntr.com/bounties/86f58dcd-683f-4adc-a735-849f51e9abb2","https://github.com/advisories/GHSA-fpwr-67px-3qhx"],"source_kind":"github","identifiers":["GHSA-fpwr-67px-3qhx","CVE-2025-1194"],"repository_url":"https://github.com/huggingface/transformers","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"4.50.0","vulnerable_version_range":"\u003c 4.50.0"}],"ecosystem":"pypi","package_name":"transformers"}],"created_at":"2025-04-29T16:08:54.471Z","updated_at":"2025-04-29T15:17:04.000Z","epss_percentage":0.00052,"epss_percentile":0.16294}],"docker_usage_url":"https://docker.ecosyste.ms/usage/pypi/transformers","docker_dependents_count":2711,"docker_downloads_count":44558964,"usage_url":"https://repos.ecosyste.ms/usage/pypi/transformers","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/pypi/transformers/dependencies","status":null,"funding_links":[],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/transformers/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/transformers/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/transformers/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/transformers/related_packages","maintainers":[{"uuid":"lysandre","login":"lysandre","name":null,"email":null,"url":null,"packages_count":10,"html_url":"https://pypi.org/user/lysandre/","role":null,"created_at":"2023-01-17T05:56:23.536Z","updated_at":"2023-01-17T05:56:23.536Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/lysandre/packages"},{"uuid":"Thomwolf","login":"Thomwolf","name":null,"email":null,"url":null,"packages_count":16,"html_url":"https://pypi.org/user/Thomwolf/","role":null,"created_at":"2023-01-17T05:56:23.549Z","updated_at":"2023-01-17T05:56:23.549Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/Thomwolf/packages"},{"uuid":"ArthurZucker","login":"ArthurZucker","name":null,"email":null,"url":null,"packages_count":2,"html_url":"https://pypi.org/user/ArthurZucker/","role":"Owner","created_at":"2023-09-18T12:26:36.139Z","updated_at":"2023-09-18T12:26:36.139Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/ArthurZucker/packages"},{"uuid":"amysartran","login":"amysartran","name":null,"email":null,"url":null,"packages_count":1,"html_url":"https://pypi.org/user/amysartran/","role":null,"created_at":"2023-12-18T19:06:20.906Z","updated_at":"2023-12-18T19:06:20.906Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/amysartran/packages"}],"registry":{"name":"pypi.org","url":"https://pypi.org","ecosystem":"pypi","default":true,"packages_count":690322,"maintainers_count":292759,"namespaces_count":0,"keywords_count":228590,"github":"pypi","metadata":{"funded_packages_count":48950},"icon_url":"https://github.com/pypi.png","created_at":"2022-04-04T15:19:23.364Z","updated_at":"2025-06-06T05:32:09.692Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/namespaces"}},"unique_repositories_count":2536,"unique_repositories_count_past_30_days":146,"recent_issues":[{"uuid":"5606816122","node_id":"PR_kwDOTdD-cs8AAAABFZcwdA","number":19,"state":"open","title":"Bump the minor-update group across 1 directory with 169 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-27T22:25:11.000Z","updated_at":"2026-09-27T22:25:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":169,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.5.3","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.128.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"mistral-common","old_version":"1.11.2","new_version":"1.12.0","repository_url":"https://github.com/mistralai/mistral-common"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.6.2.post1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"arrow","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/arrow-py/arrow"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.3","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.102","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.102","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.1.7","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.3","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.2","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.83.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastsafetensors","old_version":"0.2.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.9.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"harfile","old_version":"0.3.0","new_version":"0.5.0","repository_url":"https://github.com/schemathesis/harfile"},{"name":"hf-xet","old_version":"1.4.3","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.2","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.1","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"hypothesis-graphql","old_version":"0.11.1","new_version":"0.13.2","repository_url":"https://github.com/Stranger6667/hypothesis-graphql"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.5","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonpointer","old_version":"3.0.0","new_version":"3.1.1","repository_url":"https://github.com/stefankoegl/python-json-pointer"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.6","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.3","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.8","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.1","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.0.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.19.0.56","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.0","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.28.9","new_version":"2.32.3"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.8.0"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.18.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.4.0","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.12","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.15.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-subtests","old_version":"0.14.1","new_version":"0.15.0","repository_url":"https://github.com/pytest-dev/pytest-subtests"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"safetensors","old_version":"0.4.5","new_version":"0.8.0","repository_url":"https://github.com/huggingface/safetensors"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tomli","old_version":"2.2.1","new_version":"2.4.1","repository_url":"https://github.com/hukkin/tomli"},{"name":"triton","old_version":"3.6.0","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.15.2","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.6","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.9.1","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"zstandard","old_version":"0.23.0","new_version":"0.25.0","repository_url":"https://github.com/indygreg/python-zstandard"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.19.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"flashinfer-python","old_version":"0.6.8.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"helion","old_version":"1.0.0","new_version":"1.4.0","repository_url":"https://github.com/pytorch/helion"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 169 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.5.3` | `5.17.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.128.0` | `0.141.1` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [mistral-common](https://github.com/mistralai/mistral-common) | `1.11.2` | `1.12.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.6.2.post1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [arrow](https://github.com/arrow-py/arrow) | `1.3.0` | `1.4.0` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.3` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.102` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.102` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.1.7` | `8.5.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.3` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.2` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.83.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.2.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.1` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.9.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [harfile](https://github.com/schemathesis/harfile) | `0.3.0` | `0.5.0` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.4.3` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.2` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.1` |\n| [hypothesis-graphql](https://github.com/Stranger6667/hypothesis-graphql) | `0.11.1` | `0.13.2` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.5` | `0.2.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonpointer](https://github.com/stefankoegl/python-json-pointer) | `3.0.0` | `3.1.1` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.6` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.3` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.8` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.1` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.0.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.19.0.56` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.0` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.28.9` | `2.32.3` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.8.0` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.18.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.4.0` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.12` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.15.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-subtests](https://github.com/pytest-dev/pytest-subtests) | `0.14.1` | `0.15.0` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [safetensors](https://github.com/huggingface/safetensors) | `0.4.5` | `0.8.0` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [tomli](https://github.com/hukkin/tomli) | `2.2.1` | `2.4.1` |\n| [triton](https://github.com/triton-lang/triton) | `3.6.0` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.15.2` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.6` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.9.1` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [zstandard](https://github.com/indygreg/python-zstandard) | `0.23.0` | `0.25.0` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.19.0` | `0.29.0` |\n| [flashinfer-python](https://github.com/flashinfer-ai/flashinfer) | `0.6.8.post1` | `0.7.0` |\n| [helion](https://github.com/pytorch/helion) | `1.0.0` | `1.4.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.5.3 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.3...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2217\"\u003e#2217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/447890f84deab25794ccfdee2a877901b6893569\"\u003e\u003ccode\u003e447890f\u003c/code\u003e\u003c/a\u003e fix(python): pin the ruff rule set so a ruff release can't redden main (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2292\"\u003e#2292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/68b3ab7788b58408f37a3dc73eeabf2417d14c22\"\u003e\u003ccode\u003e68b3ab7\u003c/code\u003e\u003c/a\u003e chore(node): take node security alerts from 33 to 0 (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2287\"\u003e#2287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/74ef81f64e6d1cd4979c56d7d75f3ce21ba11992\"\u003e\u003ccode\u003e74ef81f\u003c/code\u003e\u003c/a\u003e ci: pin every action to one SHA, drop stale audit suppressions (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2291\"\u003e#2291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/b26727f1a92cdf727cd965fc1c467a7c77c63aae\"\u003e\u003ccode\u003eb26727f\u003c/code\u003e\u003c/a\u003e chore(node): drop 8 unused devDependencies (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2286\"\u003e#2286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c7cfd838fb79e76aaba6b0931898073a784fb2a\"\u003e\u003ccode\u003e7c7cfd8\u003c/code\u003e\u003c/a\u003e chore: remove stale examples (kills 50% of dependabot traffic) (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2285\"\u003e#2285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.22.2...v0.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fastapi` from 0.128.0 to 0.141.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/fastapi/releases\"\u003efastapi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.141.1\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix support for background tasks and headers from dependencies in \u003ccode\u003eapp.frontend()\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16105\"\u003e#16105\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16104\"\u003e#16104\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.141.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more convenient with \u003ccode\u003efastapi dev\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16102\"\u003e#16102\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.13\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003estatus_code\u003c/code\u003e being ignored for SSE and JSONL streaming endpoints. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15937\"\u003e#15937\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Fix \u003ccode\u003eformat_sse_event\u003c/code\u003e docstring rendering of \u003ccode\u003e\\n\\n\u003c/code\u003e terminator. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15613\"\u003e#15613\u003c/a\u003e by \u003ca href=\"https://github.com/AshNicolus\"\u003e\u003ccode\u003e@​AshNicolus\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e📝 Add API reference page for fastapi.sse. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15930\"\u003e#15930\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.12\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix line splitting in \u003ccode\u003eformat_sse_event\u003c/code\u003e to comply with SSE spec. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15515\"\u003e#15515\u003c/a\u003e by \u003ca href=\"https://github.com/Zawwarsami16\"\u003e\u003ccode\u003e@​Zawwarsami16\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.11\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eresponse_model_*\u003c/code\u003e params ignored for non-generator endpoints with \u003ccode\u003eIterable[..]\u003c/code\u003e return type. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15093\"\u003e#15093\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.10\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix handling sequences with nested Annotated types. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/14874\"\u003e#14874\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Accept any base test failure as regression. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16092\"\u003e#16092\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🐛 Preserve pytest exit code in regression check. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16091\"\u003e#16091\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e✅ Test PR regressions against base code. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16090\"\u003e#16090\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.9\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eexclude_defaults\u003c/code\u003e not propagated to dict keys and values in \u003ccode\u003ejsonable_encoder\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16043\"\u003e#16043\u003c/a\u003e by \u003ca href=\"https://github.com/MBGrao\"\u003e\u003ccode\u003e@​MBGrao\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/95f8322ee1dcda7ceace7b1c4f6c9915b36d748f\"\u003e\u003ccode\u003e95f8322\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.1 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16106\"\u003e#16106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/f137944c435cff4e4b30ea7d12855ea88ddb868c\"\u003e\u003ccode\u003ef137944\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/d62354434b2e508fe89024213b220ca8e67dea5e\"\u003e\u003ccode\u003ed623544\u003c/code\u003e\u003c/a\u003e 🐛 Fix support for background tasks and headers from dependencies in `app.fron...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/1d211b9c1009d577f39fa2b19b10d9a93a72a0ed\"\u003e\u003ccode\u003e1d211b9\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/8a1f8768411e62093e70ce142ea10863a485643c\"\u003e\u003ccode\u003e8a1f876\u003c/code\u003e\u003c/a\u003e 📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16104\"\u003e#16104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/c7e7b651d6946c07cc9f675f39c9501d08319e57\"\u003e\u003ccode\u003ec7e7b65\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.0 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16103\"\u003e#16103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/6bceb84053eb2405e9c000aad30ea13367b5ee32\"\u003e\u003ccode\u003e6bceb84\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/5429fed84e84e32672c25a953eca3429b841ce90\"\u003e\u003ccode\u003e5429fed\u003c/code\u003e\u003c/a\u003e ✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more conven...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/628663f4f899c465da423bce681c7adf9a218948\"\u003e\u003ccode\u003e628663f\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.140.13 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16096\"\u003e#16096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/0b54fd00273019034dd30b120ac842e65d80690e\"\u003e\u003ccode\u003e0b54fd0\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/fastapi/compare/0.128.0...0.141.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.13.3 to 3.14.3\nUpdates `pydantic` from 2.12.0 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirec...\n\n_Description has been truncated_","html_url":"https://github.com/Wenz20101/vllm-0.17.1w/pull/19","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Wenz20101%2Fvllm-0.17.1w/issues/19","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/19/packages"},{"uuid":"5576671790","node_id":"PR_kwDOTw8DQM8AAAABFCOc6w","number":18,"state":"open","title":"Bump the minor-update group across 1 directory with 194 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-25T01:12:52.000Z","updated_at":"2026-09-25T01:13:02.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":194,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.26.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"watchfiles","old_version":"1.2.0","new_version":"1.3.0","repository_url":"https://github.com/samuelcolvin/watchfiles"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.57.1","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.6","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.6","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.1","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.26.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"flashinfer-python","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"flashinfer-cubin","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.0","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"auto-round-lib","old_version":"0.14.2","new_version":"0.15.0","repository_url":"https://github.com/intel/auto-round"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"\u003e [!WARNING]\n\u003e Cooldown could not be applied because no publication date was available from the registry.\n\u003e\n\nBumps the minor-update group with 194 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.26.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.99` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.99` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.1` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.57.1` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.6` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.6` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.1` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.26.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [flashinfer-python](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [flashinfer-cubin](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.0` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.10` |\n| [auto-round-lib](https://github.com/intel/auto-round) | `0.14.2` | `0.15.0` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.14.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.14.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.26.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.26.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggi...\n\n_Description has been truncated_","html_url":"https://github.com/kuoihao/vllm-tle/pull/18","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kuoihao%2Fvllm-tle/issues/18","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/18/packages"},{"uuid":"5570060544","node_id":"PR_kwDOTg5ijc8AAAABE877pw","number":20,"state":"open","title":"Bump the minor-update group across 1 directory with 173 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T14:42:10.000Z","updated_at":"2026-09-24T14:42:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":173,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.5.3","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"safetensors","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/huggingface/safetensors"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.6.2.post1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.1.7","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.2","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.4.3","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"huggingface-hub","old_version":"1.10.2","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.5","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.4","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.0.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.19.0.56","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.0","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.28.9","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.18.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.6.0","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.15.2","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.23.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"nvidia-cutlass-dsl","old_version":"4.5.2","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.2","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"},{"name":"helion","old_version":"1.1.0","new_version":"1.4.0","repository_url":"https://github.com/pytorch/helion"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 173 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.5.3` | `5.17.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [safetensors](https://github.com/huggingface/safetensors) | `0.7.0` | `0.8.0` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.6.2.post1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.1.7` | `8.5.0` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.2` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.4.3` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.10.2` | `1.32.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.5` | `0.2.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.4` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.0.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.19.0.56` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.0` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.28.9` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.18.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.6.0` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.15.2` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.23.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.5.2` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.2` | `0.2.10` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n| [helion](https://github.com/pytorch/helion) | `1.1.0` | `1.4.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.5.3 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.3...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2217\"\u003e#2217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/447890f84deab25794ccfdee2a877901b6893569\"\u003e\u003ccode\u003e447890f\u003c/code\u003e\u003c/a\u003e fix(python): pin the ruff rule set so a ruff release can't redden main (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2292\"\u003e#2292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/68b3ab7788b58408f37a3dc73eeabf2417d14c22\"\u003e\u003ccode\u003e68b3ab7\u003c/code\u003e\u003c/a\u003e chore(node): take node security alerts from 33 to 0 (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2287\"\u003e#2287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/74ef81f64e6d1cd4979c56d7d75f3ce21ba11992\"\u003e\u003ccode\u003e74ef81f\u003c/code\u003e\u003c/a\u003e ci: pin every action to one SHA, drop stale audit suppressions (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2291\"\u003e#2291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/b26727f1a92cdf727cd965fc1c467a7c77c63aae\"\u003e\u003ccode\u003eb26727f\u003c/code\u003e\u003c/a\u003e chore(node): drop 8 unused devDependencies (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2286\"\u003e#2286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c7cfd838fb79e76aaba6b0931898073a784fb2a\"\u003e\u003ccode\u003e7c7cfd8\u003c/code\u003e\u003c/a\u003e chore: remove stale examples (kills 50% of dependabot traffic) (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2285\"\u003e#2285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.22.2...v0.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `safetensors` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/safetensors/releases\"\u003esafetensors's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eNews\u003c/h2\u003e\n\u003cp\u003esafetensors joins the PyTorch foundation!\u003c/p\u003e\n\n\u003cp\u003eRead more on that: \u003ca href=\"https://huggingface.co/blog/safetensors-joins-pytorch-foundation\"\u003ehttps://huggingface.co/blog/safetensors-joins-pytorch-foundation\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's changed\u003c/h2\u003e\n\u003cp\u003eSafetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.\u003c/p\u003e\n\u003ch3\u003eBreaking\u003c/h3\u003e\n\u003cp\u003eThe \u003ccode\u003eserialize\u003c/code\u003e and \u003ccode\u003eserialize_file\u003c/code\u003e functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a \u003ccode\u003eTensorSpec\u003c/code\u003e class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level \u003ccode\u003eserialize\u003c/code\u003e / \u003ccode\u003eserialize_file\u003c/code\u003e API directly; the high-level wrappers (\u003ccode\u003esafetensors.torch\u003c/code\u003e, \u003ccode\u003esafetensors.numpy\u003c/code\u003e, \u003ccode\u003esafetensors.paddle\u003c/code\u003e) are updated internally and their public API is unchanged.\u003c/p\u003e\n\u003cp\u003eThe minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eTensorIndexer::Narrow\u003c/code\u003e now carries a \u003ccode\u003estep: NonZeroUsize\u003c/code\u003e parameter, so a slice is now \u003ccode\u003estart:stop:step\u003c/code\u003e. This is a fix as this silent error was hidden behind the \u003ccode\u003eStorage::Torch\u003c/code\u003e variant which offloaded slicing logic to torch directly.\u003c/p\u003e\n\u003ch3\u003eCI\u003c/h3\u003e\n\u003cp\u003eOn the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.\u003c/p\u003e\n\u003cp\u003eAlso dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.\u003c/p\u003e\n\u003ch3\u003eNew features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDirect MPS load on Apple Silicon: tensors are directly loaded in an \u003ccode\u003eMTLBuffer\u003c/code\u003e and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.\u003c/li\u003e\n\u003cli\u003eNew \u003ccode\u003ebackend\u003c/code\u003e parameter introduced, for the addition of the \u003ccode\u003epread\u003c/code\u003e backend. We now support loading files via \u003ccode\u003epread(2)\u003c/code\u003e syscall instead of just mmap. Useful for specific archs/platforms.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eget_slice\u003c/code\u003e now handles ellipsis \u003ccode\u003e[...]\u003c/code\u003e and strided slices \u003ccode\u003e[:, ::8]\u003c/code\u003e wherever safetensors does the slicing itself (\u003ccode\u003epread\u003c/code\u003e for any framework, MPS, and \u003ccode\u003emmap\u003c/code\u003e outside torch/paddle), which silently dropped the step or rejected \u003ccode\u003e...\u003c/code\u003e before.\u003c/li\u003e\n\u003cli\u003eMUSA device support for MooreThreads GPUs.\u003c/li\u003e\n\u003cli\u003eNew dtype support includes \u003ccode\u003efloat8_e4m3fnuz\u003c/code\u003e and \u003ccode\u003efloat8_e5m2fnuz\u003c/code\u003e (AMD FNUZ FP8 formats).\u003c/li\u003e\n\u003cli\u003eThe reader is now explicitly lenient about leading whitespace in the JSON header, which keeps the door open for future page-aligned writes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements/perf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile writes on macOS now use \u003ccode\u003eF_NOCACHE\u003c/code\u003e for direct I/O, yielding roughly 30% faster \u003ccode\u003esave_file\u003c/code\u003e on Apple Silicon.\u003c/li\u003e\n\u003cli\u003eThe packaging dependency has been dropped from the \u003ccode\u003e[torch]\u003c/code\u003e extra, replaced by a simple \u003ccode\u003ehasattr\u003c/code\u003e probe for efficiency.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd arm64 windows support by \u003ca href=\"https://github.com/finnagin\"\u003e\u003ccode\u003e@​finnagin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/678\"\u003esafetensors/safetensors#678\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(backend): support musa backend for MooreThreads GPU by \u003ca href=\"https://github.com/caizhi-mt\"\u003e\u003ccode\u003e@​caizhi-mt\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/671\"\u003esafetensors/safetensors#671\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd gil free serialize_file(serialize_file_threadable) by \u003ca href=\"https://github.com/TomQunChao\"\u003e\u003ccode\u003e@​TomQunChao\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/679\"\u003esafetensors/safetensors#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: remove outdated comment by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/685\"\u003esafetensors/safetensors#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add direct io write fast path on macos by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/687\"\u003esafetensors/safetensors#687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: keep dropped reference to tensor moved from gpu to cpu by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/689\"\u003esafetensors/safetensors#689\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: bump torch to \u003ccode\u003e2.4\u003c/code\u003e by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/710\"\u003esafetensors/safetensors#710\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContribution guide security by \u003ca href=\"https://github.com/LysandreJik\"\u003e\u003ccode\u003e@​LysandreJik\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/712\"\u003esafetensors/safetensors#712\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/safetensors/safetensors/blob/main/RELEASE.md\"\u003esafetensors's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.8.0-dev.0 → 0.8.0\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nUpdate lockfiles again:\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003ecargo check\ncd bindings/python \u0026amp;amp;\u0026amp;amp; uv lock\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;Commit:\u0026lt;/p\u0026gt;\n\u0026lt;pre\u0026gt;\u0026lt;code\u0026gt;Set version to 0.8.0\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;The Python version is not set in \u0026lt;code\u0026gt;pyproject.toml\u0026lt;/code\u0026gt; directly — maturin reads it from \u0026lt;code\u0026gt;bindings/python/Cargo.toml\u0026lt;/code\u0026gt; at build time.\u0026lt;/p\u0026gt;\n\u0026lt;h3\u0026gt;4. Create the release on GitHub\u0026lt;/h3\u0026gt;\n\u0026lt;p\u0026gt;Go to the \u0026lt;a href=\u0026quot;https://github.com/huggingface/safetensors/releases\u0026quot;\u0026gt;GitHub Releases page\u0026lt;/a\u0026gt; and draft a new release:\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Choose the release branch\u0026lt;/strong\u0026gt; (e.g. \u0026lt;code\u0026gt;git_v0.8.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Create a new tag\u0026lt;/strong\u0026gt; on publish: \u0026lt;code\u0026gt;v0.8.0\u0026lt;/code\u0026gt;\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Generate release notes\u0026lt;/strong\u0026gt; from the previous tag (e.g. \u0026lt;code\u0026gt;v0.7.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Add any notable highlights at the top of the generated notes\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;Structure for manual notes:\u0026lt;/p\u0026gt;\n\u0026lt;pre lang=\u0026quot;markdown\u0026quot;\u0026gt;...\n\n_Description has been truncated_","html_url":"https://github.com/KASW-UI/cpu-vllm/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KASW-UI%2Fcpu-vllm/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"},{"uuid":"5562149578","node_id":"PR_kwDOT_43As8AAAABE2wmZw","number":79,"state":"open","title":"chore(deps): bump the vision-python group across 1 directory with 8 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T02:31:55.000Z","updated_at":"2026-09-24T02:32:01.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"vision-python","update_count":8,"packages":[{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"torchvision","old_version":"0.28.0","new_version":"0.29.0+cpu"},{"name":"transformers","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.30.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"numpy","old_version":"2.5.2","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"sqlalchemy","old_version":"2.0.52","new_version":"2.0.54","repository_url":"https://github.com/sqlalchemy/sqlalchemy"},{"name":"psycopg","old_version":"3.3.5","new_version":"3.3.6","repository_url":"https://github.com/psycopg/psycopg"},{"name":"boto3","old_version":"1.43.88","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"}],"path":null,"ecosystem":"pip"},"body":"\u003e [!WARNING]\n\u003e Cooldown could not be applied because no publication date was available from the registry.\n\u003e\n\nBumps the vision-python group with 8 updates in the /vision directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| torchvision | `0.28.0` | `0.29.0+cpu` |\n| [transformers](https://github.com/huggingface/transformers) | `5.16.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.30.0` | `1.32.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |\n| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.52` | `2.0.54` |\n| [psycopg](https://github.com/psycopg/psycopg) | `3.3.5` | `3.3.6` |\n| [boto3](https://github.com/boto/boto3) | `1.43.88` | `1.43.98` |\n\n\nUpdates `uvicorn` from 0.52.4 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torchvision` from 0.28.0 to 0.29.0+cpu\n\nUpdates `transformers` from 5.16.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.30.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.30.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.5.2 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.5.2...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sqlalchemy` from 2.0.52 to 2.0.54\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sqlalchemy/sqlalchemy/releases\"\u003esqlalchemy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.0.54\u003c/h1\u003e\n\u003cp\u003eReleased: September 15, 2026\u003c/p\u003e\n\u003ch2\u003eplatform\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[platform] [change]\u003c/strong\u003e Binary wheels are no longer built for Python 3.7.  PyPI now rejects wheel\nfiles whose filename does not begin with the normalized project name, and\nthe packaging tools that can be installed on Python 3.7 do not produce\nsuch a filename.  As a result, SQLAlchemy 2.0.44 was the last release to\npublish Python 3.7 wheels to PyPI, and releases 2.0.45 and later have\nbeen available on Python 3.7 only as a source distribution; the wheel\nbuilds for Python 3.7 are now removed.  Python 3.7 remains supported by\nthe 2.0 series.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[platform] [bug]\u003c/strong\u003e Fixed issue where the Cython extensions were compiled without the\n\u003ccode\u003efreethreading_compatible\u003c/code\u003e directive, so that they did not declare\nthemselves as safe to run without the GIL.  On a free-threaded Python\ninterpreter such as Python 3.13t or 3.14t, importing SQLAlchemy would\ncause the interpreter to re-enable the GIL, emitting a\n\u003ccode\u003eRuntimeWarning\u003c/code\u003e.  The directive is now set when building for Python\n3.13 and above, and a test has been added which confirms that importing\nSQLAlchemy on a free-threaded build does not enable the GIL.\u003c/p\u003e\n\u003cp\u003eReferences: \u003ca href=\"https://www.sqlalchemy.org/trac/ticket/13592\"\u003e#13592\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.0.53\u003c/h1\u003e\n\u003cp\u003eReleased: September 14, 2026\u003c/p\u003e\n\u003ch2\u003eorm\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[orm] [bug]\u003c/strong\u003e Fixed issue where an expression passed to \u003ccode\u003e_orm.with_expression()\u003c/code\u003e\nthat embedded a \u003ccode\u003e_sql.select()\u003c/code\u003e, such as a correlated\n\u003ccode\u003e_sql.exists()\u003c/code\u003e, would fail to populate the attribute correctly on\nthe second and subsequent executions of an otherwise identical\nstatement, when the \u003ccode\u003e_orm.query_expression()\u003c/code\u003e attribute was loaded\nby a relationship loader that emits a second query, i.e.\n\u003ccode\u003e_orm.selectinload()\u003c/code\u003e, \u003ccode\u003e_orm.lazyload()\u003c/code\u003e or\n\u003ccode\u003e_orm.immediateload()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eReferences: \u003ca href=\"https://www.sqlalchemy.org/trac/ticket/13560\"\u003e#13560\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[orm] [bug]\u003c/strong\u003e Fixed memory issue where mapped classes, along with their\n\u003ccode\u003eTable\u003c/code\u003e and \u003ccode\u003e_orm.Mapper\u003c/code\u003e objects, would not be garbage\ncollected after the \u003ccode\u003e_orm.registry\u003c/code\u003e in which they were mapped had\nbeen disposed and dereferenced.  The issue would occur for mappings that\nmade use of \u003ccode\u003e_orm.relationship()\u003c/code\u003e together with constructs such as an\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sqlalchemy/sqlalchemy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `psycopg` from 3.3.5 to 3.3.6\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psycopg/psycopg/blob/master/docs/news.rst\"\u003epsycopg's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e.. currentmodule:: psycopg\u003c/p\u003e\n\u003cp\u003e.. index::\nsingle: Release notes\nsingle: News\u003c/p\u003e\n\u003ch1\u003e\u003ccode\u003epsycopg\u003c/code\u003e release notes\u003c/h1\u003e\n\u003ch2\u003eCurrent release\u003c/h2\u003e\n\u003cp\u003ePsycopg 3.3.6\n^^^^^^^^^^^^^\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for Python 3.15 (:ticket:\u003ccode\u003e[#1245](https://github.com/psycopg/psycopg/issues/1245)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDon't wait forever for a query to terminate after interrupting it, for\ninstance if the server is unresponsive. The fix requires libpq 17 or newer\n(:ticket:\u003ccode\u003e[#1371](https://github.com/psycopg/psycopg/issues/1371)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eCancel a running query upon receiving \u003ccode\u003e!SystemExit\u003c/code\u003e (:ticket:\u003ccode\u003e[#1384](https://github.com/psycopg/psycopg/issues/1384)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eReport \u003ccode\u003e!None\u003c/code\u003e instead of \u003ccode\u003e65535\u003c/code\u003e as the \u003ccode\u003eColumn.precision\u003c/code\u003e of an\n:sql:\u003ccode\u003einterval\u003c/code\u003e column declared with a fields restriction and no explicit\nprecision, such as e.g. :sql:\u003ccode\u003einterval day to second\u003c/code\u003e (:ticket:\u003ccode\u003e[#1397](https://github.com/psycopg/psycopg/issues/1397)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix dumping of nested subclasses of lists as arrays (:ticket:\u003ccode\u003e[#1398](https://github.com/psycopg/psycopg/issues/1398)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDiscard prepared statements upon :sql:\u003ccode\u003eDEALLOCATE ALL\u003c/code\u003e (:ticket:\u003ccode\u003e[#1408](https://github.com/psycopg/psycopg/issues/1408)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eBetter guards dumping large Python \u003ccode\u003e!int\u003c/code\u003e to binary numeric (:ticket:\u003ccode\u003e[#1414](https://github.com/psycopg/psycopg/issues/1414)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eImprove performance of async queries by reducing the overhead of the\n\u003ccode\u003e!wait_async()\u003c/code\u003e function (:ticket:\u003ccode\u003e[#1331](https://github.com/psycopg/psycopg/issues/1331)\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePsycopg 3.3.5\n^^^^^^^^^^^^^\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDiscard prepared statements upon :sql:\u003ccode\u003eALTER *\u003c/code\u003e or \u003ccode\u003eDISCARD *\u003c/code\u003e\n(:ticket:\u003ccode\u003e[#1307](https://github.com/psycopg/psycopg/issues/1307)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003e!ProgrammingError\u003c/code\u003e when dumping non-\u003ccode\u003e!None\u003c/code\u003e values with\nno \u003ccode\u003e!NoneType\u003c/code\u003e dumper registered in python implementation (:ticket:\u003ccode\u003e[#1325](https://github.com/psycopg/psycopg/issues/1325)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003e!wait_selector\u003c/code\u003e wait function to not raise \u003ccode\u003e!KeyError\u003c/code\u003e\n(:ticket:\u003ccode\u003e[#1327](https://github.com/psycopg/psycopg/issues/1327)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003e!DataError\u003c/code\u003e messages leaking the literal \u003ccode\u003e{...}\u003c/code\u003e placeholder instead\nof the offending value when loading a pre-year-1 :sql:\u003ccode\u003etimestamp\u003c/code\u003e or a\nmalformed binary :sql:\u003ccode\u003ejsonb\u003c/code\u003e value (:ticket:\u003ccode\u003e[#1372](https://github.com/psycopg/psycopg/issues/1372)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003e!DataError\u003c/code\u003e instead of \u003ccode\u003e!ValueError\u003c/code\u003e when \u003ccode\u003e~psycopg.rows.namedtuple_row\u003c/code\u003e\nreceives duplicate column names (:ticket:\u003ccode\u003e[#1348](https://github.com/psycopg/psycopg/issues/1348)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003e!DataError\u003c/code\u003e on inconsistent copy data (:tickets:\u003ccode\u003e[#1359](https://github.com/psycopg/psycopg/issues/1359), [#1360](https://github.com/psycopg/psycopg/issues/1360)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eHandle client encodings aliases (:ticket:\u003ccode\u003e[#1363](https://github.com/psycopg/psycopg/issues/1363)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix building C extension with Cython 3.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePsycopg 3.3.4\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/a67654d1e7afbf9b3a619557838f62de1c790e7c\"\u003e\u003ccode\u003ea67654d\u003c/code\u003e\u003c/a\u003e chore: bump psycopg package version to 3.3.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/443814b3b111ac678a39fd523c1a826266fb69b5\"\u003e\u003ccode\u003e443814b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/psycopg/psycopg/issues/1416\"\u003e#1416\u003c/a\u003e from dvarrazzo/wait-async-perf\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/42966e9ebbda3b9c69b15c5588543c15f2aae5dd\"\u003e\u003ccode\u003e42966e9\u003c/code\u003e\u003c/a\u003e test: add helpful comments to some tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/5e8797f0c8003d8cd12a1e5c13f05fbb94c1c1d2\"\u003e\u003ccode\u003e5e8797f\u003c/code\u003e\u003c/a\u003e test: add reasonable connect_timeout to most tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/c81ba62442dfbd69e207d6914e6ae2aa27e56886\"\u003e\u003ccode\u003ec81ba62\u003c/code\u003e\u003c/a\u003e perf: reduce the overhead of wait_async()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/d2bbfe4e2b1e36a20e72a18097f35a3db27296e3\"\u003e\u003ccode\u003ed2bbfe4\u003c/code\u003e\u003c/a\u003e refactor: use get_running_loop() in the async wait functions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/2b1484a550e01c88fda077099678f0abb9217ecb\"\u003e\u003ccode\u003e2b1484a\u003c/code\u003e\u003c/a\u003e test: add a script to measure the async wait functions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/573cf4aa70d8fdefc9d5f3eb69d5419cd6d3cd51\"\u003e\u003ccode\u003e573cf4a\u003c/code\u003e\u003c/a\u003e test: fix incorrect wait timing test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/2b68990874175b8d97269218d4963b2d5c8656f3\"\u003e\u003ccode\u003e2b68990\u003c/code\u003e\u003c/a\u003e refactor: drop leftovers of waiting with inf interval in wait_conn_async\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/60765dd8fc7d8df03cd75efcff485bfb3c83a0ed\"\u003e\u003ccode\u003e60765dd\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/psycopg/psycopg/issues/1414\"\u003e#1414\u003c/a\u003e from dvarrazzo/fix-decimal-overflow\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psycopg/psycopg/compare/3.3.5...3.3.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `boto3` from 1.43.88 to 1.43.98\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/3314d844db83f544d5e9e0a69e832c00aa5d35b4\"\u003e\u003ccode\u003e3314d84\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.98'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/3a3637ffdcfcbc372301c116fd4378bba35da85b\"\u003e\u003ccode\u003e3a3637f\u003c/code\u003e\u003c/a\u003e Bumping version to 1.43.98\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/d8023504a9d68112c34302fed9fa47256e05edac\"\u003e\u003ccode\u003ed802350\u003c/code\u003e\u003c/a\u003e Add changelog entries from botocore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/ed7de96664d52b6e04521b189462c7d43959e90a\"\u003e\u003ccode\u003eed7de96\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.97'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/fba1e41a696d49d48c1fb0d8a844515869fe832c\"\u003e\u003ccode\u003efba1e41\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.97' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/275709c0e197e696f122571d26a6d2a51d7438a7\"\u003e\u003ccode\u003e275709c\u003c/code\u003e\u003c/a\u003e Bumping version to 1.43.97\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/a5c0088fb17e49e4bb4b1ea3d1a69dc5e3ecc907\"\u003e\u003ccode\u003ea5c0088\u003c/code\u003e\u003c/a\u003e Add changelog entries from botocore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/2be9967c9214ffb4421dc9710c7f7fead47dcd33\"\u003e\u003ccode\u003e2be9967\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.96'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/bc6248938c188c427b902be1362e85e0bce2be32\"\u003e\u003ccode\u003ebc62489\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.96' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/6e1774a1ffe1d84bfd70f36c0bdff3e6dd079aaa\"\u003e\u003ccode\u003e6e1774a\u003c/code\u003e\u003c/a\u003e Bumping version to 1.43.96\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/boto/boto3/compare/1.43.88...1.43.98\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/oldmoldycake/Snagr/pull/79","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/oldmoldycake%2FSnagr/issues/79","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/79/packages"},{"uuid":"5540499012","node_id":"PR_kwDOPZl8xs8AAAABEloFHw","number":85,"state":"open","title":"chore(deps): bump transformers from 4.57.6 to 5.10.1","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T13:47:59.000Z","updated_at":"2026-09-24T06:37:02.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"transformers","old_version":"4.57.6","new_version":"5.10.1","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Bumps [transformers](https://github.com/huggingface/transformers) from 4.57.6 to 5.10.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v5.10.1\u003c/h1\u003e\n\u003cp\u003ev5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!\u003c/p\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eGemma4 unified+ Gemma4 MTP\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eGemma 4 12B Unified is an \u003cstrong\u003eencoder-free\u003c/strong\u003e multimodal model with pretrained and instruction-tuned variants. Unlike \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gemma4\"\u003estandard Gemma 4\u003c/a\u003e, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.\u003c/p\u003e\n\u003cp\u003eKey differences from standard Gemma 4:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo Vision Tower\u003c/strong\u003e: Raw pixel patches are projected directly into LM space via a \u003ccode\u003eDense + LayerNorm\u003c/code\u003e pipeline with factorized 2D positional embeddings, replacing the vision encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNo Audio Tower\u003c/strong\u003e: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple \u003ccode\u003eRMSNorm → Linear\u003c/code\u003e pipeline, replacing the mel spectrogram + Conformer encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eShared Multimodal Pipeline\u003c/strong\u003e: Both vision and audio use the same \u003ccode\u003eGemma4UnifiedMultimodalEmbedder\u003c/code\u003e (RMSNorm → Linear) for the final projection to text hidden space.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou can find the original Gemma 4 12B Unified checkpoints under the \u003ca href=\"https://huggingface.co/collections/google/gemma-4\"\u003eGemma 4\u003c/a\u003e release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewho needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e) by \u003ca href=\"https://github.com/douglas-reid\"\u003e\u003ccode\u003e@​douglas-reid\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/sgerrard\"\u003e\u003ccode\u003e@​sgerrard\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/vasqu\"\u003e\u003ccode\u003e@​vasqu\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/molbap\"\u003e\u003ccode\u003e@​molbap\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSapiens2\u003c/h3\u003e\n\u003cp\u003eSapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2\"\u003eDocumentation\u003c/a\u003e | \u003ca href=\"https://huggingface.co/papers/2604.21681\"\u003ePaper\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e) by \u003ca href=\"https://github.com/guarin\"\u003e\u003ccode\u003e@​guarin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45919\"\u003e#45919\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDeepSeek-OCR-2\u003c/h3\u003e\n\u003cp\u003eDeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Deepseek-OCR-2 model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45075\"\u003e#45075\u003c/a\u003e) by \u003ca href=\"https://github.com/thisisiron\"\u003e\u003ccode\u003e@​thisisiron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45075\"\u003e#45075\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMellum\u003c/h3\u003e\n\u003cp\u003eMellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/mellum\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Add support for JetBrains' \u003ccode\u003eMellum\u003c/code\u003e v2 code generation model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46112\"\u003e#46112\u003c/a\u003e) by \u003ca href=\"https://github.com/shadeMe\"\u003e\u003ccode\u003e@​shadeMe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/46112\"\u003e#46112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBreaking changes\u003c/h2\u003e\n\u003cp\u003eThe Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 Fix float16 overflow in Gemma4 vision pooler (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46277\"\u003e#46277\u003c/a\u003e) by \u003ca href=\"https://github.com/Bluear7878\"\u003e\u003ccode\u003e@​Bluear7878\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAudio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 [ALM] Add base model without head (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45534\"\u003e#45534\u003c/a\u003e) by \u003ca href=\"https://github.com/eustlb\"\u003e\u003ccode\u003e@​eustlb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d\"\u003e\u003ccode\u003e90c3ae5\u003c/code\u003e\u003c/a\u003e Patch because we had to yank 5.10 because the release branch was not up to date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968\"\u003e\u003ccode\u003e0bd94b3\u003c/code\u003e\u003c/a\u003e v5.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897\"\u003e\u003ccode\u003e1423d22\u003c/code\u003e\u003c/a\u003e who needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98\"\u003e\u003ccode\u003e50eb20a\u003c/code\u003e\u003c/a\u003e Fix dsv4 dequant + tp/ep (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46378\"\u003e#46378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299\"\u003e\u003ccode\u003e74464e8\u003c/code\u003e\u003c/a\u003e Fix wrong changes produced by style/repo. check bot (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46371\"\u003e#46371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc\"\u003e\u003ccode\u003e1b8ec34\u003c/code\u003e\u003c/a\u003e Fix path traversal when saving Bark voice preset embeddings (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46237\"\u003e#46237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872\"\u003e\u003ccode\u003ee820678\u003c/code\u003e\u003c/a\u003e Add Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43\"\u003e\u003ccode\u003e595721c\u003c/code\u003e\u003c/a\u003e Pass library_name/version to Hub calls via a shared HfApi (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46318\"\u003e#46318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a\"\u003e\u003ccode\u003e0f0036c\u003c/code\u003e\u003c/a\u003e docs: update ACL Anthology URL in CITATION.cff (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46352\"\u003e#46352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353\"\u003e\u003ccode\u003efa6c830\u003c/code\u003e\u003c/a\u003e DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45634\"\u003e#45634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.57.6...v5.10.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=transformers\u0026package-manager=uv\u0026previous-version=4.57.6\u0026new-version=5.10.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/manykarim/rf-mcp/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/manykarim/rf-mcp/pull/85","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/manykarim%2Frf-mcp/issues/85","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/85/packages"},{"uuid":"5537987472","node_id":"PR_kwDORRqaa88AAAABEjmjBg","number":155,"state":"closed","title":"build(deps): bump the python-minor-patch group across 1 directory with 22 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-23T23:48:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-22T09:58:13.000Z","updated_at":"2026-09-23T23:48:03.000Z","time_to_close":136188,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"python-minor-patch","update_count":22,"packages":[{"name":"pillow-heif","old_version":"1.5.0","new_version":"1.7.0","repository_url":"https://github.com/bigcat88/pillow_heif"},{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pyjwt","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"filelock","old_version":"3.32.4","new_version":"3.32.7","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"grpcio","old_version":"1.83.1","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"huggingface-hub","old_version":"1.29.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"hypothesis","old_version":"6.167.1","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"multidict","old_version":"6.7.1","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.25.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"onnx","old_version":"1.22.0","new_version":"1.23.0","repository_url":"https://github.com/onnx/onnx"},{"name":"propcache","old_version":"0.5.2","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"protobuf","old_version":"7.36.0","new_version":"7.36.2","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"python-discovery","old_version":"1.6.0","new_version":"1.6.1","repository_url":"https://github.com/tox-dev/python-discovery"},{"name":"regex","old_version":"2026.8.31","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"ruff","old_version":"0.16.5","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"threadpoolctl","old_version":"3.6.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"virtualenv","old_version":"21.7.7","new_version":"21.7.16","repository_url":"https://github.com/pypa/virtualenv"},{"name":"yarl","old_version":"1.24.5","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-minor-patch group with 22 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pillow-heif](https://github.com/bigcat88/pillow_heif) | `1.5.0` | `1.7.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.4` | `3.32.7` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| [grpcio](https://github.com/grpc/grpc) | `1.83.1` | `1.84.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.29.0` | `1.32.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.167.1` | `6.168.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.9.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.25.0` | `2.26.0` |\n| [onnx](https://github.com/onnx/onnx) | `1.22.0` | `1.23.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.5.2` | `0.5.4` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.36.0` | `7.36.2` |\n| [python-discovery](https://github.com/tox-dev/python-discovery) | `1.6.0` | `1.6.1` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.8.31` | `2026.9.10` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.8` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.6.0` | `3.7.0` |\n| [virtualenv](https://github.com/pypa/virtualenv) | `21.7.7` | `21.7.16` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.5` | `1.25.1` |\n\n\nUpdates `pillow-heif` from 1.5.0 to 1.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/bigcat88/pillow_heif/releases\"\u003epillow-heif's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.7.0\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing nominal diffuse white luminance HDR metadata: \u003ccode\u003enominal_diffuse_white_luminance\u003c/code\u003e key in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/468\"\u003e#468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epy.typed\u003c/code\u003e marker, the package type annotations are now visible to type checkers. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.2\u003c/code\u003e to \u003ccode\u003e1.23.3\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/470\"\u003e#470\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibde265\u003c/code\u003e was updated from the \u003ccode\u003e1.1.1\u003c/code\u003e to \u003ccode\u003e1.1.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/471\"\u003e#471\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOut-of-bounds read in \u003ccode\u003eencode()\u003c/code\u003e when \u003ccode\u003estride\u003c/code\u003e was smaller than the image row width. (GHSA-ccw6-q225-c975) Thanks to \u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e for finding this!\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTypeError\u003c/code\u003e when saving an image whose \u003ccode\u003einfo\u003c/code\u003e dictionary contains non-string keys. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.6.0\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing HDR metadata: \u003ccode\u003econtent_light_level\u003c/code\u003e, \u003ccode\u003emastering_display_colour_volume\u003c/code\u003e, \u003ccode\u003eambient_viewing_environment\u003c/code\u003e keys in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/456\"\u003e#456\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython \u003ccode\u003e3.15\u003c/code\u003e and \u003ccode\u003e3.15t\u003c/code\u003e wheels added.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.1\u003c/code\u003e to \u003ccode\u003e1.23.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/466\"\u003e#466\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse-after-free when a numpy array or the \u003ccode\u003edata\u003c/code\u003e memoryview outlived the \u003ccode\u003eHeifFile\u003c/code\u003e it was created from. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/453\"\u003e#453\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConflicting license metadata: removed the \u003ccode\u003eGPLv2\u003c/code\u003e classifier, the package license is \u003ccode\u003eBSD-3-Clause\u003c/code\u003e; bundled library licenses in wheels are described in \u003ccode\u003eLICENSES_bundled.txt\u003c/code\u003e, which was updated to match the current libraries. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/455\"\u003e#455\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/bigcat88/pillow_heif/blob/master/CHANGELOG.md\"\u003epillow-heif's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.7.0 - 2026-09-06]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing nominal diffuse white luminance HDR metadata: \u003ccode\u003enominal_diffuse_white_luminance\u003c/code\u003e key in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/468\"\u003e#468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epy.typed\u003c/code\u003e marker, the package type annotations are now visible to type checkers. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.2\u003c/code\u003e to \u003ccode\u003e1.23.3\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/470\"\u003e#470\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibde265\u003c/code\u003e was updated from the \u003ccode\u003e1.1.1\u003c/code\u003e to \u003ccode\u003e1.1.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/471\"\u003e#471\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOut-of-bounds read in \u003ccode\u003eencode()\u003c/code\u003e when \u003ccode\u003estride\u003c/code\u003e was smaller than the image row width. (GHSA-ccw6-q225-c975) Thanks to \u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e for finding this!\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTypeError\u003c/code\u003e when saving an image whose \u003ccode\u003einfo\u003c/code\u003e dictionary contains non-string keys. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.6.0 - 2026-08-31]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing HDR metadata: \u003ccode\u003econtent_light_level\u003c/code\u003e, \u003ccode\u003emastering_display_colour_volume\u003c/code\u003e, \u003ccode\u003eambient_viewing_environment\u003c/code\u003e keys in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/456\"\u003e#456\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython \u003ccode\u003e3.15\u003c/code\u003e and \u003ccode\u003e3.15t\u003c/code\u003e wheels added.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.1\u003c/code\u003e to \u003ccode\u003e1.23.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/466\"\u003e#466\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse-after-free when a numpy array or the \u003ccode\u003edata\u003c/code\u003e memoryview outlived the \u003ccode\u003eHeifFile\u003c/code\u003e it was created from. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/453\"\u003e#453\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConflicting license metadata: removed the \u003ccode\u003eGPLv2\u003c/code\u003e classifier, the package license is \u003ccode\u003eBSD-3-Clause\u003c/code\u003e; bundled library licenses in wheels are described in \u003ccode\u003eLICENSES_bundled.txt\u003c/code\u003e, which was updated to match the current libraries. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/455\"\u003e#455\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/f65a9ac77809609ad8ebb001c691b5a3ee01146b\"\u003e\u003ccode\u003ef65a9ac\u003c/code\u003e\u003c/a\u003e v1.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/a32776839dc69bc0bc7452a015fc48f145b1831e\"\u003e\u003ccode\u003ea327768\u003c/code\u003e\u003c/a\u003e feat: py.typed marker; fix the mypy errors it exposes (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/b7d8f391d67de84080d5a254268537aaa71567dc\"\u003e\u003ccode\u003eb7d8f39\u003c/code\u003e\u003c/a\u003e fix: out-of-bounds read in encode() when stride is smaller than the row (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/474\"\u003e#474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/cb0edae400111e6b83ac8af146d81da92baddcfd\"\u003e\u003ccode\u003ecb0edae\u003c/code\u003e\u003c/a\u003e chore(deps): update pypa/cibuildwheel action to v4.2.1 (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/472\"\u003e#472\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/9a255542051d9ca8ff43015a58bf5967567559dc\"\u003e\u003ccode\u003e9a25554\u003c/code\u003e\u003c/a\u003e chore(deps): update dependency strukturag/libheif to v1.23.3 (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/470\"\u003e#470\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/fb3a3842914fd3c07c3c8a93dffe35045ded2df7\"\u003e\u003ccode\u003efb3a384\u003c/code\u003e\u003c/a\u003e ci: let renovate update every bundled library version reference (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/473\"\u003e#473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/14c0c24ac81f5d2ddca17d3505efe32ea5fa6fbc\"\u003e\u003ccode\u003e14c0c24\u003c/code\u003e\u003c/a\u003e chore(deps): update dependency strukturag/libde265 to v1.1.2 (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/471\"\u003e#471\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/1460a210cced41f99788c1dc96e7a5ba49cc94a2\"\u003e\u003ccode\u003e1460a21\u003c/code\u003e\u003c/a\u003e feat: read and write nominal diffuse white luminance (ndwt) (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/468\"\u003e#468\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/e7b41516053be108ef1fb4feaac69b99bc7cc811\"\u003e\u003ccode\u003ee7b4151\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/469\"\u003e#469\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/5695650dbe0d4bf5616110782697b43d57805e46\"\u003e\u003ccode\u003e5695650\u003c/code\u003e\u003c/a\u003e bump version to 1.7.0.dev0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/bigcat88/pillow_heif/compare/v1.5.0...v1.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `uvicorn` from 0.52.4 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.13.0 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ePyJWT 2.14.0\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst\"\u003e2.14.0 changelog\u003c/a\u003e for the complete release details and related security advisories.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.14.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Harden HMAC key validation against public-key material supplied as JWK,\n  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See\n  `GHSA-r6x4-923q-g947 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947\u0026gt;`__,\n  `GHSA-ffc3-869f-jxw9 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9\u0026gt;`__,\n  `GHSA-p4g4-x82p-q773 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773\u0026gt;`__,\n  and `GHSA-w2cx-738m-mc7w \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w\u0026gt;`__.\n- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing\n  redirected destinations from being treated as trusted key sources. See\n  `GHSA-9v7f-9g4p-ffgj \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj\u0026gt;`__.\n- Limit repeated JWKS refreshes caused by unknown key IDs while preserving\n  normal key-rotation behavior. See\n  `GHSA-2gx3-rcp4-g85q \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q\u0026gt;`__.\n- Handle deeply nested and malformed JWS/JWK input without uncaught recursion\n  errors or whole-set parsing failures. See\n  `GHSA-8wjv-2p76-3863 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863\u0026gt;`__\n  and `GHSA-w6j9-cwv2-h6wq \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq\u0026gt;`__.\n- Enforce compact JWS encoding rules during decoding. See\n  `GHSA-hxm8-2xgr-2p9m \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m\u0026gt;`__.\n- Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n\n  \u0026lt;https://github.com/xclow3n\u0026gt;`__ for reporting this behavior; fixed in commit\n  `37b54877 \u0026lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Apply HMAC key validation consistently when keys are loaded through\n  ``PyJWK`` and ``PyJWKClient``. See\n  `GHSA-pxh4-856f-4h89 \u0026amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89\u0026amp;gt;`__.\n- Reject empty HMAC keys when represented as JWKs.\n  See `GHSA-pxh4-856f-4h89 \u0026amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89\u0026amp;gt;`__.\n\nFixed\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eRaise the documented \u003ccode\u003ePyJWTError\u003c/code\u003e subclass instead of leaking a\u003cbr /\u003e\n\u003ccode\u003eTypeError\u003c/code\u003e when the \u003ccode\u003eexp\u003c/code\u003e, \u003ccode\u003enbf\u003c/code\u003e, or \u003ccode\u003eiat\u003c/code\u003e claim decodes to a\u003cbr /\u003e\nnon-numeric, non-string value such as a list, dict, or \u003ccode\u003enull\u003c/code\u003e.\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df\"\u003e\u003ccode\u003ec6fe464\u003c/code\u003e\u003c/a\u003e release: prepare v2.14.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42\"\u003e\u003ccode\u003ef541302\u003c/code\u003e\u003c/a\u003e style: apply Ruff formatting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95\"\u003e\u003ccode\u003e801cd12\u003c/code\u003e\u003c/a\u003e fix: reject public JWK container HMAC keys\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb\"\u003e\u003ccode\u003eaf8181c\u003c/code\u003e\u003c/a\u003e fix: reject empty HMAC keys from JWKs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1\"\u003e\u003ccode\u003eba4853a\u003c/code\u003e\u003c/a\u003e Throttle repeated PyJWKClient refreshes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499\"\u003e\u003ccode\u003e2798504\u003c/code\u003e\u003c/a\u003e fix: reject DER public keys as HMAC secrets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07\"\u003e\u003ccode\u003e8b4e233\u003c/code\u003e\u003c/a\u003e fix: reject loader-accepted PEM variants\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258\"\u003e\u003ccode\u003e1f8180a\u003c/code\u003e\u003c/a\u003e fix: format JWS tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab\"\u003e\u003ccode\u003ecff1ac5\u003c/code\u003e\u003c/a\u003e Fix redirect handler return annotation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56\"\u003e\u003ccode\u003e0a795b8\u003c/code\u003e\u003c/a\u003e Reject redirects in PyJWKClient fetches\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anyio` from 4.14.2 to 4.15.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.15.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplemented a compatibility fix for supporting direct access of \u003ccode\u003eanyio.*\u003c/code\u003e submodules from the main package even when those submodules were not directly imported first (\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311\"\u003e#1311\u003c/a\u003e \u0026lt;\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E\"\u003eagronholm/anyio#1311\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.15.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for the newer keyword-only arguments on \u003ccode\u003eanyio.Path\u003c/code\u003e methods to match the standard library \u003ccode\u003epathlib.Path\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eexists()\u003c/code\u003e (Python 3.12+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_dir()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_file()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eowner()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003egroup()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enewline\u003c/code\u003e on \u003ccode\u003eread_text()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1286\"\u003e#1286\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1293\"\u003e#1293\u003c/a\u003e; PR by \u003ca href=\"https://github.com/jaideeppyne\"\u003e\u003ccode\u003e@​jaideeppyne\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eamap\u003c/code\u003e, \u003ccode\u003egather\u003c/code\u003e, and \u003ccode\u003eas_completed\u003c/code\u003e utility functions to simplify common patterns (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1173\"\u003e#1173\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003e--anyio-mode\u003c/code\u003e command-line option as an alternative to the \u003ccode\u003eanyio_mode\u003c/code\u003e ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: \u003ccode\u003epytest_asyncio\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1242\"\u003e#1242\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003eanyio.Future\u003c/code\u003e synchronization primitive which behaves similar to \u003ccode\u003easyncio.Future\u003c/code\u003e, allowing tasks to wait for a value (or exception) from another task (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1146\"\u003e#1146\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Vizonex\"\u003e\u003ccode\u003e@​Vizonex\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded guidance for managing multiple memory object stream producers and consumers with cloned streams (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/330\"\u003e#330\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nightcityblade\"\u003e\u003ccode\u003e@​nightcityblade\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eStapledObjectStream.send_nowait()\u003c/code\u003e that delegates to the underlying \u003ccode\u003eObjectSendStream\u003c/code\u003e, if it implements it (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1241\"\u003e#1241\u003c/a\u003e; PR by \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003emove_on_at()\u003c/code\u003e and \u003ccode\u003efail_at()\u003c/code\u003e functions to complement \u003ccode\u003emove_on_after()\u003c/code\u003e and \u003ccode\u003efail_after()\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the default name for a task spawned with \u003ccode\u003eTaskGroup.create_task(func())\u003c/code\u003e to match the default task name for the analogous task spawned with \u003ccode\u003eTaskGroup.start_soon(func)\u003c/code\u003e or \u003ccode\u003eTaskGroup.start(func)\u003c/code\u003e in more situations. Previously, the default name of a \u003ccode\u003eTaskGroup.create_task\u003c/code\u003e task never included the module name. (The default name for a task spawned with \u003ccode\u003eTaskGroup.start_soon\u003c/code\u003e or \u003ccode\u003eTaskGroup.start\u003c/code\u003e typically includes the module name.) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1234\"\u003e#1234\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the \u003ccode\u003eanyio\u003c/code\u003e and \u003ccode\u003eanyio.abc\u003c/code\u003e modules to lazily (much like \u003ccode\u003e810\u003c/code\u003e) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the \u003ccode\u003eif TYPE_CHECKING:\u003c/code\u003e block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1169\"\u003e#1169\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to \u003ccode\u003estart_blocking_portal()\u003c/code\u003e and \u003ccode\u003eanyio.to_thread.run_sync()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1224\"\u003e#1224\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eSpooledTemporaryFile.readinto()\u003c/code\u003e and \u003ccode\u003ereadinto1()\u003c/code\u003e reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1215\"\u003e#1215\u003c/a\u003e; PR by \u003ca href=\"https://github.com/c-tonneslan\"\u003e\u003ccode\u003e@​c-tonneslan\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded a \u003ccode\u003ereason\u003c/code\u003e parameter to \u003ccode\u003efail_after\u003c/code\u003e (and the new \u003ccode\u003efail_at\u003c/code\u003e) allowing for added exception context when raising \u003ccode\u003eTimeoutError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1227\"\u003e#1227\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the default \u003ccode\u003eTaskHandle.name\u003c/code\u003e missing part of the task name for tasks started with \u003ccode\u003eTaskGroup.start\u003c/code\u003e on Trio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1231\"\u003e#1231\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.run\u003c/code\u003e leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a \u003ccode\u003eRunVar\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1203\"\u003e#1203\u003c/a\u003e; PR by \u003ca href=\"https://github.com/tapetersen\"\u003e\u003ccode\u003e@​tapetersen\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.Path.with_stem()\u003c/code\u003e silently producing a wrong path (e.g. \u003ccode\u003ePath(\u0026quot;.txt\u0026quot;)\u003c/code\u003e) instead of raising \u003ccode\u003eValueError\u003c/code\u003e when given an empty stem on a path with a non-empty suffix, unlike \u003ccode\u003epathlib.PurePath.with_stem\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1200\"\u003e#1200\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Sanjays2402\"\u003e\u003ccode\u003e@​Sanjays2402\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eUNIXSocketStream.aclose()\u003c/code\u003e raising \u003ccode\u003easyncio.InvalidStateError\u003c/code\u003e when a concurrent receive or send operation had just been cancelled on the asyncio backend (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1267\"\u003e#1267\u003c/a\u003e; PR by \u003ca href=\"https://github.com/alloutflo\"\u003e\u003ccode\u003e@​alloutflo\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the pytest plugin importing the deprecated \u003ccode\u003e_pytest.python.CallSpec2\u003c/code\u003e alias, which triggers \u003ccode\u003ePytestRemovedIn10Warning\u003c/code\u003e on \u003ccode\u003epytest\u0026gt;=9.2\u003c/code\u003e and crashes pytest at startup when \u003ccode\u003efilterwarnings = error\u003c/code\u003e is configured (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1271\"\u003e#1271\u003c/a\u003e; PR by \u003ca href=\"https://github.com/matthewfeickert\"\u003e\u003ccode\u003e@​matthewfeickert\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed an asyncio worker thread race that could raise \u003ccode\u003eRuntimeError\u003c/code\u003e when the event loop closed between checking its state and scheduling the worker result (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1265\"\u003e#1265\u003c/a\u003e; PR by \u003ca href=\"https://github.com/hansu650\"\u003e\u003ccode\u003e@​hansu650\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens when \u003ccode\u003etotal_tokens\u003c/code\u003e was raised while the limiter was over-subscribed (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1223\"\u003e#1223\u003c/a\u003e; PR by \u003ca href=\"https://github.com/zelinewang\"\u003e\u003ccode\u003e@​zelinewang\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703\"\u003e\u003ccode\u003effcd154\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f\"\u003e\u003ccode\u003e0ecf5ed\u003c/code\u003e\u003c/a\u003e Added a workaround for third party code accessing unimported submodules (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f\"\u003e\u003ccode\u003e9283662\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d\"\u003e\u003ccode\u003ed137692\u003c/code\u003e\u003c/a\u003e Improved the instructions for AI agents\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265\"\u003e\u003ccode\u003e033fc52\u003c/code\u003e\u003c/a\u003e Shield TemporaryDirectory cleanup from cancellation (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc\"\u003e\u003ccode\u003e942e9a6\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1305\"\u003e#1305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704\"\u003e\u003ccode\u003eb825c3b\u003c/code\u003e\u003c/a\u003e Fixed pyproject.toml changes not triggering the test suite\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af\"\u003e\u003ccode\u003e9727dc5\u003c/code\u003e\u003c/a\u003e Fixed start inconsistencies between trio and asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1198\"\u003e#1198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8\"\u003e\u003ccode\u003eb05fe6d\u003c/code\u003e\u003c/a\u003e Fixed wrong type in move_on_after (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153\"\u003e\u003ccode\u003e44d0c93\u003c/code\u003e\u003c/a\u003e Fixed asyncio task group coroutine cleanup (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1275\"\u003e#1275\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.14.2...4.15.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `filelock` from 3.32.4 to 3.32.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/py-filelock/releases\"\u003efilelock's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.32.7\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix final symlink test on musl by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/737\"\u003etox-dev/filelock#737\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say acquire() falls back to the lock's blocking attribute by \u003ca href=\"https://github.com/hxperl\"\u003e\u003ccode\u003e@​hxperl\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/733\"\u003etox-dev/filelock#733\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hxperl\"\u003e\u003ccode\u003e@​hxperl\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/733\"\u003etox-dev/filelock#733\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.6...3.32.7\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.6...3.32.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix(lease): reject a duration no marker can carry by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/723\"\u003etox-dev/filelock#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(soft-rw): reject non-finite timing options by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/724\"\u003etox-dev/filelock#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve exception notes when copying and pickling by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(soft-rw): reuse existing test module by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/730\"\u003etox-dev/filelock#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: respect ACL write access when the owner write bit is absent by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/728\"\u003etox-dev/filelock#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SoftReadWriteLock state lock timeout by \u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.5\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(fork): report where a stalled fork stops by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/715\"\u003etox-dev/filelock#715\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say that mode is read-only in the thread-local section by \u003ca href=\"https://github.com/Gares95\"\u003e\u003ccode\u003e@​Gares95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/716\"\u003etox-dev/filelock#716\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(lease): clear token after failed acquire by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst\"\u003efilelock's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e###########\nChangelog\n###########\u003c/p\u003e\n\u003cp\u003e.. towncrier-draft-entries:: Unreleased\u003c/p\u003e\n\u003cp\u003e.. towncrier release notes start\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.1 (2026-09-19)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epoll_interval\u003c/code\u003e is now validated at construction, on the setter, and on \u003ccode\u003eacquire()\u003c/code\u003e: a negative, non-finite, or\nnon-numeric value raises :class:\u003ccode\u003eValueError\u003c/code\u003e/:class:\u003ccode\u003eTypeError\u003c/code\u003e immediately instead of failing inside \u003ccode\u003etime.sleep\u003c/code\u003e. :pr:\u003ccode\u003e739\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.0 (2026-09-17)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eThe :class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e on-disk protocol is a generation log under \u003ccode\u003e\u0026lt;path\u0026gt;.rw\u003c/code\u003e, and a process\nrunning an earlier release does not see it: an old and a new participant on one lock path do not exclude each\nother. Stop every participant, upgrade them all, then restart them; the new code ignores leftover \u003ccode\u003e.state\u003c/code\u003e,\n\u003ccode\u003e.write\u003c/code\u003e and \u003ccode\u003e.readers/\u003c/code\u003e files, and you can delete them. The filesystem must provide no-replace hard links, as\nit must for :class:\u003ccode\u003e~filelock.StrictSoftFileLock\u003c/code\u003e, so a runtime without \u003ccode\u003eos.link\u003c/code\u003e raises\n:class:\u003ccode\u003e~filelock.SoftFileLockProtocolError\u003c/code\u003e on acquire. Constructing a singleton again with a different\n\u003ccode\u003eon_compromise\u003c/code\u003e, or with \u003ccode\u003epoll_interval\u003c/code\u003e at or above \u003ccode\u003estale_threshold\u003c/code\u003e, now raises :class:\u003ccode\u003eValueError\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e exposes :attr:\u003ccode\u003e~filelock.SoftReadWriteLock.generation\u003c/code\u003e as a fencing token for\nthe protected resource and reports a lost hold through \u003ccode\u003eon_compromise\u003c/code\u003e and\n:attr:\u003ccode\u003e~filelock.SoftReadWriteLock.compromise\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e no longer deadlocks when a holder dies on another host mid-transition, and\n\u003ccode\u003erelease()\u003c/code\u003e no longer waits on a mutex a dead host left behind (:pr:\u003ccode\u003e725\u003c/code\u003e, :pr:\u003ccode\u003e735\u003c/code\u003e). The state mutex is gone.\nEach transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock\nrather than an \u003ccode\u003emtime\u003c/code\u003e read against another host's. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.7 (2026-09-16)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eValidate final-symlink refusal by error number so the test works across libc implementations. :pr:\u003ccode\u003e737\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocument that :meth:\u003ccode\u003e~filelock.BaseFileLock.acquire\u003c/code\u003e reads \u003ccode\u003eblocking=None\u003c/code\u003e as the lock's \u003ccode\u003eblocking\u003c/code\u003e attribute and\nraises :class:\u003ccode\u003e~filelock.Timeout\u003c/code\u003e after one attempt when \u003ccode\u003eblocking=False\u003c/code\u003e. :pr:\u003ccode\u003e733\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.6 (2026-09-08)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSoftFileLease\u003c/code\u003e and \u003ccode\u003eAsyncSoftFileLease\u003c/code\u003e now reject a boolean or non-finite \u003ccode\u003elease_duration\u003c/code\u003e, which used to\npublish an owner record their own \u003ccode\u003eowner\u003c/code\u003e property reads back as malformed. :pr:\u003ccode\u003e723\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eReject non-finite heartbeat, stale, and polling intervals in \u003ccode\u003eSoftReadWriteLock\u003c/code\u003e and \u003ccode\u003eAsyncSoftReadWriteLock\u003c/code\u003e,\nincluding cached singleton construction and overflow in the default stale threshold. :pr:\u003ccode\u003e724\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/20929f7d1439d5fa1df158fcac87b60815f5d422\"\u003e\u003ccode\u003e20929f7\u003c/code\u003e\u003c/a\u003e Release 3.32.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/35f07c48009c41faecfa7182939e5b7e1c78ae71\"\u003e\u003ccode\u003e35f07c4\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/736\"\u003e#736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e860d3905d369b4753de5759d1cd70d0ca639d1f\"\u003e\u003ccode\u003ee860d39\u003c/code\u003e\u003c/a\u003e 📝 docs: say acquire() falls back to the lock's blocking attribute (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/c530efec2ee5012eeaa742c196c3623d478888ba\"\u003e\u003ccode\u003ec530efe\u003c/code\u003e\u003c/a\u003e Fix final symlink test on musl (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/737\"\u003e#737\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d\"\u003e\u003ccode\u003e4efd93e\u003c/code\u003e\u003c/a\u003e Release 3.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1\"\u003e\u003ccode\u003e7b7b7a8\u003c/code\u003e\u003c/a\u003e Fix SoftReadWriteLock state lock timeout (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2\"\u003e\u003ccode\u003ef2f7b86\u003c/code\u003e\u003c/a\u003e fix: respect ACL write access when the owner write bit is absent (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153\"\u003e\u003ccode\u003ee947a69\u003c/code\u003e\u003c/a\u003e test(soft-rw): reuse existing test module (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88\"\u003e\u003ccode\u003eda3ae2b\u003c/code\u003e\u003c/a\u003e fix: preserve exception notes when copying and pickling (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812\"\u003e\u003ccode\u003eae9cb5b\u003c/code\u003e\u003c/a\u003e 🐛 fix(soft-rw): reject non-finite timing options (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tox-dev/py-filelock/compare/3.32.4...3.32.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fonttools` from 4.63.0 to 4.65.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fonttools/fonttools/releases\"\u003efonttools's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.65.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[glyf] Add \u003ccode\u003e__iter__\u003c/code\u003e, \u003ccode\u003eitems\u003c/code\u003e and \u003ccode\u003evalues\u003c/code\u003e methods to the \u003ccode\u003eglyf\u003c/code\u003e table to make it more dict-like (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4156\"\u003e#4156\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Escape the anonymous block tag when scanning for its terminator, so tags containing regex metacharacters are matched literally (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4167\"\u003e#4167\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib] Strip directory components from \u003ccode\u003e\u0026lt;variable-font name=\u0026quot;...\u0026quot;/\u0026gt;\u003c/code\u003e when deriving the output filename in the \u003ccode\u003evarLib\u003c/code\u003e command line, so a designspace cannot write outside the output directory (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4168\"\u003e#4168\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Fix tracking of the current script and language across redundant \u003ccode\u003escript\u003c/code\u003e statements. Rules following a \u003ccode\u003escript\u003c/code\u003e statement that names the first declared language system no longer end up under the \u003ccode\u003eDFLT\u003c/code\u003e script, and a \u003ccode\u003escript\u003c/code\u003e statement naming the already-current script still narrows the language systems and terminates the current lookup while leaving the \u003ccode\u003elookupflag\u003c/code\u003e alone, matching makeotf (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1824\"\u003e#1824\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/2522\"\u003e#2522\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4169\"\u003e#4169\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.interpolatable] Escape glyph names in the HTML report (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4172\"\u003e#4172\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[otlLib] Fix overflow handling when building contextual lookups: offset overflows now raise \u003ccode\u003eOTLOffsetOverflowError\u003c/code\u003e instead of \u003ccode\u003eAttributeError\u003c/code\u003e so another contextual format can be tried (regression from \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3439\"\u003e#3439\u003c/a\u003e). When all formats overflow, split the ruleset in halves until it fits (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4171\"\u003e#4171\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.64.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[feaLib] Fix name-table parsing for multibyte Mac encodings (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1196\"\u003e#1196\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4092\"\u003e#4092\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttProgram] Also indent TrueType assembly following \u003ccode\u003eIDEF[ ]\u003c/code\u003e, like function definitions (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4093\"\u003e#4093\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Keep East Asian spacing \u003ccode\u003epalt\u003c/code\u003e by default (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4094\"\u003e#4094\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Bug fix for MATH table in which constructions for glyphs that are only added during MATH closure were kept (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4096\"\u003e#4096\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ufoLib] Make glyph-to-group construction accessible outside of lookup function (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4102\"\u003e#4102\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[glyf] Use reverse glyph map for O(1) \u003ccode\u003e__setitem__\u003c/code\u003e membership (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4103\"\u003e#4103\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Fix \u003ccode\u003efixLookupOverFlows()\u003c/code\u003e reporting success when it had not promoted any lookup to Extension, masking unresolvable overflows.\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for TrueType Collection version 2 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4100\"\u003e#4100\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Pin a single head.modified timestamp across \u003ccode\u003eTTCollection.save\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4111\"\u003e#4111\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Give an actionable error when LookupList overflow is unrecoverable (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4109\"\u003e#4109\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for the AAT bitmap tables \u003ccode\u003ebhed\u003c/code\u003e, \u003ccode\u003ebdat\u003c/code\u003e, \u003ccode\u003ebloc\u003c/code\u003e, variants of \u003ccode\u003ehead\u003c/code\u003e, \u003ccode\u003eEBDT\u003c/code\u003e, \u003ccode\u003eEBLC\u003c/code\u003e used in legacy Apple bitmap-only fonts (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4115\"\u003e#4115\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Check \u003ccode\u003eOS/2\u003c/code\u003e fsSelection/macStyle consistency against \u003ccode\u003ebhed\u003c/code\u003e as well as \u003ccode\u003ehead\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4118\"\u003e#4118\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4119\"\u003e#4119\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.roundTools] Add types and documentation (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4123\"\u003e#4123\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Instance the \u003ccode\u003eBASE\u003c/code\u003e table (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4137\"\u003e#4137\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Fix Private-dict \u003ccode\u003evsindex\u003c/code\u003e handling in \u003ccode\u003einstantiateCFF2\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4129\"\u003e#4129\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4132\"\u003e#4132\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Fix crash instancing CFF2 fonts without a VariationStore (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4130\"\u003e#4130\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4131\"\u003e#4131\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[sfnt] Raise \u003ccode\u003eTTLibError\u003c/code\u003e instead of \u003ccode\u003eAssertionError\u003c/code\u003e or \u003ccode\u003estruct.error\u003c/code\u003e when reading a font truncated within the table directory or a table entry (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4147\"\u003e#4147\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4149\"\u003e#4149\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.xmlWriter] Escape the \u003ccode\u003e]]\u0026gt;\u003c/code\u003e terminator inside CDATA sections, so an SVG document containing it can no longer smuggle markup past a TTX round trip (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4139\"\u003e#4139\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Implement avar2 partial-instancing: the avar version 2 ItemVariationStore is adjusted so that remaining axes behave the same after limiting the designspace (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4045\"\u003e#4045\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Add shorthand for the value at the default location in a variable scalar: \u003ccode\u003e(100 wght=900:120)\u003c/code\u003e means \u003ccode\u003e(wght=400:100 wght=900:120)\u003c/code\u003e when the wght default is 400 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4024\"\u003e#4024\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[cmap] Raise \u003ccode\u003eTTLibError\u003c/code\u003e for a truncated or out-of-bounds cmap subtable header (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4151\"\u003e#4151\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[designspaceLib] Reject conflicting duplicate inputs in axis maps instead of silently keeping the last one (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4153\"\u003e#4153\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[designspaceLib] Read an empty \u003ccode\u003e\u0026lt;lib\u0026gt;\u003c/code\u003e element as an empty lib instead of raising \u003ccode\u003eIndexError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4142\"\u003e#4142\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4144\"\u003e#4144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[colorLib] Raise a legible error when a COLRv0 layer, or a COLRv1 PaintGlyph or PaintColrGlyph, references a glyph missing from the glyphMap, instead of failing obscurely later (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/2629\"\u003e#2629\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4141\"\u003e#4141\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[cmap] Don't drop subtables in unsupported formats when compiling or dumping a font read from binary (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4136\"\u003e#4136\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Implement \u003ccode\u003esplitSinglePos\u003c/code\u003e so GPOS lookup type 1 offset overflows can be recovered by splitting the subtable (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4091\"\u003e#4091\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4108\"\u003e#4108\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[cmap] Round-trip empty Macintosh format 2 subtables (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3663\"\u003e#3663\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4117\"\u003e#4117\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[glyf] Raise \u003ccode\u003eTTLibError\u003c/code\u003e instead of \u003ccode\u003eRecursionError\u003c/code\u003e when \u003ccode\u003erecalcBounds()\u003c/code\u003e hits a composite-component reference cycle (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3899\"\u003e#3899\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4116\"\u003e#4116\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[svgLib] Fix crash parsing an SVG path with consecutive closepath commands (\u003ccode\u003eZ Z\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4122\"\u003e#4122\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Fix \u003ccode\u003eDefaultTable\u003c/code\u003e type annotations (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4126\"\u003e#4126\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for the \u003ccode\u003eEBSC\u003c/code\u003e (Embedded Bitmap Scaling) table (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4113\"\u003e#4113\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[svgLib] Suppress spurious close segments caused by floating-point drift in relative path commands (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3860\"\u003e#3860\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4127\"\u003e#4127\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[qu2cu] Fix \u003ccode\u003eTypeError\u003c/code\u003e in the Cython-compiled build when \u003ccode\u003eQu2CuPen\u003c/code\u003e passes tuple splines (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4160\"\u003e#4160\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[mort] Add semantic decompilation, TTX, and compilation support for rearrangement, contextual-substitution, ligature, and insertion subtables (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4158\"\u003e#4158\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4159\"\u003e#4159\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4161\"\u003e#4161\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[svgLib] Start a new subpath at the just-closed subpath's initial point when a drawto command follows a closepath, per SVG spec (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4154\"\u003e#4154\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4155\"\u003e#4155\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.filesystem] \u003cstrong\u003eSECURITY\u003c/strong\u003e Reject paths that resolve outside the filesystem root: a malicious UFO could read arbitrary files via \u003ccode\u003e..\u003c/code\u003e components in \u003ccode\u003econtents.plist\u003c/code\u003e, and a crafted \u003ccode\u003e.ufoz\u003c/code\u003e could create files outside its temporary mirror (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4124\"\u003e#4124\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] \u003cstrong\u003eSECURITY\u003c/strong\u003e Sanitise glyph names used as filenames in EBDT/CBDT \u003ccode\u003ettx -z extfile\u003c/code\u003e export, preventing arbitrary file writes from untrusted fonts (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4128\"\u003e#4128\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.etree] \u003cstrong\u003eSECURITY\u003c/strong\u003e Don't resolve external XML entities in \u003ccode\u003eXMLParser\u003c/code\u003e when lxml is used, preventing XXE file disclosure on lxml \u0026lt; 5.0 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4145\"\u003e#4145\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Fully prune \u003ccode\u003eVARC\u003c/code\u003e auxiliary data: collect and remap variation indices referenced by condition tables when subsetting the \u003ccode\u003eMultiVarStore\u003c/code\u003e, and drop the \u003ccode\u003eAxisIndicesList\u003c/code\u003e, \u003ccode\u003eConditionList\u003c/code\u003e, and \u003ccode\u003eMultiVarStore\u003c/code\u003e when they end up empty (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4162\"\u003e#4162\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fonttools/fonttools/blob/main/NEWS.rst\"\u003efonttools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.65.0 (released 2026-09-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[glyf] Add \u003ccode\u003e__iter__\u003c/code\u003e, \u003ccode\u003eitems\u003c/code\u003e and \u003ccode\u003evalues\u003c/code\u003e methods to the \u003ccode\u003eglyf\u003c/code\u003e table\nto make it more dict-like (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4156\"\u003e#4156\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Escape the anonymous block tag when scanning for its terminator, so tags\ncontaining regex metacharacters are matched literally (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4167\"\u003e#4167\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib] Strip directory components from \u003ccode\u003e\u0026lt;variable-font name=\u0026quot;...\u0026quot;/\u0026gt;\u003c/code\u003e when\nderiving the output filename in the \u003ccode\u003evarLib\u003c/code\u003e command line, so a designspace\ncannot write outside the output directory (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4168\"\u003e#4168\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Fix tracking of the current script and language across redundant\n\u003ccode\u003escript\u003c/code\u003e statements. Rules following a \u003ccode\u003escript\u003c/code\u003e statement that names the\nfirst declared language system no longer end up under the \u003ccode\u003eDFLT\u003c/code\u003e script, and\na \u003ccode\u003escript\u003c/code\u003e statement naming the already-current script still narrows the\nlanguage systems and terminates the current lookup while leaving the\n\u003ccode\u003elookupflag\u003c/code\u003e alone, matching makeotf (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1824\"\u003e#1824\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/2522\"\u003e#2522\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4169\"\u003e#4169\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.interpolatable] Escape glyph names in the HTML report (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4172\"\u003e#4172\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[otlLib] Fix overflow handling when building contextual lookups: offset overflows\nnow raise \u003ccode\u003eOTLOffsetOverflowError\u003c/code\u003e instead of \u003ccode\u003eAttributeError\u003c/code\u003e so another\ncontextual format can be tried (regression from \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3439\"\u003e#3439\u003c/a\u003e). When all formats\noverflow, split the ruleset in halves until it fits (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4171\"\u003e#4171\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.64.0 (released 2026-08-31)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[feaLib] Fix name-table parsing for multibyte Mac encodings (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1196\"\u003e#1196\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4092\"\u003e#4092\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttProgram] Also indent TrueType assembly following \u003ccode\u003eIDEF[ ]\u003c/code\u003e, like function\ndefinitions (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4093\"\u003e#4093\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Keep East Asian spacing \u003ccode\u003epalt\u003c/code\u003e by default (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4094\"\u003e#4094\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Bug fix for MATH table in which constructions for glyphs that are only\nadded during MATH closure were kept (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4096\"\u003e#4096\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ufoLib] Make glyph-to-group construction accessible outside of lookup function\n(\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4102\"\u003e#4102\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[glyf] Use reverse glyph map for O(1) \u003ccode\u003e__setitem__\u003c/code\u003e membership (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4103\"\u003e#4103\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Fix \u003ccode\u003efixLookupOverFlows()\u003c/code\u003e reporting success when it had not promoted\nany lookup to Extension, masking unresolvable overflows.\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for TrueType Collection version 2 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4100\"\u003e#4100\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Pin a single head.modified timestamp across \u003ccode\u003eTTCollection.save\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4111\"\u003e#4111\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Give an actionable error when LookupList overflow is unrecoverable (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4109\"\u003e#4109\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for the AAT bitmap tables \u003ccode\u003ebhed\u003c/code\u003e, \u003ccode\u003ebdat\u003c/code\u003e, \u003ccode\u003ebloc\u003c/code\u003e,\nvariants of \u003ccode\u003ehead\u003c/code\u003e, \u003ccode\u003eEBDT\u003c/code\u003e, \u003ccode\u003eEBLC\u003c/code\u003e used in legacy Apple bitmap-only fonts\n(\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4115\"\u003e#4115\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Check \u003ccode\u003eOS/2\u003c/code\u003e fsSelection/macStyle consistency against \u003ccode\u003ebhed\u003c/code...\n\n_Description has been truncated_","html_url":"https://github.com/ncoevoet/facet/pull/155","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ncoevoet%2Ffacet/issues/155","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/155/packages"},{"uuid":"5536027477","node_id":"PR_kwDONC03Hc8AAAABEiBuuw","number":4260,"state":"open","title":"build(deps): bump the python group with 85 updates","user":"dependabot[bot]","labels":["backport:skip","dependencies","python:uv","first-time-contributor"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T06:23:30.000Z","updated_at":"2026-09-22T06:33:34.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"python","update_count":85,"packages":[{"name":"pin-pink","old_version":"4.3.0","new_version":"4.4.0","repository_url":"https://github.com/stephane-caron/pink"},{"name":"reactivex","old_version":"4.1.0","new_version":"5.1.0","repository_url":"https://github.com/ReactiveX/RxPY"},{"name":"pydantic","old_version":"2.12.5","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"packaging","old_version":"25.0","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"filelock","old_version":"3.23.0","new_version":"3.32.6","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"plum-dispatch","old_version":"2.5.7","new_version":"2.10.1","repository_url":"https://github.com/beartype/plum"},{"name":"gitpython","old_version":"3.1.52","new_version":"3.1.62","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"structlog","old_version":"25.5.0","new_version":"26.1.0","repository_url":"https://github.com/hynek/structlog"},{"name":"opencv-contrib-python","old_version":"4.13.0.92","new_version":"5.0.0.93","repository_url":"https://github.com/opencv/opencv-python"},{"name":"pydantic-settings","old_version":"2.12.0","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"textual","old_version":"3.7.1","new_version":"8.2.8","repository_url":"https://github.com/Textualize/textual"},{"name":"terminaltexteffects","old_version":"0.12.2","new_version":"0.15.0","repository_url":"https://github.com/ChrisBuilds/terminaltexteffects"},{"name":"typer","old_version":"0.23.1","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"ipython","old_version":"8.38.0","new_version":"8.39.0","repository_url":"https://github.com/ipython/ipython"},{"name":"plotext","old_version":"5.3.2","new_version":"6.1.0","repository_url":"https://github.com/piccolomo/plotext"},{"name":"numba","old_version":"0.63.1","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"llvmlite","old_version":"0.46.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"rerun-sdk","old_version":"0.32.0","new_version":"0.37.2","repository_url":"https://github.com/rerun-io/rerun"},{"name":"protobuf","old_version":"6.33.5","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"ipykernel","old_version":"7.2.0","new_version":"7.3.0","repository_url":"https://github.com/ipython/ipykernel"},{"name":"open-clip-torch","old_version":"3.2.0","new_version":"3.3.0","repository_url":"https://github.com/mlfoundations/open_clip"},{"name":"gdown","old_version":"6.0.0","new_version":"6.2.0","repository_url":"https://github.com/wkentaro/gdown"},{"name":"tensorboard","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/tensorflow/tensorboard"},{"name":"portal","old_version":"3.7.4","new_version":"3.8.1","repository_url":"https://github.com/danijar/portal"},{"name":"bosdyn-client","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-api","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-core","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"pyarrow","old_version":"23.0.0","new_version":"25.0.1","repository_url":"https://github.com/apache/arrow"},{"name":"langchain-core","old_version":"1.3.3","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-openai","old_version":"1.1.6","new_version":"1.6.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-huggingface","old_version":"1.2.0","new_version":"1.2.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-ollama","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"ollama","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/ollama/ollama-python"},{"name":"openai","old_version":"2.21.0","new_version":"3.14.0","repository_url":"https://github.com/openai/openai-python"},{"name":"sounddevice","old_version":"0.5.5","new_version":"0.5.6","repository_url":"https://github.com/spatialaudio/python-sounddevice"},{"name":"fastapi","old_version":"0.129.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"python-socketio","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/sponsors/miguelgrinberg"},{"name":"python-multipart","old_version":"0.0.27","new_version":"0.0.32","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"sse-starlette","old_version":"3.2.0","new_version":"3.4.11","repository_url":"https://github.com/sysid/sse-starlette"},{"name":"uvicorn","old_version":"0.40.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"soundfile","old_version":"0.13.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"timm","old_version":"1.0.24","new_version":"1.0.29","repository_url":"https://github.com/huggingface/pytorch-image-models"},{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"lap","old_version":"0.5.12","new_version":"0.5.13","repository_url":"https://github.com/gatagat/lap"},{"name":"transformers","old_version":"4.53.3","new_version":"5.17.0"},{"name":"moondream","old_version":"0.2.0","new_version":"2.3.0","repository_url":"https://github.com/vikhyat/moondream"},{"name":"omegaconf","old_version":"2.3.0","new_version":"2.3.1","repository_url":"https://github.com/omry/omegaconf"},{"name":"hydra-core","old_version":"1.3.2","new_version":"1.3.7","repository_url":"https://github.com/facebookresearch/hydra"},{"name":"unitree-webrtc-connect","old_version":"2.1.2","new_version":"2.2.0","repository_url":"https://github.com/legion1581/unitree_webrtc_connect"},{"name":"cyclonedds","old_version":"0.10.5","new_version":"11.0.1","repository_url":"https://github.com/eclipse-cyclonedds/cyclonedds-python"},{"name":"mcap","old_version":"1.3.1","new_version":"1.4.0","repository_url":"https://github.com/foxglove/mcap"},{"name":"piper-sdk","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/agilexrobotics/piper_sdk"},{"name":"xarm-python-sdk","old_version":"1.17.3","new_version":"1.18.4","repository_url":"https://github.com/xArm-Developer/xArm-Python-SDK"},{"name":"roboplan","old_version":"0.6.0","new_version":"0.6.1","repository_url":"https://github.com/open-planning/roboplan"},{"name":"matplotlib","old_version":"3.10.8","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"cupy-cuda12x","old_version":"13.6.0","new_version":"14.2.0","repository_url":"https://github.com/cupy/cupy"},{"name":"mujoco","old_version":"3.10.0","new_version":"3.13.0","repository_url":"https://github.com/google-deepmind/mujoco"},{"name":"gtsam-extended","old_version":"4.3a1.post1","new_version":"4.3a2.post202608240418"},{"name":"aiortc","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/aiortc/aiortc"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"reportlab","old_version":"4.5.0","new_version":"5.0.1"},{"name":"manifold3d","old_version":"3.5.1","new_version":"3.5.3","repository_url":"https://github.com/elalish/manifold"},{"name":"coacd","old_version":"1.0.11","new_version":"1.0.14","repository_url":"https://github.com/SarahWeiii/CoACD"},{"name":"usd-core","old_version":"26.5","new_version":"26.8","repository_url":"https://github.com/PixarAnimationStudios/OpenUSD"},{"name":"ruff","old_version":"0.14.3","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"},{"name":"pytest","old_version":"8.3.5","new_version":"9.1.1","repository_url":"https://github.com/pytest-dev/pytest"},{"name":"pytest-mock","old_version":"3.15.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-env","old_version":"1.1.5","new_version":"1.7.1","repository_url":"https://github.com/pytest-dev/pytest-env"},{"name":"pytest-rerunfailures","old_version":"16.4","new_version":"16.6.1","repository_url":"https://github.com/pytest-dev/pytest-rerunfailures"},{"name":"coverage","old_version":"7.13.4","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"pre-commit","old_version":"4.2.0","new_version":"4.6.2","repository_url":"https://github.com/pre-commit/pre-commit"},{"name":"py-spy","old_version":"0.4.1","new_version":"0.4.2","repository_url":"https://github.com/benfred/py-spy"},{"name":"maturin","old_version":"1.13.3","new_version":"1.15.0","repository_url":"https://github.com/pyo3/maturin"},{"name":"python-lsp-server","old_version":"1.14.0","new_version":"1.15.0"},{"name":"python-lsp-ruff","old_version":"2.3.0","new_version":"2.3.4","repository_url":"https://github.com/python-lsp/python-lsp-ruff"},{"name":"playwright","old_version":"1.61.0","new_version":"1.62.0","repository_url":"https://github.com/microsoft/playwright-python"},{"name":"mypy","old_version":"1.19.0","new_version":"2.3.1","repository_url":"https://github.com/python/mypy"},{"name":"types-pyyaml","old_version":"6.0.12.20250915","new_version":"6.0.12.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"types-reportlab","old_version":"4.5.0.20260509","new_version":"5.0.0.20260911","repository_url":"https://github.com/python/typeshed"},{"name":"types-requests","old_version":"2.32.4.20260107","new_version":"2.33.0.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"pybind11","old_version":"3.0.4","new_version":"3.1.0","repository_url":"https://github.com/pybind/pybind11"},{"name":"optuna","old_version":"4.9.0","new_version":"5.0.0","repository_url":"https://github.com/optuna/optuna"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python group with 85 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pin-pink](https://github.com/stephane-caron/pink) | `4.3.0` | `4.4.0` |\n| [reactivex](https://github.com/ReactiveX/RxPY) | `4.1.0` | `5.1.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [packaging](https://github.com/pypa/packaging) | `25.0` | `26.3` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.23.0` | `3.32.6` |\n| [plum-dispatch](https://github.com/beartype/plum) | `2.5.7` | `2.10.1` |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.52` | `3.1.62` |\n| [structlog](https://github.com/hynek/structlog) | `25.5.0` | `26.1.0` |\n| [opencv-contrib-python](https://github.com/opencv/opencv-python) | `4.13.0.92` | `5.0.0.93` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.12.0` | `2.15.0` |\n| [textual](https://github.com/Textualize/textual) | `3.7.1` | `8.2.8` |\n| [terminaltexteffects](https://github.com/ChrisBuilds/terminaltexteffects) | `0.12.2` | `0.15.0` |\n| [typer](https://github.com/fastapi/typer) | `0.23.1` | `0.27.2` |\n| [ipython](https://github.com/ipython/ipython) | `8.38.0` | `8.39.0` |\n| [plotext](https://github.com/piccolomo/plotext) | `5.3.2` | `6.1.0` |\n| [numba](https://github.com/numba/numba) | `0.63.1` | `0.67.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.46.0` | `0.49.0` |\n| [rerun-sdk](https://github.com/rerun-io/rerun) | `0.32.0` | `0.37.2` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `6.33.5` | `7.36.1` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.1` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [ipykernel](https://github.com/ipython/ipykernel) | `7.2.0` | `7.3.0` |\n| [open-clip-torch](https://github.com/mlfoundations/open_clip) | `3.2.0` | `3.3.0` |\n| [gdown](https://github.com/wkentaro/gdown) | `6.0.0` | `6.2.0` |\n| [tensorboard](https://github.com/tensorflow/tensorboard) | `2.20.0` | `2.21.0` |\n| [portal](https://github.com/danijar/portal) | `3.7.4` | `3.8.1` |\n| [bosdyn-client](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-api](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-core](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [pyarrow](https://github.com/apache/arrow) | `23.0.0` | `25.0.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.3.3` | `1.6.3` |\n| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.6` | `1.6.2` |\n| [langchain-huggingface](https://github.com/langchain-ai/langchain) | `1.2.0` | `1.2.2` |\n| [langchain-ollama](https://github.com/langchain-ai/langchain) | `1.0.1` | `1.1.0` |\n| [ollama](https://github.com/ollama/ollama-python) | `0.6.1` | `0.6.2` |\n| [openai](https://github.com/openai/openai-python) | `2.21.0` | `3.14.0` |\n| [sounddevice](https://github.com/spatialaudio/python-sounddevice) | `0.5.5` | `0.5.6` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.129.0` | `0.141.1` |\n| [python-socketio](https://github.com/sponsors/miguelgrinberg) | `5.16.1` | `5.17.0` |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.27` | `0.0.32` |\n| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.2.0` | `3.4.11` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.53.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.13.1` | `0.14.0` |\n| [timm](https://github.com/huggingface/pytorch-image-models) | `1.0.24` | `1.0.29` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.2.0` | `12.3.0` |\n| [lap](https://github.com/gatagat/lap) | `0.5.12` | `0.5.13` |\n| [transformers[torch]](https://github.com/huggingface/transformers) | `4.53.3` | `5.17.0` |\n| [moondream](https://github.com/vikhyat/moondream) | `0.2.0` | `2.3.0` |\n| [omegaconf](https://github.com/omry/omegaconf) | `2.3.0` | `2.3.1` |\n| [hydra-core](https://github.com/facebookresearch/hydra) | `1.3.2` | `1.3.7` |\n| [unitree-webrtc-connect](https://github.com/legion1581/unitree_webrtc_connect) | `2.1.2` | `2.2.0` |\n| [cyclonedds](https://github.com/eclipse-cyclonedds/cyclonedds-python) | `0.10.5` | `11.0.1` |\n| [mcap](https://github.com/foxglove/mcap) | `1.3.1` | `1.4.0` |\n| [piper-sdk](https://github.com/agilexrobotics/piper_sdk) | `0.6.1` | `0.6.2` |\n| [xarm-python-sdk](https://github.com/xArm-Developer/xArm-Python-SDK) | `1.17.3` | `1.18.4` |\n| [roboplan](https://github.com/open-planning/roboplan) | `0.6.0` | `0.6.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.10.8` | `3.10.9` |\n| [cupy-cuda12x](https://github.com/cupy/cupy) | `13.6.0` | `14.2.0` |\n| [mujoco](https://github.com/google-deepmind/mujoco) | `3.10.0` | `3.13.0` |\n| [gtsam-extended](https://gtsam.org/) | `4.3a1.post1` | `4.3a2.post202608240418` |\n| [aiortc](https://github.com/aiortc/aiortc) | `1.14.0` | `1.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [reportlab](https://www.reportlab.com/) | `4.5.0` | `5.0.1` |\n| [manifold3d](https://github.com/elalish/manifold) | `3.5.1` | `3.5.3` |\n| [coacd](https://github.com/SarahWeiii/CoACD) | `1.0.11` | `1.0.14` |\n| [usd-core](https://github.com/PixarAnimationStudios/OpenUSD) | `26.5` | `26.8` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.14.3` | `0.16.7` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.3.5` | `9.1.1` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.0` | `3.15.1` |\n| [pytest-env](https://github.com/pytest-dev/pytest-env) | `1.1.5` | `1.7.1` |\n| [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.4` | `16.6.1` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.13.4` | `7.16.1` |\n| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.2.0` | `4.6.2` |\n| [py-spy](https://github.com/benfred/py-spy) | `0.4.1` | `0.4.2` |\n| [maturin](https://github.com/pyo3/maturin) | `1.13.3` | `1.15.0` |\n| [python-lsp-server[all]](https://github.com/python-lsp/python-lsp-server) | `1.14.0` | `1.15.0` |\n| [python-lsp-ruff](https://github.com/python-lsp/python-lsp-ruff) | `2.3.0` | `2.3.4` |\n| [playwright](https://github.com/microsoft/playwright-python) | `1.61.0` | `1.62.0` |\n| [mypy](https://github.com/python/mypy) | `1.19.0` | `2.3.1` |\n| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20250915` | `6.0.12.20260906` |\n| [types-reportlab](https://github.com/python/typeshed) | `4.5.0.20260509` | `5.0.0.20260911` |\n| [types-requests](https://github.com/python/typeshed) | `2.32.4.20260107` | `2.33.0.20260906` |\n| [pybind11](https://github.com/pybind/pybind11) | `3.0.4` | `3.1.0` |\n| [optuna](https://github.com/optuna/optuna) | `4.9.0` | `5.0.0` |\n\nUpdates `pin-pink` from 4.3.0 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/stephane-caron/pink/releases\"\u003epin-pink's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cp\u003eThis release allows custom boundaries in velocity limits, allowing bounds on joints that can't have a limit from their URDF model (such as continuous joints).\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pink-kinematics/pink/blob/main/CHANGELOG.md\"\u003epin-pink's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.4.0] - 2026-09-09\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/c14d0ae62f4fb744bbe84e35f9e16f1b680b20c0\"\u003e\u003ccode\u003ec14d0ae\u003c/code\u003e\u003c/a\u003e Release v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/5c890570ee42d397f03d1cf8e1b8f4a9797bde97\"\u003e\u003ccode\u003e5c89057\u003c/code\u003e\u003c/a\u003e doc: Add context to configuration limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/7df4f5a323c423b591ff3c35c7e66df40ff9c197\"\u003e\u003ccode\u003e7df4f5a\u003c/code\u003e\u003c/a\u003e Update link to CBF note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/bfd30c7aec222b66fb36629c20439bedb223d161\"\u003e\u003ccode\u003ebfd30c7\u003c/code\u003e\u003c/a\u003e lint: Apply pylint recos in FrameTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/e71a42bd424680b039b782de1392b0b7ec2307d9\"\u003e\u003ccode\u003ee71a42b\u003c/code\u003e\u003c/a\u003e lint: Fix pylint recos in ManipulabilityTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/a7ac5aa23b591fc203fbdc636d88c1a9b410375c\"\u003e\u003ccode\u003ea7ac5aa\u003c/code\u003e\u003c/a\u003e pixi: Group linting tasks, add format task\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/771c0e0a5d80107771525321927eebb28fbc3400\"\u003e\u003ccode\u003e771c0e0\u003c/code\u003e\u003c/a\u003e lint: Fix two pylint errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/f568e80536549a3b7f627468eb29526d3404c85b\"\u003e\u003ccode\u003ef568e80\u003c/code\u003e\u003c/a\u003e Update type of velocity_limit attribute\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/232c9c0b76db644c212c1e9caa33bda345cb4dd2\"\u003e\u003ccode\u003e232c9c0\u003c/code\u003e\u003c/a\u003e minor: Removed comes before Fixed in Keep a Changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/3b60614b5f25ed8c1ed0f1fc596ec19133665035\"\u003e\u003ccode\u003e3b60614\u003c/code\u003e\u003c/a\u003e Update the changelog\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/stephane-caron/pink/compare/v4.3.0...v4.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `reactivex` from 4.1.0 to 5.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/releases\"\u003ereactivex's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.1.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0rc2\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0a2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix title header by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/744\"\u003eReactiveX/RxPY#744\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0a1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGive run a scheduler parameter by \u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid use of asyncio.get_event_loop (3.14) by \u003ca href=\"https://github.com/traylenator\"\u003e\u003ccode\u003e@​traylenator\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/728\"\u003eReactiveX/RxPY#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to uv by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/738\"\u003eReactiveX/RxPY#738\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to ruff by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/739\"\u003eReactiveX/RxPY#739\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade pyright by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/740\"\u003eReactiveX/RxPY#740\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix subscribe_on not forwarding scheduler to the source  by \u003ca href=\"https://github.com/jcafhe\"\u003e\u003ccode\u003e@​jcafhe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/726\"\u003eReactiveX/RxPY#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade deps by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/741\"\u003eReactiveX/RxPY#741\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify what you can do with the .subscribe Disposable by \u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRxPY v5 by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/743\"\u003eReactiveX/RxPY#743\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003ereactivex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.1.0 - 2026-07-27\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Add tap as an alias for do_action (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/804\"\u003e#804\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/95c54ac3652aed2bf78035c9846cb5867ee58172\"\u003e95c54ac3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(gtk)\u003c/em\u003e Call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e2b9e3f33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Accept concurrent.futures.Future wherever futures are accepted (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/806\"\u003e#806\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e19da6ac1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(scheduler)\u003c/em\u003e Use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e361951c7\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd..b286407307ace6670f6f0072a8438bc912165d43\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(scripts)\u003c/em\u003e Keep uv.lock in sync and scope the version sed to [project] (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/802\"\u003e#802\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003e10ccc0a3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/915311e3e002b933f2eb4d59c9eac1cab327ff78..10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.2 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Reset retry budget per subscription to fix retry+repeat (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/765\"\u003e#765\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/c3f19d5e83403f70d44331daf0b5a86d410f76d4\"\u003ec3f19d5e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/2975deb528c9eec73c76cf8bb53fc8780f31de45..915311e3e002b933f2eb4d59c9eac1cab327ff78\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.1 - 2026-04-20\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/8b59bc7394f1b6a8a78e2fc4b5efe200d4f47f89..2975deb528c9eec73c76cf8bb53fc8780f31de45\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Added \u003ccode\u003eAction\u003c/code\u003e and \u003ccode\u003eStartableFactory\u003c/code\u003e to \u003ccode\u003ereactivex.typing.__all__\u003c/code\u003e,\nmaking them part of the explicit public API surface.\u003c/li\u003e\n\u003cli\u003eDocs: Added missing docstring to \u003ccode\u003eon_error_resume_next\u003c/code\u003e operator.\u003c/li\u003e\n\u003cli\u003eOperators: Fixed scheduler forwarding in \u003ccode\u003epairwise\u003c/code\u003e, \u003ccode\u003eto_marbles\u003c/code\u003e, and\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e (subscription-delay path). These operators now pass the\n\u003ccode\u003escheduler\u003c/code\u003e argument through to \u003ccode\u003esource.subscribe(...)\u003c/code\u003e and, in the case of\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e, to the subscription-delay observable, consistent with\nall other pipeable operators. Closes \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/480\"\u003e#480\u003c/a\u003e (partial — the operators listed\nin the issue that were not yet fixed).\u003c/li\u003e\n\u003cli\u003eCI: Skip \u003ccode\u003etests/test_scheduler/test_mainloop/test_tkinterscheduler.py\u003c/code\u003e on\nPyPy (all platforms). The module creates a Tk root at import time; PyPy's\n\u003ccode\u003e_tkinter\u003c/code\u003e finalizer calls \u003ccode\u003ethreading.notify_all\u003c/code\u003e during interpreter\nshutdown and aborts the xdist worker, failing whichever unrelated test\nwas running. Previously guarded only on macOS+PyPy.\u003c/li\u003e\n\u003cli\u003eFix: \u003ccode\u003ereactivex.timer(duetime, period)\u003c/code\u003e now correctly resets the initial\ndelay on each resubscription (e.g. via \u003ccode\u003erepeat()\u003c/code\u003e). Previously `nonlocal\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/bbfecfbf83605f2bb2beb8b887dfe5b5fb322a67\"\u003e\u003ccode\u003ebbfecfb\u003c/code\u003e\u003c/a\u003e chore: release reactivex@5.1.0 (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/805\"\u003e#805\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b286407307ace6670f6f0072a8438bc912165d43\"\u003e\u003ccode\u003eb286407\u003c/code\u003e\u003c/a\u003e docs: correct and expand the GIL free-threading note (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/811\"\u003e#811\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/93a4f0417fe5d1d187dbd2d0dfdf2ef3b481c45c\"\u003e\u003ccode\u003e93a4f04\u003c/code\u003e\u003c/a\u003e docs: explain how to parallelize work within a single stream (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/810\"\u003e#810\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2271867415d4beaed62e6f0441fd3312e47079aa\"\u003e\u003ccode\u003e2271867\u003c/code\u003e\u003c/a\u003e Revise GIL section for Python 3.13 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/742\"\u003e#742\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e\u003ccode\u003e361951c\u003c/code\u003e\u003c/a\u003e fix(scheduler): use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b809222be63e235f439f65794dd1d4291556d072\"\u003e\u003ccode\u003eb809222\u003c/code\u003e\u003c/a\u003e docs: read version from pyproject instead of git tags (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/808\"\u003e#808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19e808000610335b4f6d0e0c739b59372b8b5a5f\"\u003e\u003ccode\u003e19e8080\u003c/code\u003e\u003c/a\u003e ci(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/807\"\u003e#807\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/dd9b8ec0185ade72dcb3aac983cd495f21ca0a6d\"\u003e\u003ccode\u003edd9b8ec\u003c/code\u003e\u003c/a\u003e refactor(combine-latest): simplify logic by removing redundant loops … (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/736\"\u003e#736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e\u003ccode\u003e19da6ac\u003c/code\u003e\u003c/a\u003e fix(operators): accept concurrent.futures.Future wherever futures are accepte...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e\u003ccode\u003e2b9e3f3\u003c/code\u003e\u003c/a\u003e fix(gtk): call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.12.5 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 2026-05-06\u003c/h2\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.3 2026-04-20\u003c/h2\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.2 2026-04-17\u003c/h2\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.1 2026-04-15\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.4\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.3\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.2\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.1 (2026-04-15)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.12.5...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `packaging` from 25.0 to 26.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/releases\"\u003epackaging's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e26.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd a public \u003ccode\u003eVersionRange\u003c/code\u003e API and \u003ccode\u003eSpecifierSet.to_range()\u003c/code\u003e, representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. \u003ccode\u003eVersionRange.to_specifier_set()\u003c/code\u003e converts a range back to a \u003ccode\u003eSpecifierSet\u003c/code\u003e where a PEP 440 form exists. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1267\"\u003e#1267\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1270\"\u003e#1270\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1194\"\u003e#1194\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1220\"\u003e#1220\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer source distributions over wheels for selected packages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1334\"\u003e#1334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epure_python_tags()\u003c/code\u003e to generate the pure-Python tags for a Python version without touching the running platform. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eSpecifierSet.is_subset()\u003c/code\u003e, \u003ccode\u003eSpecifierSet.is_superset()\u003c/code\u003e, and \u003ccode\u003eSpecifierSet.is_disjoint()\u003c/code\u003e, which compare the versions two specifier sets accept. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1313\"\u003e#1313\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior adaptations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1157\"\u003e#1157\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e tags on Linux. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for versions and specifiers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a non-string. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1319\"\u003e#1319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to \u003ccode\u003eVersion.from_parts\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1241\"\u003e#1241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1242\"\u003e#1242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary intersections. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1257\"\u003e#1257\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for requirements and markers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for trailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and \u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in sets and dicts. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1232\"\u003e#1232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize requested extra names before comparing or hashing requirements. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/644\"\u003e#644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve a \u003ccode\u003eRequirement\u003c/code\u003e's specifier \u003ccode\u003eprereleases\u003c/code\u003e override across a pickle round trip. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1204\"\u003e#1204\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of \u003ccode\u003eInvalidSpecifier\u003c/code\u003e when a requirement contains an invalid specifier. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1332\"\u003e#1332\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eClarify the error for post-release prefix wildcards like \u003ccode\u003e==1.0.post1.*\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1299\"\u003e#1299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the parentheses of a nested group when serializing markers. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1316\"\u003e#1316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize \u003ccode\u003eextra\u003c/code\u003e and \u003ccode\u003edependency_groups\u003c/code\u003e values in nested markers at parse time. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1246\"\u003e#1246\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1310\"\u003e#1310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedComparison\u003c/code\u003e when a set-valued variable like \u003ccode\u003eextras\u003c/code\u003e is used outside the membership form. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedEnvironmentName\u003c/code\u003e (a \u003ccode\u003eKeyError\u003c/code\u003e subclass) for missing environment keys during marker evaluation. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1276\"\u003e#1276\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWrap malformed string literal errors in \u003ccode\u003eInvalidMarker\u003c/code\u003e / \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of leaking a low-level error. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1249\"\u003e#1249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject requirements and markers with a trailing line break. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1345\"\u003e#1345\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for metadata and licenses\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCollect all \u003ccode\u003efrom_email\u003c/code\u003e validation errors into one \u003ccode\u003eExceptionGroup\u003c/code\u003e instead of raising the first. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1268\"\u003e#1268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAccept the UTF-8 charset case-insensitively in email payloads. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1330\"\u003e#1330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject malformed \u003ccode\u003eDescription-Content-Type\u003c/code\u003e values. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1329\"\u003e#1329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't rewrite user values that contain \u003ccode\u003e{field}\u003c/code\u003e placeholders in error messages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1327\"\u003e#1327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRoute multipart email payloads to \u003ccode\u003eunparsed\u003c/code\u003e instead of asserting. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1247\"\u003e#1247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMake \u003ccode\u003eInvalidMetadata\u003c/code\u003e and \u003ccode\u003eCyclicDependencyGroup\u003c/code\u003e picklable. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1328\"\u003e#1328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFold every line boundary \u003ccode\u003estr.splitlines\u003c/code\u003e recognizes when writing a header with \u003ccode\u003eRFC822Message\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/blob/main/CHANGELOG.rst\"\u003epackaging's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e26.3 - 2026-08-03\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nFeatures:\n\u003cul\u003e\n\u003cli\u003eAdd a public :class:\u003ccode\u003e~packaging.ranges.VersionRange\u003c/code\u003e API and\u003cbr /\u003e\n:meth:\u003ccode\u003eSpecifierSet.to_range() \u0026amp;lt;packaging.specifiers.SpecifierSet.to_range\u0026amp;gt;\u003c/code\u003e,\u003cbr /\u003e\nrepresenting the versions a specifier set accepts as an interval set that\u003cbr /\u003e\nsupports intersection, union, difference, complement, set relations,\u003cbr /\u003e\nmembership tests, and filtering.\u003cbr /\u003e\n:meth:\u003ccode\u003e~packaging.ranges.VersionRange.to_specifier_set\u003c/code\u003e converts a range back\u003cbr /\u003e\nto a :class:\u003ccode\u003e~packaging.specifiers.SpecifierSet\u003c/code\u003e where a PEP 440 form exists.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1267\u003c/code\u003e, :pull:\u003ccode\u003e1270\u003c/code\u003e, :pull:\u003ccode\u003e1298\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (:pull:\u003ccode\u003e1194\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets.\u003cbr /\u003e\n(:issue:\u003ccode\u003e1220\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer\u003cbr /\u003e\nsource distributions over wheels for selected packages. (:pull:\u003ccode\u003e1334\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :func:\u003ccode\u003e~packaging.tags.pure_python_tags\u003c/code\u003e to generate the pure-Python\u003cbr /\u003e\ntags for a Python version without touching the running platform.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1346\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :meth:\u003ccode\u003eSpecifierSet.is_subset() \u0026amp;lt;packaging.specifiers.SpecifierSet.is_subset\u0026amp;gt;\u003c/code\u003e, :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_superset\u003c/code\u003e,\u003cbr /\u003e\nand :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_disjoint\u003c/code\u003e, which compare the\u003cbr /\u003e\nversions two specifier sets accept. (:pull:\u003ccode\u003e1313\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBehavior adaptations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1157\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e\u003cbr /\u003e\ntags on Linux. (:issue:\u003ccode\u003e160\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for versions and specifiers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a\u003cbr /\u003e\nnon-string. (:pull:\u003ccode\u003e1319\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to\u003cbr /\u003e\n\u003ccode\u003eVersion.from_parts\u003c/code\u003e. (:pull:\u003ccode\u003e1241\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1242\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary\u003cbr /\u003e\nintersections. (:pull:\u003ccode\u003e1257\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for requirements and markers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for\u003cbr /\u003e\ntrailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and\u003cbr /\u003e\n\u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in\u003cbr /\u003e\nsets and dicts. (:pull:\u003ccode\u003e1232\u003c/code\u003e)\u003cbr /\u003e\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/929fd4b1410ac7ef61ef3f45b2f5d7e87711a9b5\"\u003e\u003ccode\u003e929fd4b\u003c/code\u003e\u003c/a\u003e Bump for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f300ebf0c155e1f7ea6d62fba11dba4bac3d1944\"\u003e\u003ccode\u003ef300ebf\u003c/code\u003e\u003c/a\u003e chore(deps): bump the pre-commit group with 5 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1357\"\u003e#1357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f91d97566a966177ad7ea5a7c703b12a7273e3b1\"\u003e\u003ccode\u003ef91d975\u003c/code\u003e\u003c/a\u003e ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1361\"\u003e#1361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/b1a7124fe3d40c3302c029e9eb01ac3fc3496a54\"\u003e\u003ccode\u003eb1a7124\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 7 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1358\"\u003e#1358\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/2d873eb6002021a8c007c933fbdab58b37a5079b\"\u003e\u003ccode\u003e2d873eb\u003c/code\u003e\u003c/a\u003e fix(metadata): fold every line boundary when writing headers (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/413d006fadf5b9b14d78ad444201d8189bff8c64\"\u003e\u003ccode\u003e413d006\u003c/code\u003e\u003c/a\u003e docs: changelog for 26.3 (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1343\"\u003e#1343\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/4eb0753dba8fcaaac8eb75463374e448f0931558\"\u003e\u003ccode\u003e4eb0753\u003c/code\u003e\u003c/a\u003e docs(metadata): explain selective field validation (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1342\"\u003e#1342\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/77e9ed42b6db9c5c011a5148047a356ebe42692a\"\u003e\u003ccode\u003e77e9ed4\u003c/code\u003e\u003c/a\u003e feat(tags): add pure Python tag generator (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/7cea5e88671ed14016e9ab3dd08eab064f596564\"\u003e\u003ccode\u003e7cea5e8\u003c/code\u003e\u003c/a\u003e ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/45a8b3402db5ff82158f2d0eabaf8447aa7a50bf\"\u003e\u003ccode\u003e45a8b34\u003c/code\u003e\u003c/a\u003e docs: add missing versionadded/versionchanged directives (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1344\"\u003e#1344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/packaging/compare/25.0...26.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `filelock` from 3.23.0 to 3.32.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/py-filelock/releases\"\u003efilelock's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.32.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix(lease): reject a duration no marker can carry by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/723\"\u003etox-dev/filelock#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(soft-rw): reject non-finite timing options by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/724\"\u003etox-dev/filelock#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve exception notes when copying and pickling by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(soft-rw): reuse existing test module by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/730\"\u003etox-dev/filelock#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: respect ACL write access when the owner write bit is absent by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/728\"\u003etox-dev/filelock#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SoftReadWriteLock state lock timeout by \u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.5\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(fork): report where a stalled fork stops by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/715\"\u003etox-dev/filelock#715\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say that mode is read-only in the thread-local section by \u003ca href=\"https://github.com/Gares95\"\u003e\u003ccode\u003e@​Gares95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/716\"\u003etox-dev/filelock#716\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(lease): clear token after failed acquire by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.4\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix: retry transient denials on open and claim read by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/705\"\u003etox-dev/filelock#705\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: deflake six scheduled-run failures by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/704\"\u003etox-dev/filelock#704\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: cover a reclaimed private record for real by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/706\"\u003etox-dev/filelock#706\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test(fork): fork once the event loop has closed by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/714\"\u003etox-dev/filelock#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/713\"\u003etox-dev/filelock#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eescape the hostname every marker publishes by \u003ca href=\"https://github.com/dxbjavid\"\u003e\u003ccode\u003e@​dxbjavid\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/709\"\u003etox-dev/filelock#709\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(strict): deflake close-fault injections on graalpy by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/697\"\u003etox-dev/filelock#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📄 docs: publish llms.txt from the docs build by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/700\"\u003etox-dev/filelock#700\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst\"\u003efilelock's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e###########\nChangelog\n###########\u003c/p\u003e\n\u003cp\u003e.. towncrier-draft-entries:: Unreleased\u003c/p\u003e\n\u003cp\u003e.. towncrier release notes start\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.1 (2026-09-19)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epoll_interval\u003c/code\u003e is now validated at construction, on the setter, and on \u003ccode\u003eacquire()\u003c/code\u003e: a negative, non-finite, or\nnon-numeric value raises :class:\u003ccode\u003eValueError\u003c/code\u003e/:class:\u003ccode\u003eTypeError\u003c/code\u003e immediately instead of failing inside \u003ccode\u003etime.sleep\u003c/code\u003e. :pr:\u003ccode\u003e739\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.0 (2026-09-17)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eThe :class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e on-disk protocol is a generation log under \u003ccode\u003e\u0026lt;path\u0026gt;.rw\u003c/code\u003e, and a process\nrunning an earlier release does not see it: an old and a new participant on one lock path do not exclude each\nother. Stop every participant, upgrade them all, then restart them; the new code ignores leftover \u003ccode\u003e.state\u003c/code\u003e,\n\u003ccode\u003e.write\u003c/code\u003e and \u003ccode\u003e.readers/\u003c/code\u003e files, and you can delete them. The filesystem must provide no-replace hard links, as\nit must for :class:\u003ccode\u003e~filelock.StrictSoftFileLock\u003c/code\u003e, so a runtime without \u003ccode\u003eos.link\u003c/code\u003e raises\n:class:\u003ccode\u003e~filelock.SoftFileLockProtocolError\u003c/code\u003e on acquire. Constructing a singleton again with a different\n\u003ccode\u003eon_compromise\u003c/code\u003e, or with \u003ccode\u003epoll_interval\u003c/code\u003e at or above \u003ccode\u003estale_threshold\u003c/code\u003e, now raises :class:\u003ccode\u003eValueError\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e exposes :attr:\u003ccode\u003e~filelock.SoftReadWriteLock.generation\u003c/code\u003e as a fencing token for\nthe protected resource and reports a lost hold through \u003ccode\u003eon_compromise\u003c/code\u003e and\n:attr:\u003ccode\u003e~filelock.SoftReadWriteLock.compromise\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e no longer deadlocks when a holder dies on another host mid-transition, and\n\u003ccode\u003erelease()\u003c/code\u003e no longer waits on a mutex a dead host left behind (:pr:\u003ccode\u003e725\u003c/code\u003e, :pr:\u003ccode\u003e735\u003c/code\u003e). The state mutex is gone.\nEach transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock\nrather than an \u003ccode\u003emtime\u003c/code\u003e read against another host's. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.7 (2026-09-16)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eValidate final-symlink refusal by error number so the test works across libc implementations. :pr:\u003ccode\u003e737\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocument that :meth:\u003ccode\u003e~filelock.BaseFileLock.acquire\u003c/code\u003e reads \u003ccode\u003eblocking=None\u003c/code\u003e as the lock's \u003ccode\u003eblocking\u003c/code\u003e attribute and\nraises :class:\u003ccode\u003e~filelock.Timeout\u003c/code\u003e after one attempt when \u003ccode\u003eblocking=False\u003c/code\u003e. :pr:\u003ccode\u003e733\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.6 (2026-09-08)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSoftFileLease\u003c/code\u003e and \u003ccode\u003eAsyncSoftFileLease\u003c/code\u003e now reject a boolean or non-finite \u003ccode\u003elease_duration\u003c/code\u003e, which used to\npublish an owner record their own \u003ccode\u003eowner\u003c/code\u003e property reads back as malformed. :pr:\u003ccode\u003e723\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eReject non-finite heartbeat, stale, and polling intervals in \u003ccode\u003eSoftReadWriteLock\u003c/code\u003e and \u003ccode\u003eAsyncSoftReadWriteLock\u003c/code\u003e,\nincluding cached singleton construction and overflow in the default stale threshold. :pr:\u003ccode\u003e724\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d\"\u003e\u003ccode\u003e4efd93e\u003c/code\u003e\u003c/a\u003e Release 3.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1\"\u003e\u003ccode\u003e7b7b7a8\u003c/code\u003e\u003c/a\u003e Fix SoftReadWriteLock state lock timeout (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2\"\u003e\u003ccode\u003ef2f7b86\u003c/code\u003e\u003c/a\u003e fix: respect ACL write access when the owner write bit is absent (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153\"\u003e\u003ccode\u003ee947a69\u003c/code\u003e\u003c/a\u003e test(soft-rw): reuse existing test module (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88\"\u003e\u003ccode\u003eda3ae2b\u003c/code\u003e\u003c/a\u003e fix: preserve exception notes when copying and pickling (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812\"\u003e\u003ccode\u003eae9cb5b\u003c/code\u003e\u003c/a\u003e 🐛 fix(soft-rw): reject non-finite timing options (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/d00f9bbd709fbe92a99a38cb1e32b6690813e5a8\"\u003e\u003ccode\u003ed00f9bb\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/727\"\u003e#727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/82f66d7b0aaa83755f8d71d0b0da88408b58ec4a\"\u003e\u003ccode\u003e82f66d7\u003c/code\u003e\u003c/a\u003e 🐛 fix(lease): reject a duration no marker can carry (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1d9e9e7e43a1089c57d7c6f20d6a2268235a4745\"\u003e\u003ccode\u003e1d9e9e7\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/722\"\u003e#722\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9\"\u003e\u003ccode\u003e1585dfe\u003c/code\u003e\u003c/a\u003e Release 3.32.5\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tox-dev/py-filelock/compare/3.23.0...3.32.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `plum-dispatch` from 2.5.7 to 2.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beartype/plum/releases\"\u003eplum-dispatch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOptimise \u003ccode\u003e_wrap_type_hint\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/310\"\u003e#310\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eBuild macOS arm64 mypyc wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/320\"\u003e#320\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/beartype/plum/issues/317\"\u003e#317\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/318\"\u003e#318\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCompile more things with \u003ccode\u003emypyc\u003c/code\u003e for faster dispatch (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/287\"\u003e#287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/beartype/plum/issues/288\"\u003e#288\u003c/a\u003e, and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/289\"\u003e#289\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake concurrent dispatch resolution thread safe (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/281\"\u003e#281\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix support for \u003ccode\u003ebeartype\u0026gt;=0.23\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/296\"\u003e#296\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove typing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/268\"\u003e#268\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove \u003ccode\u003eVal\u003c/code\u003e, which was deprecated in v0.5.0 in favour of \u003ccode\u003etyping.Literal\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/269\"\u003e#269\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport union aliases in Python 3.14 and later (\u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.0\u003c/h2\u003e\n\u003cp\u003eStarting this release, Plum will be available on PyPI as both \u003ccode\u003eplum-dispatch\u003c/code\u003e and \u003ccode\u003eplum\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003ev2.7.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003efaithful\u003c/code\u003e keyword to \u003ccode\u003eModuleType\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e All imports should now go through \u003ccode\u003eplum\u003c/code\u003e directly! That is, not \u003ccode\u003eplum.signature.Signature\u003c/code\u003e, but \u003ccode\u003eplum.Signature\u003c/code\u003e. Please do open an issue if this release breaks something that shouldn't break.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSignificantly improve typing of the internals (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/179\"\u003e#179\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/242\"\u003e#242\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003euv\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/218\"\u003e#218\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake modules private for public/private separation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/241\"\u003e#241\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003esrc\u003c/code\u003e layout (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/249\"\u003e#249\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove config (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/248\"\u003e#248\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003emypyc\u003c/code\u003e builds for better performance (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/247\"\u003e#247\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e)!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.6.1\u003c/h2\u003e\n\u003cp\u003eThis release features numerous very helpful contributions and improvements by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse dependency groups (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/195\"\u003e#195\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTreat \u003ccode\u003etyping_extensions\u003c/code\u003e as standard library and make more use of it (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/226\"\u003e#226\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/232\"\u003e#232\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eComplete deprecation cycles (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/230\"\u003e#230\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/236\"\u003e#236\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTurn various arguments into positional-only (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/229\"\u003e#229\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove unnecessary path manipulation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/233\"\u003e#233\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRework tests with a \u003ccode\u003edispatch\u003c/code\u003e fixture (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/234\"\u003e#234\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAvoid using a deprecated NumPy module (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/231\"\u003e#231\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDrops support for Python 3.9 (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImport exports from \u003ccode\u003emethods.py\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/237\"\u003e#237\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixes an incorrect \u003ccode\u003eoverload\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/238\"\u003e#238\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003enox\u003c/code\u003e for testing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/235\"\u003e#235\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/240\"\u003e#240\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e also fixes an important bug to do with the handling of unions (CC \u003ca href=\"https://github.com/davidwyld\"\u003e\u003ccode\u003e@​davidwyld\u003c/code\u003e\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beartype/plum/commit/c835c8cf5ebea4f00ee304a647e026739034e63b\"\u003e\u003ccode\u003ec835c8c\u003c/code\u003e\u003c/a\u003e fix(mypyc): keep \u003ccode\u003eFunction\u003c/code\u003e weak-referenceable on the compiled wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c...\n\n_Description has been truncated_","html_url":"https://github.com/dimensionalOS/dimos/pull/4260","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dimensionalOS%2Fdimos/issues/4260","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4260/packages"},{"uuid":"5534319114","node_id":"PR_kwDOS8i2VM8AAAABEgrTaA","number":119,"state":"open","title":"Bump the minor-update group with 191 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T01:41:11.000Z","updated_at":"2026-09-22T01:41:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":191,"packages":[{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.28.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"mcp","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"tpu-inference","old_version":"0.28.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"fastsafetensors","old_version":"0.3.3","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.2","new_version":"4.7.1","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.9","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.11.1","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpcore2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"httpx2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.19","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mcp-types","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.0","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.10","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.2","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.4","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.13.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 191 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.28.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.28.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.3` | `0.4.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.2` | `4.7.1` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.9` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.11.1` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mcp-types](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.0` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.10` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.2` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.4` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.13.0.0` | `2.14.0.0` |\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.28.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.28.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/iss...\n\n_Description has been truncated_","html_url":"https://github.com/yhfgyyf/vllm-deepseek-v4-sm89/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/yhfgyyf%2Fvllm-deepseek-v4-sm89/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"},{"uuid":"5531897537","node_id":"PR_kwDOS3rmoM8AAAABEev6_Q","number":2,"state":"closed","title":"Bump the pip group across 1 directory with 6 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-21T20:07:30.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-21T20:06:35.000Z","updated_at":"2026-09-21T20:07:32.000Z","time_to_close":55,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":6,"packages":[{"name":"setuptools","old_version":"59.6.0","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"wheel","old_version":"0.45.1","new_version":"0.46.2","repository_url":"https://github.com/pypa/wheel"},{"name":"accelerate","old_version":"1.10.1","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"torch","old_version":"2.8.0","new_version":"2.13.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"4.56.2","new_version":"5.10.1","repository_url":"https://github.com/huggingface/transformers"},{"name":"pytest","old_version":"8.4.2","new_version":"9.0.3","repository_url":"https://github.com/pytest-dev/pytest"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [setuptools](https://github.com/pypa/setuptools) | `59.6.0` | `83.0.0` |\n| [wheel](https://github.com/pypa/wheel) | `0.45.1` | `0.46.2` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.10.1` | `1.15.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.8.0` | `2.13.0` |\n| [transformers](https://github.com/huggingface/transformers) | `4.56.2` | `5.10.1` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.4.2` | `9.0.3` |\n\n\nUpdates `setuptools` from 59.6.0 to 83.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/setuptools/blob/main/NEWS.rst\"\u003esetuptools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev83.0.0\u003c/h1\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRequire Python 3.10 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eMANIFEST.in\u003c/code\u003e matching (via \u003ccode\u003eFileList\u003c/code\u003e) is now insensitive to Unicode\nnormalization form. A pattern authored in one form (e.g. NFC, as typically\nsaved by editors) now matches a file whose name is stored on disk in another\n(e.g. NFD, as produced by macOS APFS/HFS+). Previously an \u003ccode\u003eexclude\u003c/code\u003e,\n\u003ccode\u003eglobal-exclude\u003c/code\u003e, \u003ccode\u003erecursive-exclude\u003c/code\u003e, or \u003ccode\u003eprune\u003c/code\u003e rule could silently\nfail to drop a non-ASCII-named file from the source distribution, publishing\nit despite the exclusion -- see GHSA-h35f-9h28-mq5c.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epypa/distutils#334\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ev82.0.1\u003c/h1\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix the loading of \u003ccode\u003elauncher manifest.xml\u003c/code\u003e file. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5047\"\u003e#5047\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaced deprecated \u003ccode\u003ejson.__version__\u003c/code\u003e with fixture in tests. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5186\"\u003e#5186\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd advice about how to improve predictability when installing sdists. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5168\"\u003e#5168\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/4941\"\u003e#4941\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5157\"\u003e#5157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5169\"\u003e#5169\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5175\"\u003e#5175\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ev82.0.0\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/6519f728c6f23c992df81a5691ef7655184a20eb\"\u003e\u003ccode\u003e6519f72\u003c/code\u003e\u003c/a\u003e Bump version: 82.0.1 → 83.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/d1151b125b29a6ee1c7db860f7ee6c365d525b5f\"\u003e\u003ccode\u003ed1151b1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5250\"\u003e#5250\u003c/a\u003e from pypa/feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2df31e6a741b0fe775969618fe6a3a3d032e900\"\u003e\u003ccode\u003ea2df31e\u003c/code\u003e\u003c/a\u003e Capture removal of dry_run parameter in changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/00144dc3fb6d023fd81cdc26c380a012b084df9b\"\u003e\u003ccode\u003e00144dc\u003c/code\u003e\u003c/a\u003e Moved newsfragment to the release where it occurred.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a4a5a2b160357be77626aa077ddd1d8ee53be50f\"\u003e\u003ccode\u003ea4a5a2b\u003c/code\u003e\u003c/a\u003e Add news fragment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/77470c23c35031c9e37d7512694ac5ca52bfcaac\"\u003e\u003ccode\u003e77470c2\u003c/code\u003e\u003c/a\u003e Merge \u003ca href=\"https://github.com/pypa/distutils\"\u003ehttps://github.com/pypa/distutils\u003c/a\u003e into feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/3c43897420f25a1be1afe6eaa905d056009cc736\"\u003e\u003ccode\u003e3c43897\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5247\"\u003e#5247\u003c/a\u003e from pypa/copilot/fix-pypy-version-issue\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/bb6ea66b4bd01cb35d7c68a1bc61b96d59190269\"\u003e\u003ccode\u003ebb6ea66\u003c/code\u003e\u003c/a\u003e Bump PyPy from 3.10 to 3.11 in CI workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2bc3aca2f55eb9b93ea633e58ba68170ce14451\"\u003e\u003ccode\u003ea2bc3ac\u003c/code\u003e\u003c/a\u003e Fix broken intersphinx reference to build's installation docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/2d6a739c64cfedc65e1f635af7b52340aac8d99b\"\u003e\u003ccode\u003e2d6a739\u003c/code\u003e\u003c/a\u003e Use stacked parametrize decorators instead of itertools.product\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/setuptools/compare/v59.6.0...v83.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `wheel` from 0.45.1 to 0.46.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/wheel/releases\"\u003ewheel's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.46.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestored the \u003ccode\u003ebdist_wheel\u003c/code\u003e command for compatibility with \u003ccode\u003esetuptools\u003c/code\u003e older than v70.1\u003c/li\u003e\n\u003cli\u003eImporting \u003ccode\u003ewheel.bdist_wheel\u003c/code\u003e now emits a \u003ccode\u003eFutureWarning\u003c/code\u003e instead of a \u003ccode\u003eDeprecationWarning\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel unpack\u003c/code\u003e potentially altering the permissions of files outside of the destination tree with maliciously crafted wheels (CVE-2026-24049)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.46.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTemporarily restored the \u003ccode\u003ewheel.macosx_libfile\u003c/code\u003e module (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/659\"\u003e#659\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.46.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.8\u003c/li\u003e\n\u003cli\u003eRemoved the \u003ccode\u003ebdist_wheel\u003c/code\u003e setuptools command implementation and entry point. The \u003ccode\u003ewheel.bdist_wheel\u003c/code\u003e module is now just an alias to \u003ccode\u003esetuptools.command.bdist_wheel\u003c/code\u003e, emitting a deprecation warning on import.\u003c/li\u003e\n\u003cli\u003eRemoved vendored \u003ccode\u003epackaging\u003c/code\u003e in favor of a run-time dependency on it\u003c/li\u003e\n\u003cli\u003eMade the \u003ccode\u003ewheel.metadata\u003c/code\u003e module private (with a deprecation warning if it's imported\u003c/li\u003e\n\u003cli\u003eMade the \u003ccode\u003ewheel.cli\u003c/code\u003e package private (no deprecation warning)\u003c/li\u003e\n\u003cli\u003eFixed an exception when calling the \u003ccode\u003econvert\u003c/code\u003e command with an empty description field\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/wheel/blob/main/docs/news.rst\"\u003ewheel's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease Notes\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eUNRELEASED\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel pack --build-number\u003c/code\u003e accepting build tags that are invalid in a\nwheel file name (not starting with a digit, or containing \u003ccode\u003e-\u003c/code\u003e), the same\nvalidation \u003ccode\u003ewheel tags --build\u003c/code\u003e already performs\u003c/li\u003e\n\u003cli\u003eFixed the macOS platform-tag warning always using the plural \u0026quot;these files\u0026quot;\nwording, even when only a single library required a higher deployment target\n(\u003ccode\u003e[#697](https://github.com/pypa/wheel/issues/697) \u0026lt;https://github.com/pypa/wheel/pull/697\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.48.0 (2026-08-12)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003e--local-version\u003c/code\u003e option to \u003ccode\u003ewheel pack\u003c/code\u003e to add, replace, or remove a\nPEP 440 local version identifier from a wheel\n(\u003ccode\u003e[#570](https://github.com/pypa/wheel/issues/570) \u0026lt;https://github.com/pypa/wheel/issues/570\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel convert\u003c/code\u003e unnecessarily upgrading compatible core metadata versions\n(\u003ccode\u003e[#643](https://github.com/pypa/wheel/issues/643) \u0026lt;https://github.com/pypa/wheel/issues/643\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel tags\u003c/code\u003e producing invalid archives when retagging wheels whose\nentries use ZIP64, by dropping the central-directory ZIP64 extra field that is\nnot valid in a local file header\n(\u003ccode\u003e[#692](https://github.com/pypa/wheel/issues/692) \u0026lt;https://github.com/pypa/wheel/issues/692\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel convert\u003c/code\u003e writing the converted wheel outside the destination\ndirectory when the input archive contained a maliciously crafted project name\nor version with path separators (arbitrary file write / path traversal)\n(\u003ccode\u003eGHSA-vgq5-9859-3mmw \u0026lt;https://github.com/pypa/wheel/security/advisories/GHSA-vgq5-9859-3mmw\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.47.0 (2026-04-22)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded the \u003ccode\u003ewheel info\u003c/code\u003e subcommand to display metadata about wheel files without\nunpacking them (\u003ccode\u003e[#639](https://github.com/pypa/wheel/issues/639) \u0026lt;https://github.com/pypa/wheel/issues/639\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eWheelFile\u003c/code\u003e raising \u003ccode\u003eMissing RECORD file\u003c/code\u003e when the wheel filename contains\nuppercase characters (e.g. \u003ccode\u003eDjango-3.2.5.whl\u003c/code\u003e) but the \u003ccode\u003e.dist-info\u003c/code\u003e directory\ninside uses normalized lowercase naming\n(\u003ccode\u003e[#411](https://github.com/pypa/wheel/issues/411) \u0026lt;https://github.com/pypa/wheel/issues/411\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.46.3 (2026-01-22)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eImportError: cannot import name '_setuptools_logging' from 'wheel'\u003c/code\u003e when\ninstalled alongside an old version of setuptools and running the \u003ccode\u003ebdist_wheel\u003c/code\u003e\ncommand (\u003ccode\u003e[#676](https://github.com/pypa/wheel/issues/676) \u0026lt;https://github.com/pypa/wheel/issues/676\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.46.2 (2026-01-22)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRestored the \u003ccode\u003ebdist_wheel\u003c/code\u003e command for compatibility with \u003ccode\u003esetuptools\u003c/code\u003e older than\nv70.1\u003c/li\u003e\n\u003cli\u003eImporting \u003ccode\u003ewheel.bdist_wheel\u003c/code\u003e now emits a \u003ccode\u003eFutureWarning\u003c/code\u003e instead of a\n\u003ccode\u003eDeprecationWarning\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel unpack\u003c/code\u003e potentially altering the permissions of files outside of the\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/eba4036ccaca4e2d0c5b5bf3e3be59b2b2877d6b\"\u003e\u003ccode\u003eeba4036\u003c/code\u003e\u003c/a\u003e Updated the version number for v0.46.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/557fb5425036ccca95330b2c8875e54c9f4483cf\"\u003e\u003ccode\u003e557fb54\u003c/code\u003e\u003c/a\u003e Created a new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef\"\u003e\u003ccode\u003e7a7d2de\u003c/code\u003e\u003c/a\u003e Fixed security issue around wheel unpack (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/675\"\u003e#675\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/41418fac233d6973ea8798d620df4aa5b3aa1b66\"\u003e\u003ccode\u003e41418fa\u003c/code\u003e\u003c/a\u003e Fixed test failures due to metadata normalization changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/c1d442bec6c634fcfb89e5d58698dd226685bd14\"\u003e\u003ccode\u003ec1d442b\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/674\"\u003e#674\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/0bac8820ec90b1aaa0695d79a56563137b48686d\"\u003e\u003ccode\u003e0bac882\u003c/code\u003e\u003c/a\u003e Update github actions environments (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/673\"\u003e#673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/be9f45b4ee1210b2a815d2eefea56b71efd99d63\"\u003e\u003ccode\u003ebe9f45b\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/667\"\u003e#667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/6244f08bb92d7569da6c2fbea23de0846ad34ff3\"\u003e\u003ccode\u003e6244f08\u003c/code\u003e\u003c/a\u003e Update pre-commit ruff legacy alias (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/668\"\u003e#668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/15b7577654e8bcd23e009c6bac036b65c11d8d8f\"\u003e\u003ccode\u003e15b7577\u003c/code\u003e\u003c/a\u003e PEP 639 compliance (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/670\"\u003e#670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/fc8cb4163e4f48d86092cb2a16076f1b3efcd10f\"\u003e\u003ccode\u003efc8cb41\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Removed redundant Python version from the publish workflow (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/666\"\u003e#666\u003c/a\u003e)\u0026quot;\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/wheel/compare/0.45.1...0.46.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.10.1 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/6afc1e5ee217051fde702b23de2813344dc0fd33\"\u003e\u003ccode\u003e6afc1e5\u003c/code\u003e\u003c/a\u003e Release: v1.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/636a9343b4265db1212b04c778b8910b5cbfa713\"\u003e\u003ccode\u003e636a934\u003c/code\u003e\u003c/a\u003e Fix nightly CI: tensor parallel size detection and DeepSpeed warmup steps (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/385d9fb40bdb92b0cb34775ad0ef493c171e559f\"\u003e\u003ccode\u003e385d9fb\u003c/code\u003e\u003c/a\u003e docs: fix three dead links left by the docs restructure (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4230\"\u003e#4230\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/c424d0b82d4ed61672bf30f1a81ce80370fd945a\"\u003e\u003ccode\u003ec424d0b\u003c/code\u003e\u003c/a\u003e docs: fix garbled sentence in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4231\"\u003e#4231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/0f7e35fe7902cc6ba8dc01b146d6447900464b88\"\u003e\u003ccode\u003e0f7e35f\u003c/code\u003e\u003c/a\u003e Clip grad norm support for dtensors (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/b2ac5095f04585043e21d295afe3aaaacdcc8357\"\u003e\u003ccode\u003eb2ac509\u003c/code\u003e\u003c/a\u003e Fix FSDP2/ PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/33e8bc499254e7f3886db3f8a277d05a4ad2667e\"\u003e\u003ccode\u003e33e8bc4\u003c/code\u003e\u003c/a\u003e Fix load_accelerator_state only restoring one RNG backend (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4217\"\u003e#4217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/50de3ad45f4da279819529e443ba746eb5b3b187\"\u003e\u003ccode\u003e50de3ad\u003c/code\u003e\u003c/a\u003e Treat MPS out-of-memory errors as OOM in find_executable_batch_size (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4227\"\u003e#4227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/ab5fe8e507366f814fee59138eb96b9879cb05d6\"\u003e\u003ccode\u003eab5fe8e\u003c/code\u003e\u003c/a\u003e feat: add the neuron device branch in state (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4218\"\u003e#4218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/9baf95be958c3fd8b2449d1463e6a89e14f61e7d\"\u003e\u003ccode\u003e9baf95b\u003c/code\u003e\u003c/a\u003e Fix MLFLOW_NESTED_RUN never being able to turn nesting off (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4223\"\u003e#4223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/accelerate/compare/v1.10.1...v1.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.8.0 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.13.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eTracked Regressions\u003c/h1\u003e\n\u003ch3\u003eROCm wheels break \u003ccode\u003etorch.compile\u003c/code\u003e on CPU in environments without a GPU\u003c/h3\u003e\n\u003cp\u003eRunning a \u003ccode\u003etorch==2.13.0+rocm7.2\u003c/code\u003e wheel in an environment where no GPU is available (\u003ccode\u003etorch.cuda.is_available()\u003c/code\u003e is \u003ccode\u003eFalse\u003c/code\u003e) breaks \u003ccode\u003etorch.compile\u003c/code\u003e on the CPU path: the first compile raises \u003ccode\u003eRuntimeError: Can't detect vectorized ISA for CPU\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/189194\"\u003e#189194\u003c/a\u003e). This is a regression from \u003ccode\u003etorch==2.12.1+rocm7.2\u003c/code\u003e, which compiles CPU code fine (detecting e.g. \u003ccode\u003eVecAVX2\u003c/code\u003e) in the same setup. The 2.13 ROCm wheel appears to rely on something present in the ROCm builder image to detect the CPU vectorized ISA, so it works when run on a ROCm image but fails on a plain CPU-only image.\u003c/p\u003e\n\u003cp\u003eWorkaround: run the \u003ccode\u003e+rocm\u003c/code\u003e wheel on a ROCm image, or install a standard CPU/CUDA build for GPU-less environments.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eStop building CPython 3.13t (free-threaded) binaries (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/182951\"\u003e#182951\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eUpstream \u003ccode\u003epypa/manylinux\u003c/code\u003e removed CPython 3.13t (free-threaded) on 2026-05-07, because 3.13t\nwas experimental and has been superseded by the now-non-experimental CPython 3.14t. As a result,\nPyTorch 2.13 no longer ships \u003ccode\u003ecp313t\u003c/code\u003e wheels (Linux, Triton, and related artifacts). Users on the\nfree-threaded interpreter should move to Python 3.14t.\u003c/p\u003e\n\u003cp\u003ePyTorch 2.12:\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003e# cp313t (free-threaded 3.13) wheels were available\r\npython3.13t -m pip install torch\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003ePyTorch 2.13:\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/cf30153c4c131c8164ee7798e5022d810682e2cb\"\u003e\u003ccode\u003ecf30153\u003c/code\u003e\u003c/a\u003e [release/2.13] Strip +PTX from CUDA arch list on release/RC builds (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188914\"\u003e#188914\u003c/a\u003e) ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/3e3e24bd95b010f8f74915f0c30476906e60d4fc\"\u003e\u003ccode\u003e3e3e24b\u003c/code\u003e\u003c/a\u003e [release/2.13] Restrict cuda-bindings to Python \u0026lt; 3.15 for CUDA 12.9 builds (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/7986b068032abf5e22ea51fe7fea63ef5bcaf3b1\"\u003e\u003ccode\u003e7986b06\u003c/code\u003e\u003c/a\u003e [release/2.13] Bump binary build timeout 280 -\u0026gt; 400 minutes (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188551\"\u003e#188551\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/0bdbc268e08fba9debac8f35a8a12e9c008ec0fd\"\u003e\u003ccode\u003e0bdbc26\u003c/code\u003e\u003c/a\u003e [release/2.13] Add CUDA 12.9 to TORCH_CUDA_ARCH_LIST tables (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188443\"\u003e#188443\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/9cabb45ca6e6ed3bb4645c929bcfd07691651f74\"\u003e\u003ccode\u003e9cabb45\u003c/code\u003e\u003c/a\u003e [release/2.13] Update manywheel docker image pin to 78e737ad (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188409\"\u003e#188409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/78e737ad29420ffc4800e677c51e2a852caf8359\"\u003e\u003ccode\u003e78e737a\u003c/code\u003e\u003c/a\u003e [release/2.13] Revert \u0026quot;Tighten generalized scatter graph target (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/184075\"\u003e#184075\u003c/a\u003e)\u0026quot; (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/0bb9b5bc24bed3278488372d62d9f2235e9e77e3\"\u003e\u003ccode\u003e0bb9b5b\u003c/code\u003e\u003c/a\u003e [release/2.13] Revert \u0026quot;dynamo: round-trip torch.cuda.stream ctx mgr across gr...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/aaac2bfe460c04a4d41e83e03452d2347f7142b9\"\u003e\u003ccode\u003eaaac2bf\u003c/code\u003e\u003c/a\u003e [release/2.13] Revert \u0026quot;[Reland] Port D104346887/PR 182675 for index_add fast ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/933081368c3ab64fa2e953217e413b3ba52844e3\"\u003e\u003ccode\u003e9330813\u003c/code\u003e\u003c/a\u003e Fix build_with_debinfo.py broken by CONFIGURE_DEPENDS globbing (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188192\"\u003e#188192\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/4e077a7dcf29167db9e97d86cc62f431905e09f7\"\u003e\u003ccode\u003e4e077a7\u003c/code\u003e\u003c/a\u003e Remove setuptools upper bound (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188190\"\u003e#188190\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pytorch/pytorch/compare/v2.8.0...v2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 4.56.2 to 5.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v5.10.1\u003c/h1\u003e\n\u003cp\u003ev5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!\u003c/p\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eGemma4 unified+ Gemma4 MTP\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eGemma 4 12B Unified is an \u003cstrong\u003eencoder-free\u003c/strong\u003e multimodal model with pretrained and instruction-tuned variants. Unlike \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gemma4\"\u003estandard Gemma 4\u003c/a\u003e, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.\u003c/p\u003e\n\u003cp\u003eKey differences from standard Gemma 4:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo Vision Tower\u003c/strong\u003e: Raw pixel patches are projected directly into LM space via a \u003ccode\u003eDense + LayerNorm\u003c/code\u003e pipeline with factorized 2D positional embeddings, replacing the vision encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNo Audio Tower\u003c/strong\u003e: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple \u003ccode\u003eRMSNorm → Linear\u003c/code\u003e pipeline, replacing the mel spectrogram + Conformer encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eShared Multimodal Pipeline\u003c/strong\u003e: Both vision and audio use the same \u003ccode\u003eGemma4UnifiedMultimodalEmbedder\u003c/code\u003e (RMSNorm → Linear) for the final projection to text hidden space.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou can find the original Gemma 4 12B Unified checkpoints under the \u003ca href=\"https://huggingface.co/collections/google/gemma-4\"\u003eGemma 4\u003c/a\u003e release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewho needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e) by \u003ca href=\"https://github.com/douglas-reid\"\u003e\u003ccode\u003e@​douglas-reid\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/sgerrard\"\u003e\u003ccode\u003e@​sgerrard\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/vasqu\"\u003e\u003ccode\u003e@​vasqu\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/molbap\"\u003e\u003ccode\u003e@​molbap\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSapiens2\u003c/h3\u003e\n\u003cp\u003eSapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2\"\u003eDocumentation\u003c/a\u003e | \u003ca href=\"https://huggingface.co/papers/2604.21681\"\u003ePaper\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e) by \u003ca href=\"https://github.com/guarin\"\u003e\u003ccode\u003e@​guarin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45919\"\u003e#45919\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDeepSeek-OCR-2\u003c/h3\u003e\n\u003cp\u003eDeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Deepseek-OCR-2 model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45075\"\u003e#45075\u003c/a\u003e) by \u003ca href=\"https://github.com/thisisiron\"\u003e\u003ccode\u003e@​thisisiron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45075\"\u003e#45075\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMellum\u003c/h3\u003e\n\u003cp\u003eMellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/mellum\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Add support for JetBrains' \u003ccode\u003eMellum\u003c/code\u003e v2 code generation model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46112\"\u003e#46112\u003c/a\u003e) by \u003ca href=\"https://github.com/shadeMe\"\u003e\u003ccode\u003e@​shadeMe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/46112\"\u003e#46112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBreaking changes\u003c/h2\u003e\n\u003cp\u003eThe Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 Fix float16 overflow in Gemma4 vision pooler (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46277\"\u003e#46277\u003c/a\u003e) by \u003ca href=\"https://github.com/Bluear7878\"\u003e\u003ccode\u003e@​Bluear7878\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAudio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 [ALM] Add base model without head (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45534\"\u003e#45534\u003c/a\u003e) by \u003ca href=\"https://github.com/eustlb\"\u003e\u003ccode\u003e@​eustlb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d\"\u003e\u003ccode\u003e90c3ae5\u003c/code\u003e\u003c/a\u003e Patch because we had to yank 5.10 because the release branch was not up to date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968\"\u003e\u003ccode\u003e0bd94b3\u003c/code\u003e\u003c/a\u003e v5.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897\"\u003e\u003ccode\u003e1423d22\u003c/code\u003e\u003c/a\u003e who needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98\"\u003e\u003ccode\u003e50eb20a\u003c/code\u003e\u003c/a\u003e Fix dsv4 dequant + tp/ep (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46378\"\u003e#46378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299\"\u003e\u003ccode\u003e74464e8\u003c/code\u003e\u003c/a\u003e Fix wrong changes produced by style/repo. check bot (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46371\"\u003e#46371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc\"\u003e\u003ccode\u003e1b8ec34\u003c/code\u003e\u003c/a\u003e Fix path traversal when saving Bark voice preset embeddings (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46237\"\u003e#46237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872\"\u003e\u003ccode\u003ee820678\u003c/code\u003e\u003c/a\u003e Add Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43\"\u003e\u003ccode\u003e595721c\u003c/code\u003e\u003c/a\u003e Pass library_name/version to Hub calls via a shared HfApi (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46318\"\u003e#46318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a\"\u003e\u003ccode\u003e0f0036c\u003c/code\u003e\u003c/a\u003e docs: update ACL Anthology URL in CITATION.cff (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46352\"\u003e#46352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353\"\u003e\u003ccode\u003efa6c830\u003c/code\u003e\u003c/a\u003e DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45634\"\u003e#45634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.56.2...v5.10.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pytest` from 8.4.2 to 9.0.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytest-dev/pytest/releases\"\u003epytest's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.0.3\u003c/h2\u003e\n\u003ch1\u003epytest 9.0.3 (2026-04-07)\u003c/h1\u003e\n\u003ch2\u003eBug fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/12444\"\u003e#12444\u003c/a\u003e: Fixed \u003ccode\u003epytest.approx\u003c/code\u003e which now correctly takes into account \u003ccode\u003e~collections.abc.Mapping\u003c/code\u003e keys order to compare them.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13634\"\u003e#13634\u003c/a\u003e: Blocking a \u003ccode\u003econftest.py\u003c/code\u003e file using the \u003ccode\u003e-p no:\u003c/code\u003e option is now explicitly disallowed.\u003c/p\u003e\n\u003cp\u003ePreviously this resulted in an internal assertion failure during plugin loading.\u003c/p\u003e\n\u003cp\u003ePytest now raises a clear \u003ccode\u003eUsageError\u003c/code\u003e explaining that conftest files are not plugins and cannot be disabled via \u003ccode\u003e-p\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13734\"\u003e#13734\u003c/a\u003e: Fixed crash when a test raises an exceptiongroup with \u003ccode\u003e__tracebackhide__ = True\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14195\"\u003e#14195\u003c/a\u003e: Fixed an issue where non-string messages passed to \u003c!-- raw HTML omitted --\u003eunittest.TestCase.subTest()\u003c!-- raw HTML omitted --\u003e were not printed.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14343\"\u003e#14343\u003c/a\u003e: Fixed use of insecure temporary directory (CVE-2025-71176).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13388\"\u003e#13388\u003c/a\u003e: Clarified documentation for \u003ccode\u003e-p\u003c/code\u003e vs \u003ccode\u003ePYTEST_PLUGINS\u003c/code\u003e plugin loading and fixed an incorrect \u003ccode\u003e-p\u003c/code\u003e example.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13731\"\u003e#13731\u003c/a\u003e: Clarified that capture fixtures (e.g. \u003ccode\u003ecapsys\u003c/code\u003e and \u003ccode\u003ecapfd\u003c/code\u003e) take precedence over the \u003ccode\u003e-s\u003c/code\u003e / \u003ccode\u003e--capture=no\u003c/code\u003e command-line options in \u003ccode\u003eAccessing captured output from a test function \u0026lt;accessing-captured-output\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14088\"\u003e#14088\u003c/a\u003e: Clarified that the default \u003ccode\u003epytest_collection\u003c/code\u003e hook sets \u003ccode\u003esession.items\u003c/code\u003e before it calls \u003ccode\u003epytest_collection_finish\u003c/code\u003e, not after.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14255\"\u003e#14255\u003c/a\u003e: TOML integer log levels must be quoted: Updating reference documentation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributor-facing changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/12689\"\u003e#12689\u003c/a\u003e: The test reports are now published to Codecov from GitHub Actions.\nThe test statistics is visible \u003ca href=\"https://app.codecov.io/gh/pytest-dev/pytest/tests\"\u003eon the web interface\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e-- by \u003ccode\u003ealeguy02\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e9.0.2\u003c/h2\u003e\n\u003ch1\u003epytest 9.0.2 (2025-12-06)\u003c/h1\u003e\n\u003ch2\u003eBug fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13896\"\u003e#13896\u003c/a\u003e: The terminal progress feature added in pytest 9.0.0 has been disabled by default, except on Windows, due to compatibility issues with some terminal emulators.\u003c/p\u003e\n\u003cp\u003eYou may enable it again by passing \u003ccode\u003e-p terminalprogress\u003c/code\u003e. We may enable it by default again once compatibility improves in the future.\u003c/p\u003e\n\u003cp\u003eAdditionally, when the environment variable \u003ccode\u003eTERM\u003c/code\u003e is \u003ccode\u003edumb\u003c/code\u003e, the escape codes are no longer emitted, even if the plugin is enabled.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13904\"\u003e#13904\u003c/a\u003e: Fixed the TOML type of the \u003ccode\u003etmp_path_retention_count\u003c/code\u003e settings in the API reference from number to string.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13946\"\u003e#13946\u003c/a\u003e: The private \u003ccode\u003econfig.inicfg\u003c/code\u003e attribute was changed in a breaking manner in pytest 9.0.0.\nDue to its usage in the ecosystem, it is now restored to working order using a compatibility shim.\nIt will be deprecated in pytest 9.1 and removed in pytest 10.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/a7d58d7a21b78581e636bbbdea13c66ad1657c1e\"\u003e\u003ccode\u003ea7d58d7\u003c/code\u003e\u003c/a\u003e Prepare release version 9.0.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/089d98199c253d8f89a040243bc4f2aa6cd5ab22\"\u003e\u003ccode\u003e089d981\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14366\"\u003e#14366\u003c/a\u003e from bluetech/revert-14193-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/8127eaf4ab7f6b2fdd0dc1b38343ec97aeef05ac\"\u003e\u003ccode\u003e8127eaf\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Fix: assertrepr_compare respects dict insertion order (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14050\"\u003e#14050\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14193\"\u003e#14193\u003c/a\u003e)\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/99a7e6029e7a6e8d53e5df114b1346e035370241\"\u003e\u003ccode\u003e99a7e60\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14363\"\u003e#14363\u003c/a\u003e from pytest-dev/patchback/backports/9.0.x/95d8423bd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/ddee02a578da30dd43aedc39c1c1f1aaadfcee95\"\u003e\u003ccode\u003eddee02a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14343\"\u003e#14343\u003c/a\u003e from bluetech/cve-2025-71176-simple\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/74eac6916fee34726cb194f16c516e96fbd29619\"\u003e\u003ccode\u003e74eac69\u003c/code\u003e\u003c/a\u003e doc: Update training info (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14298\"\u003e#14298\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14301\"\u003e#14301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/f92dee777cfdb77d1c43633d02766ddf1f07c869\"\u003e\u003ccode\u003ef92dee7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14267\"\u003e#14267\u003c/a\u003e from pytest-dev/patchback/backports/9.0.x/d6fa26c62...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/7ee58acc8777c31ac6cf388d01addf5a414a7439\"\u003e\u003ccode\u003e7ee58ac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/12378\"\u003e#12378\u003c/a\u003e from Pierre-Sassoulas/fix-implicit-str-concat-and-d...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/37da870d37e3a2f5177cae075c7b9ae279432bf8\"\u003e\u003ccode\u003e37da870\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14259\"\u003e#14259\u003c/a\u003e from mitre88/patch-4 (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14268\"\u003e#14268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/c34bfa3b7acb65b594707c714f1d8461b0304eed\"\u003e\u003ccode\u003ec34bfa3\u003c/code\u003e\u003c/a\u003e Add explanation for string context diffs (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14257\"\u003e#14257\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14266\"\u003e#14266\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pytest-dev/pytest/compare/8.4.2...9.0.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Ekotik15/Determining_the_toxicity_of_comments-/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Ekotik15/Determining_the_toxicity_of_comments-/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekotik15%2FDetermining_the_toxicity_of_comments-/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5531481688","node_id":"PR_kwDOMTmvWs8AAAABEeaQrw","number":344,"state":"open","title":"chore(deps-dev): bump the minor-and-patch group in /libs/langchain-db2 with 4 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T19:26:32.000Z","updated_at":"2026-09-21T19:26:55.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps-dev): bump","group_name":"minor-and-patch","update_count":4,"packages":[{"name":"ruff","old_version":"0.16.4","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"langsmith","old_version":"0.11.1","new_version":"0.13.0","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"transformers","old_version":"5.15.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"urllib3","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"}],"path":"/libs/langchain-db2","ecosystem":"pip"},"body":"Bumps the minor-and-patch group in /libs/langchain-db2 with 4 updates: [ruff](https://github.com/astral-sh/ruff), [langsmith](https://github.com/langchain-ai/langsmith-sdk), [transformers](https://github.com/huggingface/transformers) and [urllib3](https://github.com/urllib3/urllib3).\n\nUpdates `ruff` from 0.16.4 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/releases\"\u003eruff's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.8\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-16.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eVisit functional \u003ccode\u003eTypedDict\u003c/code\u003e keyword arguments correctly (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28584\"\u003e#28584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Detect nested \u003ccode\u003easync with\u003c/code\u003e under sync parent (\u003ccode\u003eSIM117\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27821\"\u003e#27821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Preserve operand order in \u003ccode\u003eSIM109\u003c/code\u003e fix (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27824\"\u003e#27824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Preserve required parentheses in multiline \u003ccode\u003eUP040\u003c/code\u003e fixes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28164\"\u003e#28164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Skip \u003ccode\u003eTypeVarTuple\u003c/code\u003e and \u003ccode\u003eParamSpec\u003c/code\u003e conversions with bounds or constraints (\u003ccode\u003eUP040\u003c/code\u003e, \u003ccode\u003eUP046\u003c/code\u003e, \u003ccode\u003eUP047\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28505\"\u003e#28505\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28459\"\u003e#28459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize PEP-728 \u003ccode\u003eTypedDict\u003c/code\u003e class keywords (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28533\"\u003e#28533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize quoted types in \u003ccode\u003etyping.TypeForm\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28507\"\u003e#28507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport conditional assignment to \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28491\"\u003e#28491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-type-checking\u003c/code\u003e] Prefer lazy imports over \u003ccode\u003eTYPE_CHECKING\u003c/code\u003e on Python 3.15 and later (\u003ccode\u003eTC001\u003c/code\u003e, \u003ccode\u003eTC002\u003c/code\u003e, \u003ccode\u003eTC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28541\"\u003e#28541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Make the fix for \u003ccode\u003eUP040\u003c/code\u003e always unsafe (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28526\"\u003e#28526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending deprecated \u003ccode\u003eByteString\u003c/code\u003e aliases (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28498\"\u003e#28498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e, \u003ccode\u003eflake8-use-pathlib\u003c/code\u003e] Recognize the \u003ccode\u003eparent_mode\u003c/code\u003e argument (\u003ccode\u003eRUF064\u003c/code\u003e, \u003ccode\u003ePTH103\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28528\"\u003e#28528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Detect \u003ccode\u003e\\Z\u003c/code\u003e in \u003ccode\u003epytest.raises()\u003c/code\u003e match patterns (\u003ccode\u003eRUF043\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28598\"\u003e#28598\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse rule name and code in formatter incompatibility warnings (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28571\"\u003e#28571\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eConfiguration\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Add \u003ccode\u003eextend-banned-api\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28644\"\u003e#28644\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/VedantMadane\"\u003e\u003ccode\u003e@​VedantMadane\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alzeph\"\u003e\u003ccode\u003e@​alzeph\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fredrikblau\"\u003e\u003ccode\u003e@​fredrikblau\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Aniket-a14\"\u003e\u003ccode\u003e@​Aniket-a14\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r-b-1\"\u003e\u003ccode\u003e@​r-b-1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eInstall ruff 0.16.8\u003c/h2\u003e\n\u003ch3\u003eInstall prebuilt binaries via shell script\u003c/h3\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003ecurl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md\"\u003eruff's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.8\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-16.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eVisit functional \u003ccode\u003eTypedDict\u003c/code\u003e keyword arguments correctly (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28584\"\u003e#28584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Detect nested \u003ccode\u003easync with\u003c/code\u003e under sync parent (\u003ccode\u003eSIM117\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27821\"\u003e#27821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Preserve operand order in \u003ccode\u003eSIM109\u003c/code\u003e fix (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27824\"\u003e#27824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Preserve required parentheses in multiline \u003ccode\u003eUP040\u003c/code\u003e fixes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28164\"\u003e#28164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Skip \u003ccode\u003eTypeVarTuple\u003c/code\u003e and \u003ccode\u003eParamSpec\u003c/code\u003e conversions with bounds or constraints (\u003ccode\u003eUP040\u003c/code\u003e, \u003ccode\u003eUP046\u003c/code\u003e, \u003ccode\u003eUP047\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28505\"\u003e#28505\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28459\"\u003e#28459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize PEP-728 \u003ccode\u003eTypedDict\u003c/code\u003e class keywords (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28533\"\u003e#28533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize quoted types in \u003ccode\u003etyping.TypeForm\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28507\"\u003e#28507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport conditional assignment to \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28491\"\u003e#28491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-type-checking\u003c/code\u003e] Prefer lazy imports over \u003ccode\u003eTYPE_CHECKING\u003c/code\u003e on Python 3.15 and later (\u003ccode\u003eTC001\u003c/code\u003e, \u003ccode\u003eTC002\u003c/code\u003e, \u003ccode\u003eTC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28541\"\u003e#28541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Make the fix for \u003ccode\u003eUP040\u003c/code\u003e always unsafe (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28526\"\u003e#28526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending deprecated \u003ccode\u003eByteString\u003c/code\u003e aliases (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28498\"\u003e#28498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e, \u003ccode\u003eflake8-use-pathlib\u003c/code\u003e] Recognize the \u003ccode\u003eparent_mode\u003c/code\u003e argument (\u003ccode\u003eRUF064\u003c/code\u003e, \u003ccode\u003ePTH103\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28528\"\u003e#28528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Detect \u003ccode\u003e\\Z\u003c/code\u003e in \u003ccode\u003epytest.raises()\u003c/code\u003e match patterns (\u003ccode\u003eRUF043\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28598\"\u003e#28598\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse rule name and code in formatter incompatibility warnings (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28571\"\u003e#28571\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eConfiguration\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Add \u003ccode\u003eextend-banned-api\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28644\"\u003e#28644\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/VedantMadane\"\u003e\u003ccode\u003e@​VedantMadane\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alzeph\"\u003e\u003ccode\u003e@​alzeph\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fredrikblau\"\u003e\u003ccode\u003e@​fredrikblau\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Aniket-a14\"\u003e\u003ccode\u003e@​Aniket-a14\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r-b-1\"\u003e\u003ccode\u003e@​r-b-1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/62914c4b9b79a9e5004374a9c482ad2ed69290e1\"\u003e\u003ccode\u003e62914c4\u003c/code\u003e\u003c/a\u003e Bump version to 0.16.8 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28648\"\u003e#28648\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/c47e0cdc665f56536ce7f7a8ac40fa0ff3f79482\"\u003e\u003ccode\u003ec47e0cd\u003c/code\u003e\u003c/a\u003e [ty] Bound aliased intersection expansion during inference (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28546\"\u003e#28546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/ff4747b509ab4fffbe5689fcae39caa7503d1dcf\"\u003e\u003ccode\u003eff4747b\u003c/code\u003e\u003c/a\u003e renovate: update uv hashes correctly with setup-uv (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28621\"\u003e#28621\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/94efeaa28630d80b2a74adf3c3963de99ed4ee29\"\u003e\u003ccode\u003e94efeaa\u003c/code\u003e\u003c/a\u003e [ty] Compact reachable binding and declaration histories (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28349\"\u003e#28349\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/50020fb1e8aa83b0826fa6f5f33a1e93c10cc60e\"\u003e\u003ccode\u003e50020fb\u003c/code\u003e\u003c/a\u003e [ty] Avoid storing constraint nodes twice (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28375\"\u003e#28375\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/446bb68da50014bb75f5ce1504a80c5883e3b0b2\"\u003e\u003ccode\u003e446bb68\u003c/code\u003e\u003c/a\u003e [ty] Compare bound-method receivers before signatures (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28384\"\u003e#28384\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/304ab86be5de6507e276ab09f5b43f44aeb92469\"\u003e\u003ccode\u003e304ab86\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eflake8-type-checking\u003c/code\u003e] Prefer lazy imports over \u003ccode\u003eTYPE_CHECKING\u003c/code\u003e on 3.15+ (`...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/d940b244f7512427b0d87c7953e88c60e69f9bdf\"\u003e\u003ccode\u003ed940b24\u003c/code\u003e\u003c/a\u003e [ty] Watch script dependencies in CLI watch mode (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28125\"\u003e#28125\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/fe9f065a504127b11da72c2ff6d7813ddf3ce8ac\"\u003e\u003ccode\u003efe9f065\u003c/code\u003e\u003c/a\u003e [flake8-tidy-imports] Add \u003ccode\u003eextend-banned-api\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28644\"\u003e#28644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/31131db44f057cce68fa6b95552b7db54167b0b3\"\u003e\u003ccode\u003e31131db\u003c/code\u003e\u003c/a\u003e [ty] Support \u003ccode\u003etype[A \u0026amp; B]\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/27124\"\u003e#27124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/astral-sh/ruff/compare/0.16.4...0.16.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langsmith` from 0.11.1 to 0.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/releases\"\u003elangsmith's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.13.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(evaluate): add disable_evaluator_tracing toggle to evaluate() and aevaluate() by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3547\"\u003elangchain-ai/langsmith-sdk#3547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(openwiki): open the update PR with gh instead of a third-party action by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3545\"\u003elangchain-ai/langsmith-sdk#3545\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(sandbox): deprecate no_proxy in proxy config helpers by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3512\"\u003elangchain-ai/langsmith-sdk#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): preserve the 403 JSON error body in raiseForStatus by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3548\"\u003elangchain-ai/langsmith-sdk#3548\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sandbox): support AWS IAM roles in Python and JavaScript helpers by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3536\"\u003elangchain-ai/langsmith-sdk#3536\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sandbox): run_config, stdin EOF, and native file search/range ops by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3522\"\u003elangchain-ai/langsmith-sdk#3522\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(js): add disableEvaluatorTracing option to evaluate() by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3549\"\u003elangchain-ai/langsmith-sdk#3549\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sandbox): stream commands over the SSE exec API behind a feature flag by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3553\"\u003elangchain-ai/langsmith-sdk#3553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(py,js): log which source the client resolved its API URL from by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3557\"\u003elangchain-ai/langsmith-sdk#3557\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.13.0 by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3555\"\u003elangchain-ai/langsmith-sdk#3555\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.6...v0.13.0\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.12.6...v0.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003erelease(js): 0.10.4 by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3542\"\u003elangchain-ai/langsmith-sdk#3542\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add OpenWiki, with a weekly refresh workflow by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3541\"\u003elangchain-ai/langsmith-sdk#3541\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(livekit): preserve system instructions with history by \u003ca href=\"https://github.com/carolinedivittorio\"\u003e\u003ccode\u003e@​carolinedivittorio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3544\"\u003elangchain-ai/langsmith-sdk#3544\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.12.6 by \u003ca href=\"https://github.com/carolinedivittorio\"\u003e\u003ccode\u003e@​carolinedivittorio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3546\"\u003elangchain-ai/langsmith-sdk#3546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.5...v0.12.6\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.12.5...v0.12.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: preserve sandbox API error IDs by \u003ca href=\"https://github.com/langchain-infra\"\u003e\u003ccode\u003e@​langchain-infra\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3515\"\u003elangchain-ai/langsmith-sdk#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): avoid stored reasoning in OpenAI integration tests by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3519\"\u003elangchain-ai/langsmith-sdk#3519\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): update vulnerable test dependencies by \u003ca href=\"https://github.com/linted\"\u003e\u003ccode\u003e@​linted\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3525\"\u003elangchain-ai/langsmith-sdk#3525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump js-yaml from 3.15.1 to 4.3.1 in /js/internal/environment_tests/test-exports-metro in the npm_and_yarn group across 1 directory by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3526\"\u003elangchain-ai/langsmith-sdk#3526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): patch vulnerable Vitest and Hono dependencies by \u003ca href=\"https://github.com/jkennedyvz\"\u003e\u003ccode\u003e@​jkennedyvz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3516\"\u003elangchain-ai/langsmith-sdk#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(js): 0.10.3 by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3509\"\u003elangchain-ai/langsmith-sdk#3509\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js,py): tag guardrail/subagent structurally in openai-agents integration by \u003ca href=\"https://github.com/ybathula707\"\u003e\u003ccode\u003e@​ybathula707\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3523\"\u003elangchain-ai/langsmith-sdk#3523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(py,js): report the configured tracing sample rate on runs by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3492\"\u003elangchain-ai/langsmith-sdk#3492\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): upgrade vulnerable js-yaml and sharp by \u003ca href=\"https://github.com/linted\"\u003e\u003ccode\u003e@​linted\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3535\"\u003elangchain-ai/langsmith-sdk#3535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(py): stop sandbox run() from waiting ~1s on the server's TCP close after exit by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3538\"\u003elangchain-ai/langsmith-sdk#3538\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(py): carry the ADK tool call ids into traced messages [LSDK-509] by \u003ca href=\"https://github.com/zduric-langchain\"\u003e\u003ccode\u003e@​zduric-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3506\"\u003elangchain-ai/langsmith-sdk#3506\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.12.5 by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3540\"\u003elangchain-ai/langsmith-sdk#3540\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/linted\"\u003e\u003ccode\u003e@​linted\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3525\"\u003elangchain-ai/langsmith-sdk#3525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zduric-langchain\"\u003e\u003ccode\u003e@​zduric-langchain\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3506\"\u003elangchain-ai/langsmith-sdk#3506\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.4...v0.12.5\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.12.4...v0.12.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(livekit): support agents 1.7 and 1.8 telemetry [Closes LSDK-506] by \u003ca href=\"https://github.com/carolinedivittorio\"\u003e\u003ccode\u003e@​carolinedivittorio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3510\"\u003elangchain-ai/langsmith-sdk#3510\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/e6863ca150cc678b737a236736ec878c1ee3c573\"\u003e\u003ccode\u003ee6863ca\u003c/code\u003e\u003c/a\u003e release(py): 0.13.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3555\"\u003e#3555\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/d0357078254706001f03bcdfa695a3a76b365e2d\"\u003e\u003ccode\u003ed035707\u003c/code\u003e\u003c/a\u003e feat(py,js): log which source the client resolved its API URL from (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3557\"\u003e#3557\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/47b85327a6a951d87bcdaa6b0751c1b85c0df02e\"\u003e\u003ccode\u003e47b8532\u003c/code\u003e\u003c/a\u003e feat(sandbox): stream commands over the SSE exec API behind a feature flag (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/e4370d68031f088764424a996e213329d763138e\"\u003e\u003ccode\u003ee4370d6\u003c/code\u003e\u003c/a\u003e feat(js): add disableEvaluatorTracing option to evaluate() (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3549\"\u003e#3549\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/69406a65e87c4945c0ff1b507f778e4389adbb45\"\u003e\u003ccode\u003e69406a6\u003c/code\u003e\u003c/a\u003e feat(sandbox): run_config, stdin EOF, and native file search/range ops (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3522\"\u003e#3522\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/529f970494887b75aa7daf50230e65f4be565851\"\u003e\u003ccode\u003e529f970\u003c/code\u003e\u003c/a\u003e feat(sandbox): support AWS IAM roles in Python and JavaScript helpers (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3536\"\u003e#3536\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/cc38f3cbb16af77b9faf9bbc49040d3f4563daae\"\u003e\u003ccode\u003ecc38f3c\u003c/code\u003e\u003c/a\u003e fix(js): preserve the 403 JSON error body in raiseForStatus (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3548\"\u003e#3548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/6bf054e09c225fa46abd1e4ead6825a09d683a26\"\u003e\u003ccode\u003e6bf054e\u003c/code\u003e\u003c/a\u003e refactor(sandbox): deprecate no_proxy in proxy config helpers (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3512\"\u003e#3512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/68342eae8047a39379c1f848390a7c5995a9166d\"\u003e\u003ccode\u003e68342ea\u003c/code\u003e\u003c/a\u003e ci(openwiki): open the update PR with gh instead of a third-party action (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3545\"\u003e#3545\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/b771c204344e33e913094517bfca43309a1a92c5\"\u003e\u003ccode\u003eb771c20\u003c/code\u003e\u003c/a\u003e feat(evaluate): add disable_evaluator_tracing toggle to evaluate() and aevalu...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.7.0 to 2.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/releases\"\u003eurllib3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.8.0\u003c/h2\u003e\n\u003ch2\u003e🚀 urllib3 is fundraising for HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support\"\u003eurllib3 is raising ~$40,000 USD\u003c/a\u003e to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects \u003ca href=\"https://opencollective.com/urllib3\"\u003eplease consider contributing financially\u003c/a\u003e to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.\u003c/p\u003e\n\u003cp\u003eThank you for your support.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eFixed the following security issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eread_chunked()\u003c/code\u003e could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)\u003c/li\u003e\n\u003cli\u003eChunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nurllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.\u003c/p\u003e\n\u003cp\u003eConfigure proxy CA certificates and client certificates in \u003ccode\u003eproxy_ssl_context\u003c/code\u003e, and proxy identity checks with \u003ccode\u003eproxy_assert_hostname\u003c/code\u003e or \u003ccode\u003eproxy_assert_fingerprint\u003c/code\u003e. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nCVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eDeprecations \u0026amp; Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecated using an empty collection as the \u003ccode\u003eRetry\u003c/code\u003e option \u003ccode\u003eallowed_methods\u003c/code\u003e to retry any verb. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5044\"\u003e#5044\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eUrl.auth_decoded\u003c/code\u003e and \u003ccode\u003eUrl.auth_decoded_joined\u003c/code\u003e convenience properties to the result of \u003ccode\u003eparse_url()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4945\"\u003e#4945\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003ebasic_auth_encoding\u003c/code\u003e and \u003ccode\u003eproxy_basic_auth_encoding\u003c/code\u003e parameters to \u003ccode\u003eurllib3.util.make_headers()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5092\"\u003e#5092\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFixed response header handling to replace obsolete folded header lines (\u003ccode\u003eobs-fold\u003c/code\u003e) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as \u003ccode\u003eSet-Cookie\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/1362\"\u003e#1362\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed usage of \u003ccode\u003eproxy_ssl_context\u003c/code\u003e with \u003ccode\u003eProxyManager\u003c/code\u003e when \u003ccode\u003euse_forwarding_for_https=True\u003c/code\u003e. Passing \u003ccode\u003essl_context\u003c/code\u003e instead of \u003ccode\u003eproxy_ssl_context\u003c/code\u003e for HTTPS proxies in this configuration now emits a \u003ccode\u003eFutureWarning\u003c/code\u003e and will raise an error in v3.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/2577\"\u003e#2577\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged behavior of the default \u003ccode\u003eConnectionPool.pool\u003c/code\u003e initialization. \u003ccode\u003eLifoQueue\u003c/code\u003e is now resolved from the \u003ccode\u003equeue\u003c/code\u003e module after the \u003ccode\u003eConnectionPool\u003c/code\u003e is instantiated instead of using the default cached \u003ccode\u003eQueueCls\u003c/code\u003e class property. This is done because sometimes the \u003ccode\u003equeue.LifoQueue\u003c/code\u003e is monkey-patched late in the program, such as by gevent. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3289\"\u003e#3289\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRaised \u003ccode\u003eUnrewindableBodyError\u003c/code\u003e instead of \u003ccode\u003eValueError\u003c/code\u003e when retrying a request whose body had \u003ccode\u003etell()\u003c/code\u003e but not \u003ccode\u003eseek()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3779\"\u003e#3779\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDecoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3785\"\u003e#3785\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e to discard unread response data in 64 KiB chunks (same as the default \u003ccode\u003eamt\u003c/code\u003e when doing \u003ccode\u003eHTTPResponse.stream(...)\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5019\"\u003e#5019\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eis_ipaddress()\u003c/code\u003e to detect non-standard IPv4 forms accepted by \u003ccode\u003esocket.connect\u003c/code\u003e, such as hex (\u003ccode\u003e0x7f000001\u003c/code\u003e), octal (\u003ccode\u003e0177.0.0.1\u003c/code\u003e), and decimal integers (\u003ccode\u003e2130706433\u003c/code\u003e), ensuring SSL certificate verification uses the correct mode for these addresses. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5029\"\u003e#5029\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPConnectionPool.urlopen\u003c/code\u003e raising a misleading \u003ccode\u003eFullPoolError\u003c/code\u003e instead of \u003ccode\u003eValueError\u003c/code\u003e when called with an invalid \u003ccode\u003etimeout\u003c/code\u003e argument on a pool created with \u003ccode\u003eblock=True\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5059\"\u003e#5059\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed port-zero handling to preserve explicit \u003ccode\u003e:0\u003c/code\u003e values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, \u003ccode\u003econnection_from_url()\u003c/code\u003e, and HTTP/2 request authority. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5071\"\u003e#5071\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5101\"\u003e#5101\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed a bug where \u003ccode\u003ePoolManager\u003c/code\u003e passed the \u003ccode\u003eassert_hostname\u003c/code\u003e and \u003ccode\u003eassert_fingerprint\u003c/code\u003e parameters to HTTP connection pools. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5077\"\u003e#5077\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPConnectionPool.urlopen()\u003c/code\u003e and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5079\"\u003e#5079\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5091\"\u003e#5091\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPSConnection.connect()\u003c/code\u003e overriding \u003ccode\u003eProxyConfig.ssl_context\u003c/code\u003e's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eHTTPSConnection\u003c/code\u003e no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its \u003ccode\u003essl_context\u003c/code\u003e as a fallback when an HTTPS proxy forwards an HTTP target. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5093\"\u003e#5093\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5095\"\u003e#5095\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst\"\u003eurllib3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.8.0 (2026-09-15)\u003c/h1\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eFixed the following security issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe TLS configuration for HTTPS proxies could be ignored or overridden.\n(High severity, \u003ccode\u003eGHSA-8988-9cw3-xx77 \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eread_chunked()\u003c/code\u003e could buffer a chunk-size\nline of unbounded length in memory. (High severity,\n\u003ccode\u003eGHSA-vxq7-64xx-v4gw \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eChunked Deflate streaming could enter an infinite loop. (Medium severity,\n\u003ccode\u003eGHSA-gh4c-6fx4-qh6g \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e.. caution::\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eurllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or\noverridden by destination settings. Configurations relying on that\nbehavior may require changes.\n\u003cp\u003eConfigure proxy CA certificates and client certificates in\n\u003ccode\u003eproxy_ssl_context\u003c/code\u003e, and proxy identity checks with\n\u003ccode\u003eproxy_assert_hostname\u003c/code\u003e or \u003ccode\u003eproxy_assert_fingerprint\u003c/code\u003e.\nDestination client certificates and identity overrides no longer\napply to HTTPS forwarding proxy connections.\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch2\u003eDeprecations \u0026amp; Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecated using an empty collection as the \u003ccode\u003eRetry\u003c/code\u003e option\n\u003ccode\u003eallowed_methods\u003c/code\u003e to retry any verb.\n(\u003ccode\u003e[#5044](https://github.com/urllib3/urllib3/issues/5044) \u0026lt;https://github.com/urllib3/urllib3/issues/5044\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eUrl.auth_decoded\u003c/code\u003e and \u003ccode\u003eUrl.auth_decoded_joined\u003c/code\u003e convenience\nproperties to the result of \u003ccode\u003eparse_url()\u003c/code\u003e.\n(\u003ccode\u003e[#4945](https://github.com/urllib3/urllib3/issues/4945) \u0026lt;https://github.com/urllib3/urllib3/issues/4945\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003ebasic_auth_encoding\u003c/code\u003e and \u003ccode\u003eproxy_basic_auth_encoding\u003c/code\u003e parameters to\n\u003ccode\u003eurllib3.util.make_headers()\u003c/code\u003e.\n(\u003ccode\u003e[#5092](https://github.com/urllib3/urllib3/issues/5092) \u0026lt;https://github.com/urllib3/urllib3/issues/5092\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a\"\u003e\u003ccode\u003eb1d30ab\u003c/code\u003e\u003c/a\u003e Release 2.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e\"\u003e\u003ccode\u003e9016d7e\u003c/code\u003e\u003c/a\u003e Skip \u003ccode\u003etest_read_chunked_with_trailing_data_does_not_hang\u003c/code\u003e for brotlicffi (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5258\"\u003e#5258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533\"\u003e\u003ccode\u003e9101f58\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003enox -s docs\u003c/code\u003e warning (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5256\"\u003e#5256\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed\"\u003e\u003ccode\u003ecd770b0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f\"\u003e\u003ccode\u003eea2ad7b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8\"\u003e\u003ccode\u003e0716e31\u003c/code\u003e\u003c/a\u003e Fix loading unencrypted client keys with a password in pyOpenSSL (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5255\"\u003e#5255\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d\"\u003e\u003ccode\u003e43c68c8\u003c/code\u003e\u003c/a\u003e Test pickling of \u003ccode\u003eInvalidChunkLength\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5247\"\u003e#5247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817\"\u003e\u003ccode\u003e308b279\u003c/code\u003e\u003c/a\u003e Share security policy between GitHub and Read the Docs (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5253\"\u003e#5253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706\"\u003e\u003ccode\u003e53fa073\u003c/code\u003e\u003c/a\u003e Add policy on duplicate pull requests (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5252\"\u003e#5252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267\"\u003e\u003ccode\u003e5f2a6a8\u003c/code\u003e\u003c/a\u003e Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5232\"\u003e#5232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/langchain-ai/langchain-ibm/pull/344","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/langchain-ai%2Flangchain-ibm/issues/344","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/344/packages"},{"uuid":"5531249555","node_id":"PR_kwDOQTfEL88AAAABEeOTKQ","number":225,"state":"closed","title":"chore(deps): bump transformers from 5.5.0 to 5.17.0 in the python-minor group","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-21T19:07:31.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-21T19:03:16.000Z","updated_at":"2026-09-21T19:07:40.000Z","time_to_close":255,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"transformers","old_version":"5.5.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":"the python-minor group","ecosystem":"pip"},"body":"Bumps the python-minor group with 1 update: [transformers](https://github.com/huggingface/transformers).\n\nUpdates `transformers` from 5.5.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=transformers\u0026package-manager=pip\u0026previous-version=5.5.0\u0026new-version=5.17.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/AmaniQuery/amaniquery-prototype/pull/225","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/AmaniQuery%2Famaniquery-prototype/issues/225","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/225/packages"},{"uuid":"5513101412","node_id":"PR_kwDOT_waCs8AAAABEP-mQw","number":89,"state":"open","title":"build(deps): bump the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T19:44:57.000Z","updated_at":"2026-09-19T19:44:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip-minor-patch","update_count":70,"packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"annotated-doc","old_version":"0.0.4","new_version":"0.0.5","repository_url":"https://github.com/fastapi/annotated-doc"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"build","old_version":"1.5.0","new_version":"1.6.1","repository_url":"https://github.com/pypa/build"},{"name":"certifi","old_version":"2026.6.17","new_version":"2026.7.22","repository_url":"https://github.com/certifi/python-certifi"},{"name":"cffi","old_version":"2.1.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.9","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cloudpathlib","old_version":"0.24.0","new_version":"0.25.0","repository_url":"https://github.com/drivendataorg/cloudpathlib"},{"name":"contourpy","old_version":"1.3.3","new_version":"1.4.0","repository_url":"https://github.com/contourpy/contourpy"},{"name":"durationpy","old_version":"0.10","new_version":"0.11","repository_url":"https://github.com/icholy/durationpy"},{"name":"fastapi","old_version":"0.139.2","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"filelock","old_version":"3.30.2","new_version":"3.32.7","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"fsspec","old_version":"2026.6.0","new_version":"2026.7.0","repository_url":"https://github.com/fsspec/filesystem_spec"},{"name":"google-auth","old_version":"2.55.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-genai","old_version":"2.12.0","new_version":"2.23.0","repository_url":"https://github.com/googleapis/python-genai"},{"name":"googleapis-common-protos","old_version":"1.75.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"grpcio","old_version":"1.82.1","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"hf-xet","old_version":"1.5.2","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"huggingface-hub","old_version":"1.23.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"idna","old_version":"3.18","new_version":"3.19","repository_url":"https://github.com/kjd/idna"},{"name":"jiter","old_version":"0.16.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"kiwisolver","old_version":"1.5.0","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"langchain","old_version":"1.3.14","new_version":"1.4.1","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-core","old_version":"1.4.9","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-google-genai","old_version":"4.2.7","new_version":"4.4.0","repository_url":"https://github.com/langchain-ai/langchain-google"},{"name":"langchain-protocol","old_version":"0.0.18","new_version":"0.0.19","repository_url":"https://github.com/langchain-ai/agent-protocol"},{"name":"langgraph","old_version":"1.2.9","new_version":"1.2.11","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-checkpoint","old_version":"4.1.1","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-sdk","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langsmith","old_version":"0.10.5","new_version":"0.12.6","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"mmh3","old_version":"5.2.1","new_version":"5.3.0","repository_url":"https://github.com/hajimes/mmh3"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"multidict","old_version":"6.7.1","new_version":"6.8.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.24.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"numpy","old_version":"2.5.1","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"onnxruntime","old_version":"1.27.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"orjson","old_version":"3.11.9","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"packaging","old_version":"26.2","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"pandas","old_version":"3.0.3","new_version":"3.0.5","repository_url":"https://github.com/pandas-dev/pandas"},{"name":"propcache","old_version":"0.5.2","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"protobuf","old_version":"7.35.1","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pydantic-core","old_version":"2.46.4","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pygments","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyproject-hooks","old_version":"1.2.0","new_version":"1.3.3","repository_url":"https://github.com/pypa/pyproject-hooks"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"regex","old_version":"2026.7.10","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"scikit-learn","old_version":"1.9.0","new_version":"1.9.1","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.18.0","new_version":"1.18.1","repository_url":"https://github.com/scipy/scipy"},{"name":"smart-open","old_version":"8.0.0","new_version":"8.0.1","repository_url":"https://github.com/piskvorky/smart_open"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"threadpoolctl","old_version":"3.6.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"tqdm","old_version":"4.68.4","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"typing-inspection","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/pydantic/typing-inspection"},{"name":"tzdata","old_version":"2026.3","new_version":"2026.4","repository_url":"https://github.com/python/tzdata"},{"name":"urllib3","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.51.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"wrapt","old_version":"2.2.2","new_version":"2.4.1","repository_url":"https://github.com/GrahamDumpleton/wrapt"},{"name":"yarl","old_version":"1.24.2","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"}],"path":"/services/ai-orchestrator-service","ecosystem":"pip"},"body":"Bumps the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [build](https://github.com/pypa/build) | `1.5.0` | `1.6.1` |\n| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cloudpathlib](https://github.com/drivendataorg/cloudpathlib) | `0.24.0` | `0.25.0` |\n| [contourpy](https://github.com/contourpy/contourpy) | `1.3.3` | `1.4.0` |\n| [durationpy](https://github.com/icholy/durationpy) | `0.10` | `0.11` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.2` | `0.141.1` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.30.2` | `3.32.7` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| [fsspec](https://github.com/fsspec/filesystem_spec) | `2026.6.0` | `2026.7.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.55.2` | `2.58.0` |\n| [google-genai](https://github.com/googleapis/python-genai) | `2.12.0` | `2.23.0` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.0` | `1.75.3` |\n| [grpcio](https://github.com/grpc/grpc) | `1.82.1` | `1.84.0` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.2` | `1.6.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.23.0` | `1.31.0` |\n| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |\n| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.5.0` | `1.5.1` |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.3.14` | `1.4.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.4.9` | `1.6.3` |\n| [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.2.7` | `4.4.0` |\n| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) | `0.0.18` | `0.0.19` |\n| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.9` | `1.2.11` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.1.1` | `4.2.0` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.2` | `0.4.4` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.5` | `0.12.6` |\n| [mmh3](https://github.com/hajimes/mmh3) | `5.2.1` | `5.3.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.8.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.24.0` | `2.26.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.1` | `2.5.3` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.27.0` | `1.30.0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |\n| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |\n| [pandas](https://github.com/pandas-dev/pandas) | `3.0.3` | `3.0.5` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.5.2` | `0.5.4` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.1` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.4` | `2.49.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |\n| [pyproject-hooks](https://github.com/pypa/pyproject-hooks) | `1.2.0` | `1.3.3` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.7.10` | `2026.9.10` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` |\n| [scipy](https://github.com/scipy/scipy) | `1.18.0` | `1.18.1` |\n| [smart-open](https://github.com/piskvorky/smart_open) | `8.0.0` | `8.0.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.6.0` | `3.7.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.68.4` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |\n| [tzdata](https://github.com/python/tzdata) | `2026.3` | `2026.4` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.51.0` | `0.53.0` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.2.2` | `2.4.1` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.2` | `1.25.1` |\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `annotated-doc` from 0.0.4 to 0.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/releases\"\u003eannotated-doc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.27 to 0.0.33. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/52\"\u003e#52\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/blob/main/release-notes.md\"\u003eannotated-doc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5 (2026-07-28)\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef48d6ad51d226f772fd9c5284f55199afe4007c\"\u003e\u003ccode\u003eef48d6a\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.0.5 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/93\"\u003e#93\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/c628000835a26f6bc8c776f90bcbcf95211f233b\"\u003e\u003ccode\u003ec628000\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/e0b4579d2ad8d62a304c9f30a1c2c084f0d372e5\"\u003e\u003ccode\u003ee0b4579\u003c/code\u003e\u003c/a\u003e ➖ Drop support for Python 3.8 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/36\"\u003e#36\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef956b4e9f2c0e2bead1cba7a6888e1ed8c2c237\"\u003e\u003ccode\u003eef956b4\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/84bf1e5402c5e0cfd1462c5d3c8bae22fb717bd8\"\u003e\u003ccode\u003e84bf1e5\u003c/code\u003e\u003c/a\u003e ⬆️ Upgrade latest-changes to 0.7.1 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cf773e138b1dc5608ce0f0d11e1939c410ef6228\"\u003e\u003ccode\u003ecf773e1\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/1375d6eb8147cb2352d080ef09f356dfc18e0d29\"\u003e\u003ccode\u003e1375d6e\u003c/code\u003e\u003c/a\u003e ⬆ Bump the github-actions group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/91\"\u003e#91\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cd373656cbf40e5fd4cc28680ca5e05bf12709cb\"\u003e\u003ccode\u003ecd37365\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/f9f3b695cbacc4ffc37d9cebff6e05bd1751f68a\"\u003e\u003ccode\u003ef9f3b69\u003c/code\u003e\u003c/a\u003e ⬆ Bump the python-packages group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/842084457f0a7739fb91d2a4ea602b2bc4e15767\"\u003e\u003ccode\u003e8420844\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/annotated-doc/compare/0.0.4...0.0.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `annotated-types` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/annotated-types/annotated-types/releases\"\u003eannotated-types's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRename DocInfo to Doc by \u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.13 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix docstring of \u003ccode\u003eTimezone\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/84\"\u003eannotated-types/annotated-types#84\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) by \u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: typo in README.md by \u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd CI for PyPy3.11 and fix test (issue 71) by \u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix string predicate names in doc by \u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd SPDX license expression by \u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Python 3.14 to the test matrix by \u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.14 and drop EOL 3.8-3.9 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/97\"\u003eannotated-types/annotated-types#97\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix typo in \u003ccode\u003eLen\u003c/code\u003e docstring by \u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare for 0.8.0 release by \u003ca href=\"https://github.com/adriangb\"\u003e\u003ccode\u003e@​adriangb\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/103\"\u003eannotated-types/annotated-types#103\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ehttps://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/9eb96680138269811a39d838d720abc3dce33954\"\u003e\u003ccode\u003e9eb9668\u003c/code\u003e\u003c/a\u003e Prepare for 0.8.0 release (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/103\"\u003e#103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/10b77644f88b385357653730a1ab23748ca3ae2e\"\u003e\u003ccode\u003e10b7764\u003c/code\u003e\u003c/a\u003e Fix typo in \u003ccode\u003eLen\u003c/code\u003e docstring (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/100\"\u003e#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/955f7576d616feb6e9407c74498517787c38afd4\"\u003e\u003ccode\u003e955f757\u003c/code\u003e\u003c/a\u003e Add support for Python 3.14 and drop EOL 3.8-3.9 (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/97\"\u003e#97\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/bd280fea7983550d266f993d868b8dd7ff822bf1\"\u003e\u003ccode\u003ebd280fe\u003c/code\u003e\u003c/a\u003e Added Python 3.14 to the test matrix (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/96\"\u003e#96\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/a471bb757663452459893e6f593118ec21eb1b9e\"\u003e\u003ccode\u003ea471bb7\u003c/code\u003e\u003c/a\u003e Add SPDX license expression (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/eab91d9a8c0d3f73661fc4b0794a1fe76c94fa84\"\u003e\u003ccode\u003eeab91d9\u003c/code\u003e\u003c/a\u003e Fix string predicate names in doc (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/03ad9c3c7b4d4dfe9e33c09075a3a2766c0820e1\"\u003e\u003ccode\u003e03ad9c3\u003c/code\u003e\u003c/a\u003e add CI for PyPy3.11 and fix test (issue 71) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/88\"\u003e#88\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/5ae60437f0ab493cedd27311bc6ce6d2188e8d8b\"\u003e\u003ccode\u003e5ae6043\u003c/code\u003e\u003c/a\u003e fix: typo in README.md (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/87\"\u003e#87\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/b60ad7bff90019c7de3547df1c8e3586eb328423\"\u003e\u003ccode\u003eb60ad7b\u003c/code\u003e\u003c/a\u003e Update license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/86\"\u003e#86\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/3fbeb6d129760ae48d7a0372fb9301764acc95ae\"\u003e\u003ccode\u003e3fbeb6d\u003c/code\u003e\u003c/a\u003e Fix docstring of \u003ccode\u003eTimezone\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/84\"\u003e#84\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anyio` from 4.14.2 to 4.15.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.15.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplemented a compatibility fix for supporting direct access of \u003ccode\u003eanyio.*\u003c/code\u003e submodules from the main package even when those submodules were not directly imported first (\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311\"\u003e#1311\u003c/a\u003e \u0026lt;\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E\"\u003eagronholm/anyio#1311\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.15.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for the newer keyword-only arguments on \u003ccode\u003eanyio.Path\u003c/code\u003e methods to match the standard library \u003ccode\u003epathlib.Path\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eexists()\u003c/code\u003e (Python 3.12+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_dir()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_file()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eowner()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003egroup()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enewline\u003c/code\u003e on \u003ccode\u003eread_text()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1286\"\u003e#1286\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1293\"\u003e#1293\u003c/a\u003e; PR by \u003ca href=\"https://github.com/jaideeppyne\"\u003e\u003ccode\u003e@​jaideeppyne\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eamap\u003c/code\u003e, \u003ccode\u003egather\u003c/code\u003e, and \u003ccode\u003eas_completed\u003c/code\u003e utility functions to simplify common patterns (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1173\"\u003e#1173\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003e--anyio-mode\u003c/code\u003e command-line option as an alternative to the \u003ccode\u003eanyio_mode\u003c/code\u003e ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: \u003ccode\u003epytest_asyncio\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1242\"\u003e#1242\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003eanyio.Future\u003c/code\u003e synchronization primitive which behaves similar to \u003ccode\u003easyncio.Future\u003c/code\u003e, allowing tasks to wait for a value (or exception) from another task (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1146\"\u003e#1146\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Vizonex\"\u003e\u003ccode\u003e@​Vizonex\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded guidance for managing multiple memory object stream producers and consumers with cloned streams (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/330\"\u003e#330\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nightcityblade\"\u003e\u003ccode\u003e@​nightcityblade\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eStapledObjectStream.send_nowait()\u003c/code\u003e that delegates to the underlying \u003ccode\u003eObjectSendStream\u003c/code\u003e, if it implements it (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1241\"\u003e#1241\u003c/a\u003e; PR by \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003emove_on_at()\u003c/code\u003e and \u003ccode\u003efail_at()\u003c/code\u003e functions to complement \u003ccode\u003emove_on_after()\u003c/code\u003e and \u003ccode\u003efail_after()\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the default name for a task spawned with \u003ccode\u003eTaskGroup.create_task(func())\u003c/code\u003e to match the default task name for the analogous task spawned with \u003ccode\u003eTaskGroup.start_soon(func)\u003c/code\u003e or \u003ccode\u003eTaskGroup.start(func)\u003c/code\u003e in more situations. Previously, the default name of a \u003ccode\u003eTaskGroup.create_task\u003c/code\u003e task never included the module name. (The default name for a task spawned with \u003ccode\u003eTaskGroup.start_soon\u003c/code\u003e or \u003ccode\u003eTaskGroup.start\u003c/code\u003e typically includes the module name.) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1234\"\u003e#1234\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the \u003ccode\u003eanyio\u003c/code\u003e and \u003ccode\u003eanyio.abc\u003c/code\u003e modules to lazily (much like \u003ccode\u003e810\u003c/code\u003e) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the \u003ccode\u003eif TYPE_CHECKING:\u003c/code\u003e block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1169\"\u003e#1169\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to \u003ccode\u003estart_blocking_portal()\u003c/code\u003e and \u003ccode\u003eanyio.to_thread.run_sync()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1224\"\u003e#1224\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eSpooledTemporaryFile.readinto()\u003c/code\u003e and \u003ccode\u003ereadinto1()\u003c/code\u003e reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1215\"\u003e#1215\u003c/a\u003e; PR by \u003ca href=\"https://github.com/c-tonneslan\"\u003e\u003ccode\u003e@​c-tonneslan\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded a \u003ccode\u003ereason\u003c/code\u003e parameter to \u003ccode\u003efail_after\u003c/code\u003e (and the new \u003ccode\u003efail_at\u003c/code\u003e) allowing for added exception context when raising \u003ccode\u003eTimeoutError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1227\"\u003e#1227\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the default \u003ccode\u003eTaskHandle.name\u003c/code\u003e missing part of the task name for tasks started with \u003ccode\u003eTaskGroup.start\u003c/code\u003e on Trio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1231\"\u003e#1231\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.run\u003c/code\u003e leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a \u003ccode\u003eRunVar\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1203\"\u003e#1203\u003c/a\u003e; PR by \u003ca href=\"https://github.com/tapetersen\"\u003e\u003ccode\u003e@​tapetersen\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.Path.with_stem()\u003c/code\u003e silently producing a wrong path (e.g. \u003ccode\u003ePath(\u0026quot;.txt\u0026quot;)\u003c/code\u003e) instead of raising \u003ccode\u003eValueError\u003c/code\u003e when given an empty stem on a path with a non-empty suffix, unlike \u003ccode\u003epathlib.PurePath.with_stem\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1200\"\u003e#1200\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Sanjays2402\"\u003e\u003ccode\u003e@​Sanjays2402\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eUNIXSocketStream.aclose()\u003c/code\u003e raising \u003ccode\u003easyncio.InvalidStateError\u003c/code\u003e when a concurrent receive or send operation had just been cancelled on the asyncio backend (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1267\"\u003e#1267\u003c/a\u003e; PR by \u003ca href=\"https://github.com/alloutflo\"\u003e\u003ccode\u003e@​alloutflo\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the pytest plugin importing the deprecated \u003ccode\u003e_pytest.python.CallSpec2\u003c/code\u003e alias, which triggers \u003ccode\u003ePytestRemovedIn10Warning\u003c/code\u003e on \u003ccode\u003epytest\u0026gt;=9.2\u003c/code\u003e and crashes pytest at startup when \u003ccode\u003efilterwarnings = error\u003c/code\u003e is configured (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1271\"\u003e#1271\u003c/a\u003e; PR by \u003ca href=\"https://github.com/matthewfeickert\"\u003e\u003ccode\u003e@​matthewfeickert\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed an asyncio worker thread race that could raise \u003ccode\u003eRuntimeError\u003c/code\u003e when the event loop closed between checking its state and scheduling the worker result (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1265\"\u003e#1265\u003c/a\u003e; PR by \u003ca href=\"https://github.com/hansu650\"\u003e\u003ccode\u003e@​hansu650\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens when \u003ccode\u003etotal_tokens\u003c/code\u003e was raised while the limiter was over-subscribed (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1223\"\u003e#1223\u003c/a\u003e; PR by \u003ca href=\"https://github.com/zelinewang\"\u003e\u003ccode\u003e@​zelinewang\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703\"\u003e\u003ccode\u003effcd154\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f\"\u003e\u003ccode\u003e0ecf5ed\u003c/code\u003e\u003c/a\u003e Added a workaround for third party code accessing unimported submodules (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f\"\u003e\u003ccode\u003e9283662\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d\"\u003e\u003ccode\u003ed137692\u003c/code\u003e\u003c/a\u003e Improved the instructions for AI agents\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265\"\u003e\u003ccode\u003e033fc52\u003c/code\u003e\u003c/a\u003e Shield TemporaryDirectory cleanup from cancellation (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc\"\u003e\u003ccode\u003e942e9a6\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1305\"\u003e#1305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704\"\u003e\u003ccode\u003eb825c3b\u003c/code\u003e\u003c/a\u003e Fixed pyproject.toml changes not triggering the test suite\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af\"\u003e\u003ccode\u003e9727dc5\u003c/code\u003e\u003c/a\u003e Fixed start inconsistencies between trio and asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1198\"\u003e#1198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8\"\u003e\u003ccode\u003eb05fe6d\u003c/code\u003e\u003c/a\u003e Fixed wrong type in move_on_after (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153\"\u003e\u003ccode\u003e44d0c93\u003c/code\u003e\u003c/a\u003e Fixed asyncio task group coroutine cleanup (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1275\"\u003e#1275\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.14.2...4.15.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `build` from 1.5.0 to 1.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/releases\"\u003ebuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.6.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore[v1]: prepare for v1.6.1 by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1181\"\u003epypa/build#1181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.6.0...1.6.1\"\u003ehttps://github.com/pypa/build/compare/1.6.0...1.6.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReplace prettier with mdformat and yamlfmt by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1133\"\u003epypa/build#1133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLet yamlfmt format the workflows by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1134\"\u003epypa/build#1134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(release): semver auto bump, changelog reflow, and roll back 1.5.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1132\"\u003epypa/build#1132\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: hash verification in --dependency-constraints-txt could be silently skipped by \u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): bump build-and-inspect-python-package to v3.0.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1147\"\u003epypa/build#1147\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): pin coverage core to ctrace so test contexts record by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1148\"\u003epypa/build#1148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: run mypy on more parts of the code by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1151\"\u003epypa/build#1151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: turn up strictness on mypy by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1153\"\u003epypa/build#1153\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: faster mypy, fix merge error by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1156\"\u003epypa/build#1156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): rerun integration tests on transient network errors by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1150\"\u003epypa/build#1150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: clean up unused casts in tests by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1154\"\u003epypa/build#1154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(typing): apply review feedback from \u003ca href=\"https://redirect.github.com/pypa/build/issues/1093\"\u003e#1093\u003c/a\u003e by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1155\"\u003epypa/build#1155\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Generator is more accurate than Iterator by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1152\"\u003epypa/build#1152\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: mark test_main_sdist_input_end_to_end with pytest.mark.network by \u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;⚠️ feat(util): deprecate project_wheel_metadata\u0026quot; by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1158\"\u003epypa/build#1158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: download integration sources once per run by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1157\"\u003epypa/build#1157\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse stdlib \u003ccode\u003eimportlib.metadata\u003c/code\u003e for typing by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1162\"\u003epypa/build#1162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop redundant \u003ccode\u003eexc_info\u003c/code\u003e parameter from backend exception wrapper by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1161\"\u003epypa/build#1161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop a few PyPy-specific test skips by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1164\"\u003epypa/build#1164\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1165\"\u003epypa/build#1165\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e👷 ci: use app token for releases by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1169\"\u003epypa/build#1169\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.5.1...1.6.0\"\u003ehttps://github.com/pypa/build/compare/1.5.1...1.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.5.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e✨ feat(cli): accept sdist tarball as srcdir argument by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1057\"\u003epypa/build#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: drop 3.9 branches for version_info checks by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1059\"\u003epypa/build#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: skip test_uv_install_strips_pythonpath with missing uv by \u003ca href=\"https://github.com/mtelka\"\u003e\u003ccode\u003e@​mtelka\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1063\"\u003epypa/build#1063\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove myself from codeowners by \u003ca href=\"https://github.com/FFY00\"\u003e\u003ccode\u003e@​FFY00\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1066\"\u003epypa/build#1066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: safe_extractall to use pathlib.Path by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1060\"\u003epypa/build#1060\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/blob/main/CHANGELOG.rst\"\u003ebuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e####################\n1.6.1 (2026-09-10)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:\u003ccode\u003ehenryiii\u003c/code\u003e (:issue:\u003ccode\u003e1175\u003c/code\u003e) (:issue:\u003ccode\u003e1175\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eDocumentation\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eFix doubled backslashes in the Windows pip config path (\u003ccode\u003e%APPDATA%\\pip\\pip.ini\u003c/code\u003e) in the docs - by :user:\u003ccode\u003earoh3006\u003c/code\u003e\n(:issue:\u003ccode\u003e1149\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eMiscellaneous\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e:issue:\u003ccode\u003e1168\u003c/code\u003e, :issue:\u003ccode\u003e1170\u003c/code\u003e, :issue:\u003ccode\u003e1178\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e####################\n1.6.0 (2026-08-27)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eFeatures\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003e--report=PATH\u003c/code\u003e to write a machine-readable JSON report of built artifacts; \u003ccode\u003e--metadata\u003c/code\u003e now also accepts\n\u003ccode\u003e.whl\u003c/code\u003e files - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e198\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esrcdir\u003c/code\u003e argument now accepts \u003ccode\u003e.tar.gz\u003c/code\u003e source distributions, extracting and building from them - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e311\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u0026quot;Unmet dependencies\u0026quot; error from \u003ccode\u003e--no-isolation\u003c/code\u003e builds now shows the wanted version, found version, and\ninterpreter - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e504\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e to extract the intermediate sdist into a persistent directory, enabling compiler cache\nreuse across rebuilds - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e614\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--env-dir\u003c/code\u003e to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds\n\u003cul\u003e\n\u003cli\u003eby :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e655\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePrint a summary of resolved dependency versions (\u003ccode\u003ename==version\u003c/code\u003e) after installing them in isolated builds - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e959\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eOn build failure, print a tip pointing to \u003ccode\u003e--env-dir\u003c/code\u003e and \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e for debugging and link to the\n\u0026quot;Debug a failed build\u0026quot; how-to - reported by :user:\u003ccode\u003edimpase\u003c/code\u003e, implemented by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e966\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/89cccef40df9011f03bec18cf52c53d1096ed6ee\"\u003e\u003ccode\u003e89cccef\u003c/code\u003e\u003c/a\u003e chore: prepare for 1.6.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/a6f707a75fc8548d7707645e97c7903197387849\"\u003e\u003ccode\u003ea6f707a\u003c/code\u003e\u003c/a\u003e ci: support releases from v* branches (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1178\"\u003e#1178\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/77851610de5d3894fa8a88e06e0232901cf93758\"\u003e\u003ccode\u003e7785161\u003c/code\u003e\u003c/a\u003e docs: fix doubled backslashes in Windows pip config path (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1149\"\u003e#1149\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/244b250c3219070eebb29764f7709262d48afd41\"\u003e\u003ccode\u003e244b250\u003c/code\u003e\u003c/a\u003e fix: always use copies for the isolated venv on Windows (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1176\"\u003e#1176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/c93ca6f6d252e4d8df7fda4a61f8f9ed8a55a411\"\u003e\u003ccode\u003ec93ca6f\u003c/code\u003e\u003c/a\u003e build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/e02ffd32241aec2e306d90869417c1e900c0adb4\"\u003e\u003ccode\u003ee02ffd3\u003c/code\u003e\u003c/a\u003e pre-commit: bump repositories (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1173\"\u003e#1173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/aad39a800e3d81bf907018ebe2fab135717da59b\"\u003e\u003ccode\u003eaad39a8\u003c/code\u003e\u003c/a\u003e docs: fix changelog page heading levels and sidebar (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1171\"\u003e#1171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/5c3fd46b5c38c7caea5dd95ce365971104a734aa\"\u003e\u003ccode\u003e5c3fd46\u003c/code\u003e\u003c/a\u003e docs: use PyPI ref directly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/1c5bd6c21cbd33c1816978d45219d48fb4c2b269\"\u003e\u003ccode\u003e1c5bd6c\u003c/code\u003e\u003c/a\u003e 🐛 fix(release): format generated changelog (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1170\"\u003e#1170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/7f0cc7ed19969558c7daeaa3652ce2ffc81599c1\"\u003e\u003ccode\u003e7f0cc7e\u003c/code\u003e\u003c/a\u003e 🔧 build(type): replace mypy with pyrefly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1168\"\u003e#1168\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/build/compare/1.5.0...1.6.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `certifi` from 2026.6.17 to 2026.7.22\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/f4bc676bc101fe2235846e37044e8c693d6cbaf4\"\u003e\u003ccode\u003ef4bc676\u003c/code\u003e\u003c/a\u003e 2026.07.22 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/428\"\u003e#428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/4c91f9c5f9b4676d40d2930025ba04d80dd536f6\"\u003e\u003ccode\u003e4c91f9c\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.3.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/427\"\u003e#427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/01a66c5cf32eadb8f03a0504c24cb44f6d581248\"\u003e\u003ccode\u003e01a66c5\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/426\"\u003e#426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/eb355f41cb71f71012ecf1a4d27a57d0ee2b1337\"\u003e\u003ccode\u003eeb355f4\u003c/code\u003e\u003c/a\u003e Bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/425\"\u003e#425\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/474e6fc996d55b91632248da0bade702504e62dc\"\u003e\u003ccode\u003e474e6fc\u003c/code\u003e\u003c/a\u003e Include tests in the source distribution (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/a31ef39bb5906af7dc9729890f7e4e04e75afdae\"\u003e\u003ccode\u003ea31ef39\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.2.0 to 6.3.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/420\"\u003e#420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/98eb2c76a9c7a8519912023dca00f762bbcd59af\"\u003e\u003ccode\u003e98eb2c7\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6.0.3 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/419\"\u003e#419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/certifi/python-certifi/compare/2026.06.17...2026.07.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cffi` from 2.1.0 to 2.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-cffi/cffi/releases\"\u003ecffi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMinimize internal Python API usage for interpreter and thread state sampling where possible. Avoids breaking ABI change in Python \u0026gt;= 3.15.0b4 (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/pull/269\"\u003epython-cffi/cffi#269\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/fd33e7700f0ebafe6f30bd5053f13327221b77a2\"\u003e\u003ccode\u003efd33e77\u003c/code\u003e\u003c/a\u003e New release 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/56a7876b8cd3b2d8148233a90e0121d74cd83852\"\u003e\u003ccode\u003e56a7876\u003c/code\u003e\u003c/a\u003e Use PyGILState_Ensure to avoid accessing CPython internals (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/269\"\u003e#269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/270\"\u003e#270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `charset-normalizer` from 3.4.9 to 3.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/releases\"\u003echarset-normalizer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.5.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.5.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md\"\u003echarset-normalizer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/e239bdc5cc1eb1f0db08d4046ad531f805dbea71\"\u003e\u003ccode\u003ee239bdc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/795\"\u003e#795\u003c/a\u003e from jawah/release-3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/648ad776db64a00aa7efd70a94656ac43784abb3\"\u003e\u003ccode\u003e648ad77\u003c/code\u003e\u003c/a\u003e docs: update faq\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/fab27492c39baa61aca12826022e266781108570\"\u003e\u003ccode\u003efab2749\u003c/code\u003e\u003c/a\u003e docs: write changelog for 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/7d32774e75d16cccd3d22c758a77fca135952787\"\u003e\u003ccode\u003e7d32774\u003c/code\u003e\u003c/a\u003e chore: bump version to 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/9a69f609f254ba4bfe9d0cbf375728e43360cdf2\"\u003e\u003ccode\u003e9a69f60\u003c/code\u003e\u003c/a\u003e docs: update data/info\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/5dcc6dd81a8a0a4bd525f8d6f508da8285caf402\"\u003e\u003ccode\u003e5dcc6dd\u003c/code\u003e\u003c/a\u003e perf: charinfo cache access optimization in cython\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/ea3b4479270762be1228562c590e5a212727f208\"\u003e\u003ccode\u003eea3b447\u003c/code\u003e\u003c/a\u003e fix: do not validate-decode large payload when md says it's noise\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/char...\n\n_Description has been truncated_","html_url":"https://github.com/RanugaVW/Clario-multiAgent-triage-micro-services/pull/89","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RanugaVW%2FClario-multiAgent-triage-micro-services/issues/89","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/89/packages"},{"uuid":"5506479377","node_id":"PR_kwDOUPlOCM8AAAABEKvAXA","number":119,"state":"open","title":"Bump the patch-and-minor group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T00:34:21.000Z","updated_at":"2026-09-19T00:34:22.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"patch-and-minor","update_count":5,"packages":[{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"transformers","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.30.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"ruff","old_version":"0.16.6","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"},{"name":"onnxruntime","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"}],"path":null,"ecosystem":"pip"},"body":"Bumps the patch-and-minor group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.16.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.30.0` | `1.31.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.29.0` | `1.30.0` |\n\nUpdates `uvicorn` from 0.52.4 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.16.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.30.0 to 1.31.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.31.0] Custom labels for Sandboxes, More resilient downloads and more\u003c/h2\u003e\n\u003ch2\u003e🏷️ Custom labels for Sandboxes\u003c/h2\u003e\n\u003cp\u003eDedicated sandboxes now accept custom labels, attached to the underlying Job. This is useful for cost attribution, bookkeeping, or finding and reconnecting to the sandboxes created by a given controller run. Labels use the same \u003ccode\u003e-l\u003c/code\u003e / \u003ccode\u003e--label KEY=VALUE\u003c/code\u003e syntax as \u003ccode\u003ehf jobs run\u003c/code\u003e. They are merged with the labels the SDK uses internally, and invalid or reserved labels are rejected before a billable Job is started. Pool-based sandboxes are unchanged: custom labels are only accepted for dedicated sandboxes.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e\u0026gt;\u0026gt;\u0026gt; from huggingface_hub import Sandbox\r\n\u0026gt;\u0026gt;\u0026gt; sandbox = Sandbox.create(image=\u0026quot;python:3.12\u0026quot;, labels={\u0026quot;controller-run\u0026quot;: \u0026quot;run-42\u0026quot;})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003ehf sandbox create --label controller-run=run-42 --label team=data-infra\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e[Sandbox] Support custom Job labels by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4824\"\u003e#4824\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📥 More resilient downloads\u003c/h2\u003e\n\u003cp\u003eA batch of fixes makes downloads more robust to unusual server responses, network hiccups and concurrent usage:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eA timeout while waiting for the response headers of a streamed download is now retried and resumed like a body read failure, instead of escaping \u003ccode\u003ehttp_get()\u003c/code\u003e while retries remain.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRegular HTTP downloads no longer fail when the HEAD response has no \u003ccode\u003eContent-Length\u003c/code\u003e. The file size is validated against the GET response when available.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003esnapshot_download\u003c/code\u003e now writes the \u003ccode\u003erefs/\u003c/code\u003e cache file atomically, reusing the logic already used by \u003ccode\u003ehf_hub_download\u003c/code\u003e. This fixes a long-standing race when many concurrent \u003ccode\u003esnapshot_download\u003c/code\u003e calls target the same repo (seen in vLLM / \u003ccode\u003ellm-compressor\u003c/code\u003e).\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003ehf download --dry-run --local-dir ...\u003c/code\u003e no longer copies files from the Hub cache into the destination. On large files and slow disks this looked like a hang and could leave an incomplete file behind.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Share retry handling for stream entry and body failures by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4826\"\u003e#4826\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Tolerate missing HEAD Content-Length by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4805\"\u003e#4805\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Write cache ref file atomically in \u003ccode\u003esnapshot_download\u003c/code\u003e by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4829\"\u003e#4829\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Prevent cached file copies during local-dir dry runs by \u003ca href=\"https://github.com/wakamex\"\u003e\u003ccode\u003e@​wakamex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4817\"\u003e#4817\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔌 \u003ccode\u003ehttpx\u003c/code\u003e re-exported for library integrators\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003ehuggingface_hub\u003c/code\u003e now re-exports the HTTP library it uses as \u003ccode\u003ehuggingface_hub.utils.httpx\u003c/code\u003e. Libraries built on top of \u003ccode\u003ehuggingface_hub\u003c/code\u003e that need \u003ccode\u003ehttpx\u003c/code\u003e types or exceptions (typically to catch errors) should import it from there rather than importing \u003ccode\u003ehttpx\u003c/code\u003e directly. v1.x is built on \u003ccode\u003ehttpx\u003c/code\u003e, and v2.x will move to its successor \u003ccode\u003ehttpx2\u003c/code\u003e, so importing through \u003ccode\u003ehuggingface_hub.utils\u003c/code\u003e keeps your code compatible with both. This is only for types and exceptions: to make requests to the Hub, keep using \u003ccode\u003eget_session()\u003c/code\u003e.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom huggingface_hub.utils import httpx\r\n\u003cp\u003etry:\n...\nexcept httpx.HTTPError:\n...\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/package_reference/utilities\"\u003eUtilities — The \u003ccode\u003ehttpx\u003c/code\u003e module\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[httpx migration] Expose \u003ccode\u003ehttpx\u003c/code\u003e as a \u003ccode\u003ehuggingface_hub\u003c/code\u003e submodule by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4803\"\u003e#4803\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eHfFileSystem.get()\u003c/code\u003e now validates remote filenames before writing anything locally. A server-side filename such as \u003ccode\u003efolder/..\\..\\outside.txt\u003c/code\u003e could previously escape the destination directory on Windows during a recursive download. The same check already protected \u003ccode\u003ehf_hub_download\u003c/code\u003e, \u003ccode\u003esnapshot_download\u003c/code\u003e and bucket sync. Unsafe filenames now raise \u003ccode\u003eValueError\u003c/code\u003e on all platforms, including when downloading to an explicitly named file or a file object.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/495b17c8529614759ae0f1ccf1ebe9a61c148b7c\"\u003e\u003ccode\u003e495b17c\u003c/code\u003e\u003c/a\u003e Release: v1.31.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/0f50db0d43f4e961337caefa64268fed47e31b78\"\u003e\u003ccode\u003e0f50db0\u003c/code\u003e\u003c/a\u003e Release: v1.31.0.rc1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d592df877089d8183489ea606885d777d7cb97f7\"\u003e\u003ccode\u003ed592df8\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;[Jobs] Add network groups to hf jobs run (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4833\"\u003e#4833\u003c/a\u003e)\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/3c08b69fe40b40e155f1fa00760b2b964b62f269\"\u003e\u003ccode\u003e3c08b69\u003c/code\u003e\u003c/a\u003e Release: v1.31.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f14866648507aa58afc9554c712a4e1f70dd5c3e\"\u003e\u003ccode\u003ef148666\u003c/code\u003e\u003c/a\u003e [CLI] Fix truncated command descriptions in the CLI reference (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4849\"\u003e#4849\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/c4f076ccd0b45fc24965a483285f8bbec40e7294\"\u003e\u003ccode\u003ec4f076c\u003c/code\u003e\u003c/a\u003e (LFS)Fix SliceFileObj.\u003cstrong\u003eiter\u003c/strong\u003e yielding only the first 4MB chunk (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4844\"\u003e#4844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/22fe960210ef1805ba88a381b7043123fa9f9714\"\u003e\u003ccode\u003e22fe960\u003c/code\u003e\u003c/a\u003e Fix dotenv parser truncating unquoted values containing '#' (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4842\"\u003e#4842\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6cae778caef0b61dc219d42461fcb20913cb27b9\"\u003e\u003ccode\u003e6cae778\u003c/code\u003e\u003c/a\u003e [Jobs] Add network groups to hf jobs run (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4833\"\u003e#4833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/063b37b1b6090d83660113fa28a58b56fa55444b\"\u003e\u003ccode\u003e063b37b\u003c/code\u003e\u003c/a\u003e [CLI] Raise explicit error for shell-script extensions on Windows (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4846\"\u003e#4846\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b9c14d9a51765d24832dfc2cda5fb826370be61b\"\u003e\u003ccode\u003eb9c14d9\u003c/code\u003e\u003c/a\u003e [Download] Write cache ref file atomically in \u003ccode\u003esnapshot_download\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4829\"\u003e#4829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.30.0...v1.31.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ruff` from 0.16.6 to 0.16.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/releases\"\u003eruff's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md\"\u003eruff's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nightt5879\"\u003e\u003ccode\u003e@​nightt5879\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13\"\u003e\u003ccode\u003eb5dba86\u003c/code\u003e\u003c/a\u003e Bump version to 0.16.7 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28496\"\u003e#28496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24\"\u003e\u003ccode\u003e5992d05\u003c/code\u003e\u003c/a\u003e Install rustfmt before linting releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28495\"\u003e#28495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8\"\u003e\u003ccode\u003e1713a1f\u003c/code\u003e\u003c/a\u003e ensure prepare release changes pass prek (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28488\"\u003e#28488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334\"\u003e\u003ccode\u003e18cdbb4\u003c/code\u003e\u003c/a\u003e use scoped token for release workflow (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28484\"\u003e#28484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd\"\u003e\u003ccode\u003ec3813a5\u003c/code\u003e\u003c/a\u003e add a workflow for preparing releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28486\"\u003e#28486\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38\"\u003e\u003ccode\u003e00948c0\u003c/code\u003e\u003c/a\u003e Remove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427\"\u003e\u003ccode\u003e86a2eba\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (`UP...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/609e184aa35f0034b7ef63e3e04327081c484af6\"\u003e\u003ccode\u003e609e184\u003c/code\u003e\u003c/a\u003e Stop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/859ff2f01670c43ffff1ea597c8a2e375ada0fbe\"\u003e\u003ccode\u003e859ff2f\u003c/code\u003e\u003c/a\u003e [ty] Track symlinked directory status in listings (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28482\"\u003e#28482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/77f653825800ddaf3bc221ae6db49a500e1002d5\"\u003e\u003ccode\u003e77f6538\u003c/code\u003e\u003c/a\u003e Use paid GitHub-hosted runners for Linux (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28478\"\u003e#28478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `onnxruntime` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxruntime/releases\"\u003eonnxruntime's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eONNX Runtime v1.30.0\u003c/h2\u003e\n\u003cp\u003eONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32168\"\u003e#32168\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32340\"\u003e#32340\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32515\"\u003e#32515\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31727\"\u003e#31727\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32277\"\u003e#32277\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32284\"\u003e#32284\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32420\"\u003e#32420\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31674\"\u003e#31674\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31973\"\u003e#31973\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32178\"\u003e#32178\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32356\"\u003e#32356\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements \u0026amp; Compatibility\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with \u003ccode\u003e-Donnxruntime_USE_FP4_QMOE=OFF\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32096\"\u003e#32096\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32163\"\u003e#32163\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and \u003ccode\u003eblock_size=32\u003c/code\u003e. Set \u003ccode\u003e-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON\u003c/code\u003e when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32324\"\u003e#32324\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCPU FP16 \u003ccode\u003eGemm\u003c/code\u003e and \u003ccode\u003eMatMul\u003c/code\u003e execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32301\"\u003e#32301\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32197\"\u003e#32197\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eWebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32287\"\u003e#32287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31960\"\u003e#31960\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31970\"\u003e#31970\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSecurity \u0026amp; Reliability\u003c/h2\u003e\n\u003ch3\u003eModel Loading, Memory, and Input Validation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimited nested model-graph depth and canonicalized external-data locations to harden model loading (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32344\"\u003e#32344\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32135\"\u003e#32135\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32010\"\u003e#32010\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32040\"\u003e#32040\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eStrengthened shape, rank, and parameter validation for \u003ccode\u003eSplit\u003c/code\u003e, \u003ccode\u003eScan\u003c/code\u003e, \u003ccode\u003eGatherND\u003c/code\u003e, \u003ccode\u003eScatterND\u003c/code\u003e, \u003ccode\u003eSpaceToDepth\u003c/code\u003e/\u003ccode\u003eDepthToSpace\u003c/code\u003e, \u003ccode\u003eCrop\u003c/code\u003e, \u003ccode\u003eConv\u003c/code\u003e, \u003ccode\u003eNormalizer\u003c/code\u003e, and pooling (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29461\"\u003e#29461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31668\"\u003e#31668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32034\"\u003e#32034\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32039\"\u003e#32039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32076\"\u003e#32076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32157\"\u003e#32157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32160\"\u003e#32160\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32161\"\u003e#32161\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32345\"\u003e#32345\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32349\"\u003e#32349\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eHardened generation and attention input handling, including attention-attribute narrowing, \u003ccode\u003eBifurcationDetector\u003c/code\u003e inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31648\"\u003e#31648\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31701\"\u003e#31701\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32009\"\u003e#32009\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32078\"\u003e#32078\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32144\"\u003e#32144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eValidated \u003ccode\u003eTreeEnsemble\u003c/code\u003e node references and bounded subtree comparison, rejected non-finite CPU \u003ccode\u003eRoiAlign\u003c/code\u003e coordinates, and required \u003ccode\u003eImageScaler\u003c/code\u003e bias to match the channel count (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32031\"\u003e#32031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32043\"\u003e#32043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32011\"\u003e#32011\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32002\"\u003e#32002\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded an allowlist of safe LoRA adapter parameter data types, validated \u003ccode\u003eMatMulFpQ4\u003c/code\u003e shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31682\"\u003e#31682\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32032\"\u003e#32032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32007\"\u003e#32007\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eGPU Bounds and Resource Lifetimes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHardened CUDA indexing and buffer-size arithmetic in \u003ccode\u003eMatMulNBits\u003c/code\u003e, \u003ccode\u003eRemovePadding\u003c/code\u003e, \u003ccode\u003eRotaryEmbedding\u003c/code\u003e, \u003ccode\u003eSparseAttention\u003c/code\u003e, Whisper beam search, NMS, QDQ, and \u003ccode\u003eGatherElements\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31643\"\u003e#31643\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31994\"\u003e#31994\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31995\"\u003e#31995\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31996\"\u003e#31996\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31998\"\u003e#31998\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32014\"\u003e#32014\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32029\"\u003e#32029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32030\"\u003e#32030\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32137\"\u003e#32137\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32330\"\u003e#32330\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31997\"\u003e#31997\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept \u003ccode\u003eCudaAsyncBuffer\u003c/code\u003e staging storage alive across CUDA graph replay (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31968\"\u003e#31968\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32121\"\u003e#32121\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32364\"\u003e#32364\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32063\"\u003e#32063\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32317\"\u003e#32317\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies and Tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29906\"\u003e#29906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32190\"\u003e#32190\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32424\"\u003e#32424\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUpdated JavaScript dependencies including \u003ccode\u003ejs-yaml\u003c/code\u003e, \u003ccode\u003ejoi\u003c/code\u003e, \u003ccode\u003efast-uri\u003c/code\u003e, and the Next.js end-to-end fixture (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32397\"\u003e#32397\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32486\"\u003e#32486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32488\"\u003e#32488\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32505\"\u003e#32505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32508\"\u003e#32508\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32176\"\u003e#32176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32005\"\u003e#32005\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32440\"\u003e#32440\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003ch3\u003eCore APIs \u0026amp; Runtime\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExtended memory importing with host-pointer support and added access to preallocated outputs through \u003ccode\u003eKernelContext::GetPreallocatedOutput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29726\"\u003e#29726\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32089\"\u003e#32089\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32283\"\u003e#32283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32321\"\u003e#32321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32312\"\u003e#32312\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded DeepSeek Engram contrib operators, \u003ccode\u003eEngramGate\u003c/code\u003e and \u003ccode\u003eNGramHashMapping\u003c/code\u003e, and expanded kernel coverage for Qwen-3.5 operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32106\"\u003e#32106\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/f2c39fe2f838cf35ce7da92824f5a5e3ee6e88a7\"\u003e\u003ccode\u003ef2c39fe\u003c/code\u003e\u003c/a\u003e [CUDA] Add INT4 paged KV cache with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32515\"\u003e#32515\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/5894ba8a53526b3aeb702bd86e6b117c9df8fa4f\"\u003e\u003ccode\u003e5894ba8\u003c/code\u003e\u003c/a\u003e Add portable random-access file reads to Env (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/a2ee3eb43052de307003e6256fc9258ce19d9c34\"\u003e\u003ccode\u003ea2ee3eb\u003c/code\u003e\u003c/a\u003e Fix CUDA plugin device discovery on WSL (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32517\"\u003e#32517\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/b652e595b04d202b7f71af1d9105a183fac2b100\"\u003e\u003ccode\u003eb652e59\u003c/code\u003e\u003c/a\u003e [WebGPU] Prepack Conv weights for the im2col-matmul path (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32420\"\u003e#32420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/0f0f29f5015f16926912ae47061e6a3eedcfbe04\"\u003e\u003ccode\u003e0f0f29f\u003c/code\u003e\u003c/a\u003e Get rid of spurious warning about not being able to find spectre mitigation (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/23dd6510fd395b4556f474c1c0079be2a8b7a8c8\"\u003e\u003ccode\u003e23dd651\u003c/code\u003e\u003c/a\u003e Register ONNX schemas only when static registration is disabled (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32353\"\u003e#32353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/33af5d32801b2e631ebece4f382f4ba775f17d8c\"\u003e\u003ccode\u003e33af5d3\u003c/code\u003e\u003c/a\u003e Release external data loaders after graph initialization (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32502\"\u003e#32502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/2e3c24d5963d62d0bd7c9d306433b19b7304d5d2\"\u003e\u003ccode\u003e2e3c24d\u003c/code\u003e\u003c/a\u003e Clarify external initializer and EP context path interaction (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32442\"\u003e#32442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/e76036b8e49515ee7dd2dd0ac39c9d8b7533d38a\"\u003e\u003ccode\u003ee76036b\u003c/code\u003e\u003c/a\u003e [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32433\"\u003e#32433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/82583c5b6398a9c37815f91e9cd1d7c165a132a7\"\u003e\u003ccode\u003e82583c5\u003c/code\u003e\u003c/a\u003e Add session option for a BNHS GroupQueryAttention Value cache layout (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32139\"\u003e#32139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxruntime/compare/v1.29.0...v1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/sachncs/redax/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/sachncs%2Fredax/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"},{"uuid":"5506344708","node_id":"PR_kwDOUAvcQ88AAAABEKnzpw","number":7,"state":"open","title":"build(deps): bump the minor-and-patch group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T00:16:35.000Z","updated_at":"2026-09-19T00:20:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"minor-and-patch","update_count":11,"packages":[{"name":"uvicorn","old_version":"0.52.1","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"tiktoken","old_version":"0.13.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"grpcio","old_version":"1.83.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"nvidia-riva-client","old_version":"2.26.0","new_version":"2.27.0","repository_url":"https://github.com/nvidia-riva/python-clients"},{"name":"torch","old_version":"2.13.0+cu130","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"accelerate","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"ty","old_version":"0.0.70","new_version":"0.0.81","repository_url":"https://github.com/astral-sh/ty"},{"name":"ruff","old_version":"0.16.2","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-and-patch group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.1` | `0.53.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |\n| [grpcio](https://github.com/grpc/grpc) | `1.83.0` | `1.84.0` |\n| [nvidia-riva-client](https://github.com/nvidia-riva/python-clients) | `2.26.0` | `2.27.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0+cu130` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.14.0` | `1.15.0` |\n| [ty](https://github.com/astral-sh/ty) | `0.0.70` | `0.0.81` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.16.2` | `0.16.7` |\n\n\nUpdates `uvicorn` from 0.52.1 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.4\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.3\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.2\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.4 (August 18, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.3 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.2 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.1...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.13.4 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tiktoken` from 0.13.0 to 0.14.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/tiktoken/blob/main/CHANGELOG.md\"\u003etiktoken's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v0.14.0]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBuild wheels for Python 3.15\u003c/li\u003e\n\u003cli\u003eSupport looking up more GPT-5 series models\u003c/li\u003e\n\u003cli\u003eUpgrade dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4e71bbe0c078468e00fefbf94b39849389f346e5\"\u003e\u003ccode\u003e4e71bbe\u003c/code\u003e\u003c/a\u003e Release 0.14.0 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/212b893ba940cba53476851103d2e5c1d0020c6e\"\u003e\u003ccode\u003e212b893\u003c/code\u003e\u003c/a\u003e Fail open for GPT-5 model tokenisers (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/596\"\u003e#596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4187ba33e48b7c554de02c17149ff0c5e50ddf38\"\u003e\u003ccode\u003e4187ba3\u003c/code\u003e\u003c/a\u003e Upgrade dependencies (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/595\"\u003e#595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/92a82552fc5d046839f83e3505a6d9b002208ac2\"\u003e\u003ccode\u003e92a8255\u003c/code\u003e\u003c/a\u003e Remove test-skip comment for macOS arm64 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/562\"\u003e#562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/674f5e65caad92c2b17f944fbdc4256fea32890e\"\u003e\u003ccode\u003e674f5e6\u003c/code\u003e\u003c/a\u003e Build Python 3.15 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/594\"\u003e#594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/dbea866194b3c7d496a029c8faf9ad238064a992\"\u003e\u003ccode\u003edbea866\u003c/code\u003e\u003c/a\u003e Remove deprecated freethreading build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/f6782242d03134d18b9a551845fd7d69fd23106e\"\u003e\u003ccode\u003ef678224\u003c/code\u003e\u003c/a\u003e Update cibuildwheel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/08a5f3b2c987ada4fc5aa1f16c643c203fa8acaa\"\u003e\u003ccode\u003e08a5f3b\u003c/code\u003e\u003c/a\u003e ci: use static artifact name for sdist build job (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/535\"\u003e#535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/openai/tiktoken/compare/0.13.0...0.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `grpcio` from 1.83.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003egrpcio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease v1.84.0\u003c/h2\u003e\n\u003cp\u003eThis is release 1.84.0 (\u003ca href=\"https://github.com/grpc/grpc/blob/master/doc/g_stands_for.md\"\u003egimbal\u003c/a\u003e) of gRPC Core.\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release contains refinements, improvements, and bug fixes, with highlights listed below.\u003c/p\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[promise_based_filter] enable v2_non_owning_waker_implementation experiment. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43253\"\u003e#43253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[xDS] allow server listener address to match wildcard port. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43247\"\u003e#43247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[WRR] remove env var guard for custom backend metrics. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43198\"\u003e#43198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[subchannel] enable connection scaling service config fields. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43116\"\u003e#43116\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[subchannel] add metrics as per A94. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43140\"\u003e#43140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix incorrect hostname suffix matching in no_proxy handling (prevents proxy bypass). (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/41915\"\u003e#41915\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eC#\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[C# Grpc.Tools] Add native macOS ARM64 support via universal binaries. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/41222\"\u003e#41222\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePython\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Python] Fix -Werror=unused-result error triggered by Cythonized code. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43313\"\u003e#43313\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Release Python 3.15 wheels publicly. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43259\"\u003e#43259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python][AsyncIO] Fixed reference cycles. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43121\"\u003e#43121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] fix: remove ghost key in grpc.aio.Metadata.\u003cstrong\u003edelitem\u003c/strong\u003e when last value is deleted. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42974\"\u003e#42974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Fix the StatusCode Enums to be int. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43167\"\u003e#43167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Fixed the parenthesis placement. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43111\"\u003e#43111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Removed \u003ccode\u003eUsageError\u003c/code\u003e exception from registered method. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43086\"\u003e#43086\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Added registered methods support in AsyncIO stack . (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/41796\"\u003e#41796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] AIO Part 4 - Typehints fixes and add Pyright for aio/_channel.py. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42736\"\u003e#42736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43000\"\u003e#43000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Observability plugin fixes. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42785\"\u003e#42785\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRuby\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Ruby] Fix: Addressed Array of strings passed as metadata. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42827\"\u003e#42827\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRelease v1.84.0-pre2\u003c/h2\u003e\n\u003cp\u003eThis is a prerelease of gRPC Core 1.84.0 (gimbal).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis is a Python-only pre-release that introduces pre-built wheels for Python 3.15.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/3252a89f10d8e92997862167ca7d095ecda85973\"\u003e\u003ccode\u003e3252a89\u003c/code\u003e\u003c/a\u003e Bump release version to 1.84.0 on v1.84.x branch (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43405\"\u003e#43405\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/c633e391bb20236fa7bd07b3fcce600d66a3ca69\"\u003e\u003ccode\u003ec633e39\u003c/code\u003e\u003c/a\u003e [Release] Bump version to 1.84.0-pre2 (on v1.84.x branch) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43401\"\u003e#43401\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/12cafeedefae1bcb27f7ae69d8bccf26f8270145\"\u003e\u003ccode\u003e12cafee\u003c/code\u003e\u003c/a\u003e [Backport][v1.84.x] Revert \u0026quot;[Python] Revert Python 3.15 changes due to sanity...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/56e86cb3b88de5b01cc5112e9c3c33be24c47aa5\"\u003e\u003ccode\u003e56e86cb\u003c/code\u003e\u003c/a\u003e Bump release version to 1.84.0-pre1 on v1.84.x branch (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43327\"\u003e#43327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/7ef6a9efc3a1518d838dfb250cffe520a59185ac\"\u003e\u003ccode\u003e7ef6a9e\u003c/code\u003e\u003c/a\u003e [build] Source reflection and channelz v1 schemas from BCR (\u003ca href=\"https://github.com/grpc\"\u003e\u003ccode\u003e@​grpc\u003c/code\u003e\u003c/a\u003e_proto) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43\"\u003e#43\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/c337c3e372ae1fcd0d94b9c461618f953c55478a\"\u003e\u003ccode\u003ec337c3e\u003c/code\u003e\u003c/a\u003e [core][filters] Unit test framework for v3 filter (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/42969\"\u003e#42969\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/ce22bb46d6befd39539d931bdb4b1c05de14df83\"\u003e\u003ccode\u003ece22bb4\u003c/code\u003e\u003c/a\u003e [PH2][CHTTP2] Retire stream flow control delta early to avoid data race\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/25c16f90b8103107dab0b5ff4c474aa9c50b04c7\"\u003e\u003ccode\u003e25c16f9\u003c/code\u003e\u003c/a\u003e [PH2][Test] Add destructor tests for the Seq promise combinator.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/a7fabec4d888e3500c87d455e66ae503ec5c8b4c\"\u003e\u003ccode\u003ea7fabec\u003c/code\u003e\u003c/a\u003e [Python] Fix -Werror=unused-result error triggered by Cythonized code (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43313\"\u003e#43313\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/d92ee432237eb7fec6ae74646a6bbe1d99027a79\"\u003e\u003ccode\u003ed92ee43\u003c/code\u003e\u003c/a\u003e [util] remove LoadFile() option to append null byte (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/41478\"\u003e#41478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc/compare/v1.83.0...v1.84.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nvidia-riva-client` from 2.26.0 to 2.27.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nvidia-riva/python-clients/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.13.0+cu130 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.14.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#security\"\u003eSecurity\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003ch2\u003etorch.nn\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003etorch.nn.LinearCrossEntropyOptions\u003c/code\u003e no longer accepts \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e; use \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e instead (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188283\"\u003e#188283\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003e\u0026quot;balanced\u0026quot;\u003c/code\u003e policy was removed because \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e provides the same weight-gradient accumulation precision with lower memory use on CUDA, already uses the equivalent scratch layout for mixed-precision inputs on other devices, and was never selected by \u003ccode\u003e\u0026quot;auto\u0026quot;\u003c/code\u003e. Constructing the options with \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e now raises \u003ccode\u003eValueError: invalid acc_policy: 'balanced'; expected one of 'auto', 'accurate', 'compact'\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBefore:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;balanced\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n    input, linear_weight, target, options=options\r\n)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eAfter:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;compact\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pytorch/pytorch/commits/v2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.14.0 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/6afc1e5ee217051fde702b23de2813344dc0fd33\"\u003e\u003ccode\u003e6afc1e5\u003c/code\u003e\u003c/a\u003e Release: v1.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/636a9343b4265db1212b04c778b8910b5cbfa713\"\u003e\u003ccode\u003e636a934\u003c/code\u003e\u003c/a\u003e Fix nightly CI: tensor parallel size detection and DeepSpeed warmup steps (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/385d9fb40bdb92b0cb34775ad0ef493c171e559f\"\u003e\u003ccode\u003e385d9fb\u003c/code\u003e\u003c/a\u003e docs: fix three dead links left by the docs restructure (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4230\"\u003e#4230\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/c424d0b82d4ed61672bf30f1a81ce80370fd945a\"\u003e\u003ccode\u003ec424d0b\u003c/code\u003e\u003c/a\u003e docs: fix garbled sentence in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4231\"\u003e#4231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/0f7e35fe7902cc6ba8dc01b146d6447900464b88\"\u003e\u003ccode\u003e0f7e35f\u003c/code\u003e\u003c/a\u003e Clip grad norm support for dtensors (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/b2ac5095f04585043e21d295afe3aaaacdcc8357\"\u003e\u003ccode\u003eb2ac509\u003c/code\u003e\u003c/a\u003e Fix FSDP2/ PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/33e8bc499254e7f3886db3f8a277d05a4ad2667e\"\u003e\u003ccode\u003e33e8bc4\u003c/code\u003e\u003c/a\u003e Fix load_accelerator_state only restoring one RNG backend (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4217\"\u003e#4217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/50de3ad45f4da279819529e443ba746eb5b3b187\"\u003e\u003ccode\u003e50de3ad\u003c/code\u003e\u003c/a\u003e Treat MPS out-of-memory errors as OOM in find_executable_batch_size (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4227\"\u003e#4227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/ab5fe8e507366f814fee59138eb96b9879cb05d6\"\u003e\u003ccode\u003eab5fe8e\u003c/code\u003e\u003c/a\u003e feat: add the neuron device branch in state (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4218\"\u003e#4218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/9baf95be958c3fd8b2449d1463e6a89e14f61e7d\"\u003e\u003ccode\u003e9baf95b\u003c/code\u003e\u003c/a\u003e Fix MLFLOW_NESTED_RUN never being able to turn nesting off (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4223\"\u003e#4223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/accelerate/compare/v1.14.0...v1.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ty` from 0.0.70 to 0.0.81\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/releases\"\u003ety's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.81\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-14.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEscape glob characters in anchored directory paths (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28518\"\u003e#28518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIgnore divergent markers when detecting descriptors (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28514\"\u003e#28514\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAnchor default exclude patterns at the project root (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28463\"\u003e#28463\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid rebinding extracted method calls (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28469\"\u003e#28469\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDefault-specialize class objects in meta-protocol checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28265\"\u003e#28265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix MRO ordering for generic bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28172\"\u003e#28172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix assignability of bounded typevars to intersection types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28479\"\u003e#28479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix variadic partial signature reduction (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28586\"\u003e#28586\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle gradual metaclass ancestry and conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28474\"\u003e#28474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve recursive metadata in union transformations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28497\"\u003e#28497\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve runtime comparison semantics when narrowing tagged unions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28053\"\u003e#28053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve wrapped signatures in nominal descriptor checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28466\"\u003e#28466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject reassignment of enum members (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28462\"\u003e#28462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReport override conflicts introduced by new bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28530\"\u003e#28530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eResolve dependencies within correlated inference alternatives (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28252\"\u003e#28252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect instance dictionary storage for slotted classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27749\"\u003e#27749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate explicitly overridden constructor signatures (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28115\"\u003e#28115\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid redundant superclass member inference (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28587\"\u003e#28587\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReuse rendered union elements when displaying types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28494\"\u003e#28494\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMemory usage improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReduce retained AST memory by shrinking expressions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28335\"\u003e#28335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare strings in dependency metadata (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28141\"\u003e#28141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp\"\u003e\u003ccode\u003e@​sharkdp\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ibraheemdev\"\u003e\u003ccode\u003e@​ibraheemdev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mtshiba\"\u003e\u003ccode\u003e@​mtshiba\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/blob/main/CHANGELOG.md\"\u003ety's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.81\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-14.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEscape glob characters in anchored directory paths (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28518\"\u003e#28518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIgnore divergent markers when detecting descriptors (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28514\"\u003e#28514\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAnchor default exclude patterns at the project root (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28463\"\u003e#28463\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid rebinding extracted method calls (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28469\"\u003e#28469\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDefault-specialize class objects in meta-protocol checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28265\"\u003e#28265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix MRO ordering for generic bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28172\"\u003e#28172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix assignability of bounded typevars to intersection types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28479\"\u003e#28479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix variadic partial signature reduction (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28586\"\u003e#28586\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle gradual metaclass ancestry and conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28474\"\u003e#28474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve recursive metadata in union transformations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28497\"\u003e#28497\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve runtime comparison semantics when narrowing tagged unions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28053\"\u003e#28053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve wrapped signatures in nominal descriptor checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28466\"\u003e#28466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject reassignment of enum members (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28462\"\u003e#28462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReport override conflicts introduced by new bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28530\"\u003e#28530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eResolve dependencies within correlated inference alternatives (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28252\"\u003e#28252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect instance dictionary storage for slotted classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27749\"\u003e#27749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate explicitly overridden constructor signatures (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28115\"\u003e#28115\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid redundant superclass member inference (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28587\"\u003e#28587\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReuse rendered union elements when displaying types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28494\"\u003e#28494\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMemory usage improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReduce retained AST memory by shrinking expressions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28335\"\u003e#28335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare strings in dependency metadata (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28141\"\u003e#28141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp\"\u003e\u003ccode\u003e@​sharkdp\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ibraheemdev\"\u003e\u003ccode\u003e@​ibraheemdev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mtshiba\"\u003e\u003ccode\u003e@​mtshiba\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/carljm\"\u003e\u003ccode\u003e@​carljm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/4edd7724afd129fff0a09241d3fc9b4e7607c038\"\u003e\u003ccode\u003e4edd772\u003c/code\u003e\u003c/a\u003e Bump version to 0.0.81 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4528\"\u003e#4528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/8cfdd79e9ded89997d612f816a8d0f4b0cfb2ca0\"\u003e\u003ccode\u003e8cfdd79\u003c/code\u003e\u003c/a\u003e Use paid GitHub-hosted runners for Linux (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4502\"\u003e#4502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/7fd8e15694f869200f7778082564c5968c50ce30\"\u003e\u003ccode\u003e7fd8e15\u003c/code\u003e\u003c/a\u003e Bump version to 0.0.80 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4501\"\u003e#4501\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/c163f21ed4be7a5608ae5791720b43040b08cf5c\"\u003e\u003ccode\u003ec163f21\u003c/code\u003e\u003c/a\u003e Update dependency prek to v0.4.12 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4494\"\u003e#4494\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/8ce0450332e815c0f734fb84d03d63be3eb96829\"\u003e\u003ccode\u003e8ce0450\u003c/code\u003e\u003c/a\u003e Update prek dependencies (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4495\"\u003e#4495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/5d0aa7a142189fc1955759c2987029b8ff8ef4a7\"\u003e\u003ccode\u003e5d0aa7a\u003c/code\u003e\u003c/a\u003e Update actions/attest-build-provenance action to v4.2.2 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/e22b86b3e6d461af46b549e5ebef5474b6256783\"\u003e\u003ccode\u003ee22b86b\u003c/code\u003e\u003c/a\u003e Update Swatinem/rust-cache action to v2.9.2 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4496\"\u003e#4496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/5cde40f5cb83f1cb164b91282e6a72f3dfe4580c\"\u003e\u003ccode\u003e5cde40f\u003c/code\u003e\u003c/a\u003e Document uv integration and workspace trust settings (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4339\"\u003e#4339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/b4cd79275b7ce22c4cf4208f8b005adb53e92523\"\u003e\u003ccode\u003eb4cd792\u003c/code\u003e\u003c/a\u003e Bump version to 0.0.79 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/52f2d5b12ff4a86f1100f3b9c3e2d61b086d8a89\"\u003e\u003ccode\u003e52f2d5b\u003c/code\u003e\u003c/a\u003e Add a GitHub repository threat model for ty (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4481\"\u003e#4481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/astral-sh/ty/compare/0.0.70...0.0.81\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ruff` from 0.16.2 to 0.16.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/releases\"\u003eruff's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md\"\u003eruff's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nightt5879\"\u003e\u003ccode\u003e@​nightt5879\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13\"\u003e\u003ccode\u003eb5dba86\u003c/code\u003e\u003c/a\u003e Bump version to 0.16.7 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28496\"\u003e#28496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24\"\u003e\u003ccode\u003e5992d05\u003c/code\u003e\u003c/a\u003e Install rustfmt before linting releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28495\"\u003e#28495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8\"\u003e\u003ccode\u003e1713a1f\u003c/code\u003e\u003c/a\u003e ensure prepare release changes pass prek (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28488\"\u003e#28488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334\"\u003e\u003ccode\u003e18cdbb4\u003c/code\u003e\u003c/a\u003e use scoped token for release workflow (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28484\"\u003e#28484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd\"\u003e\u003ccode\u003ec3813a5\u003c/code\u003e\u003c/a\u003e add a workflow for preparing releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28486\"\u003e#28486\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38\"\u003e\u003ccode\u003e00948c0\u003c/code\u003e\u003c/a\u003e Remove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427\"\u003e\u003ccode\u003e86a2eba\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (`UP...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https:/...\n\n_Description has been truncated_","html_url":"https://github.com/Legendary-Gamer970/aim-trainer/pull/7","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Legendary-Gamer970%2Faim-trainer/issues/7","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7/packages"},{"uuid":"5506212254","node_id":"PR_kwDOUE4m3s8AAAABEKg5kg","number":14,"state":"closed","title":"chore(deps): bump the python-runtime group across 1 directory with 16 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-25T23:58:36.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-19T00:00:03.000Z","updated_at":"2026-09-25T23:58:38.000Z","time_to_close":604713,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"python-runtime","update_count":16,"packages":[{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"},{"name":"numpy","old_version":"2.5.2","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"onnxruntime","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"openai","old_version":"3.3.1","new_version":"3.14.1","repository_url":"https://github.com/openai/openai-python"},{"name":"piper-tts","old_version":"1.4.2","new_version":"1.8.0","repository_url":"https://github.com/OHF-voice/piper1-gpl"},{"name":"playwright","old_version":"1.55.0","new_version":"1.63.0","repository_url":"https://github.com/microsoft/playwright-python"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"scipy","old_version":"1.18.0","new_version":"1.18.1","repository_url":"https://github.com/scipy/scipy"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vllm","old_version":"0.27.1","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/vllm"},{"name":"huggingface-hub","old_version":"1.28.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"ninja","old_version":"1.13.0","new_version":"1.13.2","repository_url":"https://github.com/ninja-build/ninja"},{"name":"accelerate","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.15.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-runtime group with 16 updates in the /requirements directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.1` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.29.0` | `1.30.0` |\n| [openai](https://github.com/openai/openai-python) | `3.3.1` | `3.14.1` |\n| [piper-tts](https://github.com/OHF-voice/piper1-gpl) | `1.4.2` | `1.8.0` |\n| [playwright](https://github.com/microsoft/playwright-python) | `1.55.0` | `1.63.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [scipy](https://github.com/scipy/scipy) | `1.18.0` | `1.18.1` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| [vllm](https://github.com/vllm-project/vllm) | `0.27.1` | `0.29.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.28.0` | `1.31.0` |\n| [ninja](https://github.com/ninja-build/ninja) | `1.13.0` | `1.13.2` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.14.0` | `1.15.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.1` | `5.17.0` |\n\n\nUpdates `cryptography` from 46.0.5 to 50.0.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.1 - 2026-08-25\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.\n\u003cp\u003e.. _v50-0-0:\u003c/p\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSECURITY ISSUE\u003c/strong\u003e:\n:func:\u003ccode\u003e~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der\u003c/code\u003e\nand its PEM and S/MIME variants no longer expose distinguishable errors or\ntiming when unwrapping a \u003ccode\u003eRecipientInfo\u003c/code\u003e's \u003ccode\u003eencryptedKey\u003c/code\u003e, which could\nact as a Bleichenbacher oracle for callers that decrypt untrusted messages.\nA random key is now substituted on failure, as described in :rfc:\u003ccode\u003e3218\u003c/code\u003e.\nCredit to \u003cstrong\u003e\u003ca href=\"https://github.com/X1AOxiang\"\u003e\u003ccode\u003e@​X1AOxiang\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e for reporting the issue. \u003cstrong\u003eCVE-2026-69247\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eDeprecated Diffie-Hellman key exchange over finite fields (FFDH).\nEverything FFDH is deprecated, including the types in\n\u003ccode\u003ecryptography.hazmat.primitives.asymmetric.dh\u003c/code\u003e and loading FFDH keys or\nparameters with the key loading APIs. Users should migrate to a more\nmodern key exchange algorithm.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003exof()\u003c/code\u003e class methods to\n:class:\u003ccode\u003e~cryptography.hazmat.primitives.hashes.SHAKE128\u003c/code\u003e and\n:class:\u003ccode\u003e~cryptography.hazmat.primitives.hashes.SHAKE256\u003c/code\u003e for constructing\nalgorithm instances configured for use with\n:class:\u003ccode\u003e~cryptography.hazmat.primitives.hashes.XOFHash\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe :mod:\u003ccode\u003eX.509 verification \u0026lt;cryptography.x509.verification\u0026gt;\u003c/code\u003e APIs are now\nconsidered stable and are subject to our API stability policy.\u003c/li\u003e\n\u003cli\u003eAdded the :doc:\u003ccode\u003e/cobblestone\u003c/code\u003e recipe, an implementation of the\nCobblestone-128 and Cobblestone-256 instantiations of the \u003ccode\u003eC2SP chunked-encryption specification \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;\u003c/code\u003e_ for streaming authenticated\nencryption of large messages.\u003c/li\u003e\n\u003cli\u003eParsing a Signed Certificate Timestamp list now rejects encodings that\ncarry trailing bytes after the list or after an individual SCT, instead of\nsilently ignoring them.\u003c/li\u003e\n\u003cli\u003eAdded support for using :class:\u003ccode\u003e~cryptography.x509.Name\u003c/code\u003e as a field type in\nthe :doc:\u003ccode\u003e/hazmat/asn1/index\u003c/code\u003e module.\u003c/li\u003e\n\u003cli\u003eLoading a public key or an EC private key now rejects DER where the\n\u003ccode\u003esubjectPublicKey\u003c/code\u003e (or EC \u003ccode\u003epublicKey\u003c/code\u003e) \u003ccode\u003eBIT STRING\u003c/code\u003e declares a non-zero\nnumber of unused bits, instead of silently ignoring it.\u003c/li\u003e\n\u003cli\u003eParsing a CRL entry's \u003ccode\u003eInvalidityDate\u003c/code\u003e extension now rejects a\n\u003ccode\u003eGeneralizedTime\u003c/code\u003e that carries fractional seconds or another non-DER form,\nmatching the strict encoding already required for every other X.509 time\nfield.\u003c/li\u003e\n\u003cli\u003e:func:\u003ccode\u003e~cryptography.x509.ocsp.load_der_ocsp_request\u003c/code\u003e and\n:func:\u003ccode\u003e~cryptography.x509.ocsp.load_der_ocsp_response\u003c/code\u003e now reject a request\nor response whose \u003ccode\u003eversion\u003c/code\u003e field is not \u003ccode\u003ev1\u003c/code\u003e, the only version defined\nby RFC 6960, matching the version validation already performed when loading\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/ffde75a2b594822c740a2e4748b56c00548302bf\"\u003e\u003ccode\u003effde75a\u003c/code\u003e\u003c/a\u003e bump for 50.0.1 + changelog (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15520\"\u003e#15520\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/46.0.5...50.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.5.2 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.5.2...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `onnxruntime` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxruntime/releases\"\u003eonnxruntime's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eONNX Runtime v1.30.0\u003c/h2\u003e\n\u003cp\u003eONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32168\"\u003e#32168\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32340\"\u003e#32340\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32515\"\u003e#32515\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31727\"\u003e#31727\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32277\"\u003e#32277\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32284\"\u003e#32284\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32420\"\u003e#32420\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31674\"\u003e#31674\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31973\"\u003e#31973\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32178\"\u003e#32178\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32356\"\u003e#32356\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements \u0026amp; Compatibility\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with \u003ccode\u003e-Donnxruntime_USE_FP4_QMOE=OFF\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32096\"\u003e#32096\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32163\"\u003e#32163\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and \u003ccode\u003eblock_size=32\u003c/code\u003e. Set \u003ccode\u003e-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON\u003c/code\u003e when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32324\"\u003e#32324\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCPU FP16 \u003ccode\u003eGemm\u003c/code\u003e and \u003ccode\u003eMatMul\u003c/code\u003e execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32301\"\u003e#32301\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32197\"\u003e#32197\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eWebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32287\"\u003e#32287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31960\"\u003e#31960\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31970\"\u003e#31970\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSecurity \u0026amp; Reliability\u003c/h2\u003e\n\u003ch3\u003eModel Loading, Memory, and Input Validation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimited nested model-graph depth and canonicalized external-data locations to harden model loading (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32344\"\u003e#32344\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32135\"\u003e#32135\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32010\"\u003e#32010\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32040\"\u003e#32040\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eStrengthened shape, rank, and parameter validation for \u003ccode\u003eSplit\u003c/code\u003e, \u003ccode\u003eScan\u003c/code\u003e, \u003ccode\u003eGatherND\u003c/code\u003e, \u003ccode\u003eScatterND\u003c/code\u003e, \u003ccode\u003eSpaceToDepth\u003c/code\u003e/\u003ccode\u003eDepthToSpace\u003c/code\u003e, \u003ccode\u003eCrop\u003c/code\u003e, \u003ccode\u003eConv\u003c/code\u003e, \u003ccode\u003eNormalizer\u003c/code\u003e, and pooling (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29461\"\u003e#29461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31668\"\u003e#31668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32034\"\u003e#32034\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32039\"\u003e#32039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32076\"\u003e#32076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32157\"\u003e#32157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32160\"\u003e#32160\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32161\"\u003e#32161\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32345\"\u003e#32345\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32349\"\u003e#32349\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eHardened generation and attention input handling, including attention-attribute narrowing, \u003ccode\u003eBifurcationDetector\u003c/code\u003e inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31648\"\u003e#31648\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31701\"\u003e#31701\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32009\"\u003e#32009\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32078\"\u003e#32078\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32144\"\u003e#32144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eValidated \u003ccode\u003eTreeEnsemble\u003c/code\u003e node references and bounded subtree comparison, rejected non-finite CPU \u003ccode\u003eRoiAlign\u003c/code\u003e coordinates, and required \u003ccode\u003eImageScaler\u003c/code\u003e bias to match the channel count (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32031\"\u003e#32031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32043\"\u003e#32043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32011\"\u003e#32011\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32002\"\u003e#32002\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded an allowlist of safe LoRA adapter parameter data types, validated \u003ccode\u003eMatMulFpQ4\u003c/code\u003e shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31682\"\u003e#31682\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32032\"\u003e#32032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32007\"\u003e#32007\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eGPU Bounds and Resource Lifetimes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHardened CUDA indexing and buffer-size arithmetic in \u003ccode\u003eMatMulNBits\u003c/code\u003e, \u003ccode\u003eRemovePadding\u003c/code\u003e, \u003ccode\u003eRotaryEmbedding\u003c/code\u003e, \u003ccode\u003eSparseAttention\u003c/code\u003e, Whisper beam search, NMS, QDQ, and \u003ccode\u003eGatherElements\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31643\"\u003e#31643\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31994\"\u003e#31994\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31995\"\u003e#31995\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31996\"\u003e#31996\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31998\"\u003e#31998\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32014\"\u003e#32014\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32029\"\u003e#32029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32030\"\u003e#32030\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32137\"\u003e#32137\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32330\"\u003e#32330\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31997\"\u003e#31997\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept \u003ccode\u003eCudaAsyncBuffer\u003c/code\u003e staging storage alive across CUDA graph replay (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31968\"\u003e#31968\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32121\"\u003e#32121\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32364\"\u003e#32364\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32063\"\u003e#32063\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32317\"\u003e#32317\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies and Tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29906\"\u003e#29906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32190\"\u003e#32190\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32424\"\u003e#32424\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUpdated JavaScript dependencies including \u003ccode\u003ejs-yaml\u003c/code\u003e, \u003ccode\u003ejoi\u003c/code\u003e, \u003ccode\u003efast-uri\u003c/code\u003e, and the Next.js end-to-end fixture (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32397\"\u003e#32397\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32486\"\u003e#32486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32488\"\u003e#32488\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32505\"\u003e#32505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32508\"\u003e#32508\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32176\"\u003e#32176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32005\"\u003e#32005\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32440\"\u003e#32440\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003ch3\u003eCore APIs \u0026amp; Runtime\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExtended memory importing with host-pointer support and added access to preallocated outputs through \u003ccode\u003eKernelContext::GetPreallocatedOutput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29726\"\u003e#29726\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32089\"\u003e#32089\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32283\"\u003e#32283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32321\"\u003e#32321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32312\"\u003e#32312\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded DeepSeek Engram contrib operators, \u003ccode\u003eEngramGate\u003c/code\u003e and \u003ccode\u003eNGramHashMapping\u003c/code\u003e, and expanded kernel coverage for Qwen-3.5 operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32106\"\u003e#32106\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/f2c39fe2f838cf35ce7da92824f5a5e3ee6e88a7\"\u003e\u003ccode\u003ef2c39fe\u003c/code\u003e\u003c/a\u003e [CUDA] Add INT4 paged KV cache with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32515\"\u003e#32515\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/5894ba8a53526b3aeb702bd86e6b117c9df8fa4f\"\u003e\u003ccode\u003e5894ba8\u003c/code\u003e\u003c/a\u003e Add portable random-access file reads to Env (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/a2ee3eb43052de307003e6256fc9258ce19d9c34\"\u003e\u003ccode\u003ea2ee3eb\u003c/code\u003e\u003c/a\u003e Fix CUDA plugin device discovery on WSL (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32517\"\u003e#32517\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/b652e595b04d202b7f71af1d9105a183fac2b100\"\u003e\u003ccode\u003eb652e59\u003c/code\u003e\u003c/a\u003e [WebGPU] Prepack Conv weights for the im2col-matmul path (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32420\"\u003e#32420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/0f0f29f5015f16926912ae47061e6a3eedcfbe04\"\u003e\u003ccode\u003e0f0f29f\u003c/code\u003e\u003c/a\u003e Get rid of spurious warning about not being able to find spectre mitigation (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/23dd6510fd395b4556f474c1c0079be2a8b7a8c8\"\u003e\u003ccode\u003e23dd651\u003c/code\u003e\u003c/a\u003e Register ONNX schemas only when static registration is disabled (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32353\"\u003e#32353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/33af5d32801b2e631ebece4f382f4ba775f17d8c\"\u003e\u003ccode\u003e33af5d3\u003c/code\u003e\u003c/a\u003e Release external data loaders after graph initialization (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32502\"\u003e#32502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/2e3c24d5963d62d0bd7c9d306433b19b7304d5d2\"\u003e\u003ccode\u003e2e3c24d\u003c/code\u003e\u003c/a\u003e Clarify external initializer and EP context path interaction (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32442\"\u003e#32442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/e76036b8e49515ee7dd2dd0ac39c9d8b7533d38a\"\u003e\u003ccode\u003ee76036b\u003c/code\u003e\u003c/a\u003e [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32433\"\u003e#32433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/82583c5b6398a9c37815f91e9cd1d7c165a132a7\"\u003e\u003ccode\u003e82583c5\u003c/code\u003e\u003c/a\u003e Add session option for a BNHS GroupQueryAttention Value cache layout (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32139\"\u003e#32139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxruntime/compare/v1.29.0...v1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `openai` from 3.3.1 to 3.14.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/openai-python/releases\"\u003eopenai's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.14.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.14.0...v3.14.1\"\u003e3.14.1\u003c/a\u003e (2026-09-15)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e validate retry limits and preserve application errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3867\"\u003e#3867\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/f86c7214093038faa512bd4883558b093bdb8c9a\"\u003ef86c721\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ecorrect typo \u0026quot;th\u0026quot; to \u0026quot;the\u0026quot; in StreamAlreadyConsumed error message (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3022\"\u003e#3022\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/718620397c38a546d2cbbc964983c286db7abf97\"\u003e7186203\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e correct Azure endpoint hostname (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3298\"\u003e#3298\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/543516c4223372a7fb830d560f26d8e6ad081d02\"\u003e543516c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e refresh chat streaming examples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2974\"\u003e#2974\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/54f460ef8c212a7849d10cef69853dffb48c4491\"\u003e54f460e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e split push-to-talk shebang arguments (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3210\"\u003e#3210\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d241ed65c122a964679ca9d102924761956aa71f\"\u003ed241ed6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e use uv in remaining Python launchers (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3821\"\u003e#3821\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8c76c4f5e6ee65c6393e80494d2bbbdc8607e983\"\u003e8c76c4f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003elog only metadata for Live WebSocket diagnostics (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3865\"\u003e#3865\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ccc10f595ff606cf007459aecae6ddc90d02794a\"\u003eccc10f5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eresponses:\u003c/strong\u003e skip structured parsing for commentary (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3861\"\u003e#3861\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/6520df1220a0030c7b45b00a6fa4bf2e9c7396ac\"\u003e6520df1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e bump module_client.py to gpt-5.6 (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3211\"\u003e#3211\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/1493321affb1814fba7b669892e376a119d8d36f\"\u003e1493321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unused fine-tuning data validators (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3863\"\u003e#3863\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/9640f2903d65c43f0e5aee58d60f46880ff0bd15\"\u003e9640f29\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify async client cleanup (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2388\"\u003e#2388\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/a3d83b5af23e4057453aae83dcdb4e3cced1cdad\"\u003ea3d83b5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eclarify filenames for in-memory file uploads (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3729\"\u003e#3729\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/cb27380d95f5e6995ea56dc588914454629cce0f\"\u003ecb27380\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e correct retry jitter comment (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2252\"\u003e#2252\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/bdbbc16a3f289601cb7cbcec9e64c94e95753e94\"\u003ebdbbc16\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix Realtime docstring wording (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3535\"\u003e#3535\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8cb9dedabd03297816749fcadfa12ef3ebcd3ed8\"\u003e8cb9ded\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix reusing wording in Azure client docstrings (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3061\"\u003e#3061\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/dc625f9533cb43e74aea53529c86d4848eed82ec\"\u003edc625f9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix streaming comment typo (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3005\"\u003e#3005\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d421d7ab8c0a5e4e00147407ef9941c7f2bc9c09\"\u003ed421d7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix vector store polling helper paths (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3101\"\u003e#3101\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/2ef2de6bf1603b2df8cb28bcc604c79c6e7f773d\"\u003e2ef2de6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ereadme:\u003c/strong\u003e correct SSE terminology (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2837\"\u003e#2837\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/caaa9b45a24c7698244824cda2c2d9ae16359354\"\u003ecaaa9b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate Responses API reference link (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3279\"\u003e#3279\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/557bd06bce467e7f748b9c86bdde6427e85d28c7\"\u003e557bd06\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e correct query component RFC reference (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3300\"\u003e#3300\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/929a8a500a0e95df090ef53fe38890eba1e97660\"\u003e929a8a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.14.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.13.0...v3.14.0\"\u003e3.14.0\u003c/a\u003e (2026-09-14)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estreaming:\u003c/strong\u003e normalize errors raised while reading streams (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3827\"\u003e#3827\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d7c41efee1b0802b79f3f88a678ef2052b06e9ce\"\u003ed7c41ef\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebound vector store file polling (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3401\"\u003e#3401\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ae41bc46cdd53d17e948ac8a73e16bdbf34123a1\"\u003eae41bc4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexample:\u003c/strong\u003e refresh realtime push_to_talk_app session types (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2926\"\u003e#2926\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/0b7ad38292ef862f1dd07f71543b2f60eade8999\"\u003e0b7ad38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003efiles:\u003c/strong\u003e normalize PathLike upload tuples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3475\"\u003e#3475\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/90ac74ccfe7a966787d1f204755d4cd4cc4d406a\"\u003e90ac74c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003einclude completion in content filter errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3094\"\u003e#3094\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/e57a1b19fbcc32306a691e63334fd2dc4b1a804c\"\u003ee57a1b1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/openai-python/blob/main/CHANGELOG.md\"\u003eopenai's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.14.0...v3.14.1\"\u003e3.14.1\u003c/a\u003e (2026-09-15)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e validate retry limits and preserve application errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3867\"\u003e#3867\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/f86c7214093038faa512bd4883558b093bdb8c9a\"\u003ef86c721\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ecorrect typo \u0026quot;th\u0026quot; to \u0026quot;the\u0026quot; in StreamAlreadyConsumed error message (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3022\"\u003e#3022\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/718620397c38a546d2cbbc964983c286db7abf97\"\u003e7186203\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e correct Azure endpoint hostname (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3298\"\u003e#3298\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/543516c4223372a7fb830d560f26d8e6ad081d02\"\u003e543516c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e refresh chat streaming examples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2974\"\u003e#2974\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/54f460ef8c212a7849d10cef69853dffb48c4491\"\u003e54f460e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e split push-to-talk shebang arguments (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3210\"\u003e#3210\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d241ed65c122a964679ca9d102924761956aa71f\"\u003ed241ed6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e use uv in remaining Python launchers (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3821\"\u003e#3821\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8c76c4f5e6ee65c6393e80494d2bbbdc8607e983\"\u003e8c76c4f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003elog only metadata for Live WebSocket diagnostics (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3865\"\u003e#3865\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ccc10f595ff606cf007459aecae6ddc90d02794a\"\u003eccc10f5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eresponses:\u003c/strong\u003e skip structured parsing for commentary (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3861\"\u003e#3861\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/6520df1220a0030c7b45b00a6fa4bf2e9c7396ac\"\u003e6520df1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e bump module_client.py to gpt-5.6 (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3211\"\u003e#3211\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/1493321affb1814fba7b669892e376a119d8d36f\"\u003e1493321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unused fine-tuning data validators (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3863\"\u003e#3863\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/9640f2903d65c43f0e5aee58d60f46880ff0bd15\"\u003e9640f29\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify async client cleanup (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2388\"\u003e#2388\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/a3d83b5af23e4057453aae83dcdb4e3cced1cdad\"\u003ea3d83b5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eclarify filenames for in-memory file uploads (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3729\"\u003e#3729\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/cb27380d95f5e6995ea56dc588914454629cce0f\"\u003ecb27380\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e correct retry jitter comment (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2252\"\u003e#2252\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/bdbbc16a3f289601cb7cbcec9e64c94e95753e94\"\u003ebdbbc16\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix Realtime docstring wording (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3535\"\u003e#3535\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8cb9dedabd03297816749fcadfa12ef3ebcd3ed8\"\u003e8cb9ded\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix reusing wording in Azure client docstrings (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3061\"\u003e#3061\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/dc625f9533cb43e74aea53529c86d4848eed82ec\"\u003edc625f9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix streaming comment typo (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3005\"\u003e#3005\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d421d7ab8c0a5e4e00147407ef9941c7f2bc9c09\"\u003ed421d7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix vector store polling helper paths (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3101\"\u003e#3101\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/2ef2de6bf1603b2df8cb28bcc604c79c6e7f773d\"\u003e2ef2de6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ereadme:\u003c/strong\u003e correct SSE terminology (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2837\"\u003e#2837\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/caaa9b45a24c7698244824cda2c2d9ae16359354\"\u003ecaaa9b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate Responses API reference link (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3279\"\u003e#3279\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/557bd06bce467e7f748b9c86bdde6427e85d28c7\"\u003e557bd06\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e correct query component RFC reference (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3300\"\u003e#3300\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/929a8a500a0e95df090ef53fe38890eba1e97660\"\u003e929a8a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.13.0...v3.14.0\"\u003e3.14.0\u003c/a\u003e (2026-09-14)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estreaming:\u003c/strong\u003e normalize errors raised while reading streams (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3827\"\u003e#3827\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d7c41efee1b0802b79f3f88a678ef2052b06e9ce\"\u003ed7c41ef\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebound vector store file polling (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3401\"\u003e#3401\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ae41bc46cdd53d17e948ac8a73e16bdbf34123a1\"\u003eae41bc4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexample:\u003c/strong\u003e refresh realtime push_to_talk_app session types (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2926\"\u003e#2926\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/0b7ad38292ef862f1dd07f71543b2f60eade8999\"\u003e0b7ad38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003efiles:\u003c/strong\u003e normalize PathLike upload tuples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3475\"\u003e#3475\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/90ac74ccfe7a966787d1f204755d4cd4cc4d406a\"\u003e90ac74c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003einclude completion in content filter errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3094\"\u003e#3094\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/e57a1b19fbcc32306a691e63334fd2dc4b1a804c\"\u003ee57a1b1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003elogging:\u003c/strong\u003e support standard OPENAI_LOG levels (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3734\"\u003e#3734\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/44000e0fc5e11692663045d6183568ff3ec32736\"\u003e44000e0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize API error codes to strings (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3532\"\u003e#3532\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/233d9557be3e7ee186b5ac3f1ab634a257134ac1\"\u003e233d955\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3531\"\u003e#3531\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/5bae14cb22724ef0a9db0d3a7fb7556d28b3fee3\"\u003e\u003ccode\u003e5bae14c\u003c/code\u003e\u003c/a\u003e release: 3.14.1 (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3856\"\u003e#3856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/f86c7214093038faa512bd4883558b093bdb8c9a\"\u003e\u003ccode\u003ef86c721\u003c/code\u003e\u003c/a\u003e fix(client): validate retry limits and preserve application errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3867\"\u003e#3867\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/6520df1220a0030c7b45b00a6fa4bf2e9c7396ac\"\u003e\u003ccode\u003e6520df1\u003c/code\u003e\u003c/a\u003e fix(responses): skip structured parsing for commentary (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3861\"\u003e#3861\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/b3c04f4e701e07726f320295a38928421946e530\"\u003e\u003ccode\u003eb3c04f4\u003c/code\u003e\u003c/a\u003e fix(azure): preserve deployment routing across copy/with_options (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3593\"\u003e#3593\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/ccc10f595ff606cf007459aecae6ddc90d02794a\"\u003e\u003ccode\u003eccc10f5\u003c/code\u003e\u003c/a\u003e fix: log only metadata for Live WebSocket diagnostics (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3865\"\u003e#3865\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/9640f2903d65c43f0e5aee58d60f46880ff0bd15\"\u003e\u003ccode\u003e9640f29\u003c/code\u003e\u003c/a\u003e chore: remove unused fine-tuning data validators (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3863\"\u003e#3863\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/8cb9dedabd03297816749fcadfa12ef3ebcd3ed8\"\u003e\u003ccode\u003e8cb9ded\u003c/code\u003e\u003c/a\u003e docs: fix Realtime docstring wording (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3535\"\u003e#3535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/a3d83b5af23e4057453aae83dcdb4e3cced1cdad\"\u003e\u003ccode\u003ea3d83b5\u003c/code\u003e\u003c/a\u003e docs: clarify async client cleanup (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2388\"\u003e#2388\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/54f460ef8c212a7849d10cef69853dffb48c4491\"\u003e\u003ccode\u003e54f460e\u003c/code\u003e\u003c/a\u003e fix(examples): refresh chat streaming examples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2974\"\u003e#2974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/d241ed65c122a964679ca9d102924761956aa71f\"\u003e\u003ccode\u003ed241ed6\u003c/code\u003e\u003c/a\u003e fix(examples): split push-to-talk shebang arguments (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3210\"\u003e#3210\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/openai/openai-python/compare/v3.3.1...v3.14.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `piper-tts` from 1.4.2 to 1.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/OHF-voice/piper1-gpl/releases\"\u003epiper-tts's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.8.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Thai phonemizer using TLTK in the new \u003ccode\u003eth\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type thai\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;thai\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng's Thai voice is a placeholder: its \u003ccode\u003eth_dict\u003c/code\u003e holds no lexicon, so unspaced Thai is never segmented; the leading vowels เ แ โ ใ ไ are not reordered; and a tone mark deletes the syllable's vowel, collapsing ป่า/ป้า/ป๊า/ป๋า to the same phonemes\u003c/li\u003e\n\u003cli\u003eTLTK does dictionary-based word segmentation and emits a tone digit (1-5) per syllable, in the same style \u003ccode\u003ephonemize_chinese\u003c/code\u003e uses for Mandarin tones\u003c/li\u003e\n\u003cli\u003eThe whole inventory already has ids in the default IPA map, so Thai voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --th\u003c/code\u003e, and install the \u003ccode\u003eth\u003c/code\u003e extra in CI so the Thai tests run\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.7.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Japanese phonemizer using OpenJTalk (\u003ccode\u003epyopenjtalk-plus\u003c/code\u003e) in the new \u003ccode\u003eja\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type japanese\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;japanese\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng has no kanji coverage (it reads out Unicode character names) and no pitch accent\u003c/li\u003e\n\u003cli\u003eFull-context labels are parsed for pitch accent and mapped to IPA, so Japanese voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --ja\u003c/code\u003e, and install the \u003ccode\u003eja\u003c/code\u003e extra in CI so the Japanese tests run\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibpiper\u003c/code\u003e: add \u003ccode\u003epiper_create_options\u003c/code\u003e and \u003ccode\u003epiper_create_with_options()\u003c/code\u003e, with \u003ccode\u003epiper_create()\u003c/code\u003e kept as a wrapper for ABI compatibility\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.6.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRun the g2pW model through \u003ccode\u003epiper.g2pw_onnx\u003c/code\u003e instead of \u003ccode\u003eg2pw.api\u003c/code\u003e, dropping \u003ccode\u003etorch\u003c/code\u003e (~750 MB installed) and \u003ccode\u003erequests\u003c/code\u003e from the \u003ccode\u003ezh\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eg2pw.api\u003c/code\u003e imports torch only to build padded tensors and iterate batches; the model itself already ran under onnxruntime\u003c/li\u003e\n\u003cli\u003eAlso 1.5-2x faster, since it no longer forks DataLoader worker processes on every call\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eg2pW\u003c/code\u003e is still required, for its pinyin/bopomofo lookup tables\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Hebrew phonemizer using Nakdimon\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003elibpiper\u003c/code\u003e C++ CLI executable ported from the legacy Piper repository, plus a C++ test suite\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003elibpiper\u003c/code\u003e builds on Windows (MSVC, MSYS2-GCC) and Windows CI\u003c/li\u003e\n\u003cli\u003eBump embedded espeak-ng version\u003c/li\u003e\n\u003cli\u003eAdd default speaker id for multi-speaker voices\u003c/li\u003e\n\u003cli\u003eAdd vowel clustering support (\u003ccode\u003e--data.vowel_clusters\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd in-memory patching for alignments\u003c/li\u003e\n\u003cli\u003eTraining: add MRD (Multi-Resolution STFT) discriminator, loss/MOS tracking with UTMOS, silence-trim fixes, and dataloader performance improvements\u003c/li\u003e\n\u003cli\u003ePass custom phoneme id map when training\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/blob/main/CHANGELOG.md\"\u003epiper-tts's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.8.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Thai phonemizer using TLTK in the new \u003ccode\u003eth\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type thai\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;thai\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng's Thai voice is a placeholder: its \u003ccode\u003eth_dict\u003c/code\u003e holds no lexicon, so unspaced Thai is never segmented; the leading vowels เ แ โ ใ ไ are not reordered; and a tone mark deletes the syllable's vowel, collapsing ป่า/ป้า/ป๊า/ป๋า to the same phonemes\u003c/li\u003e\n\u003cli\u003eTLTK does dictionary-based word segmentation and emits a tone digit (1-5) per syllable, in the same style \u003ccode\u003ephonemize_chinese\u003c/code\u003e uses for Mandarin tones\u003c/li\u003e\n\u003cli\u003eThe whole inventory already has ids in the default IPA map, so Thai voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --th\u003c/code\u003e, and install the \u003ccode\u003eth\u003c/code\u003e extra in CI so the Thai tests run\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.7.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Japanese phonemizer using OpenJTalk (\u003ccode\u003epyopenjtalk-plus\u003c/code\u003e) in the new \u003ccode\u003eja\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type japanese\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;japanese\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng has no kanji coverage (it reads out Unicode character names) and no pitch accent\u003c/li\u003e\n\u003cli\u003eFull-context labels are parsed for pitch accent and mapped to IPA, so Japanese voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --ja\u003c/code\u003e, and install the \u003ccode\u003eja\u003c/code\u003e extra in CI so the Japanese tests run\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibpiper\u003c/code\u003e: add \u003ccode\u003epiper_create_options\u003c/code\u003e and \u003ccode\u003epiper_create_with_options()\u003c/code\u003e, with \u003ccode\u003epiper_create()\u003c/code\u003e kept as a wrapper for ABI compatibility\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.6.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRun the g2pW model through \u003ccode\u003epiper.g2pw_onnx\u003c/code\u003e instead of \u003ccode\u003eg2pw.api\u003c/code\u003e, dropping \u003ccode\u003etorch\u003c/code\u003e (~750 MB installed) and \u003ccode\u003erequests\u003c/code\u003e from the \u003ccode\u003ezh\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eg2pw.api\u003c/code\u003e imports torch only to build padded tensors and iterate batches; the model itself already ran under onnxruntime\u003c/li\u003e\n\u003cli\u003eAlso 1.5-2x faster, since it no longer forks DataLoader worker processes on every call\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eg2pW\u003c/code\u003e is still required, for its pinyin/bopomofo lookup tables\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Hebrew phonemizer using Nakdimon\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003elibpiper\u003c/code\u003e C++ CLI executable ported from the legacy Piper repository, plus a C++ test suite\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003elibpiper\u003c/code\u003e builds on Windows (MSVC, MSYS2-GCC) and Windows CI\u003c/li\u003e\n\u003cli\u003eBump embedded espeak-ng version\u003c/li\u003e\n\u003cli\u003eAdd default speaker id for multi-speaker voices\u003c/li\u003e\n\u003cli\u003eAdd vowel clustering support (\u003ccode\u003e--data.vowel_clusters\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd in-memory patching for alignments\u003c/li\u003e\n\u003cli\u003eTraining: add MRD (Multi-Resolution STFT) discriminator, loss/MOS tracking with UTMOS, silence-trim fixes, and dataloader performance improvements\u003c/li\u003e\n\u003cli\u003ePass custom phoneme id map when training\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/639388b6317fc4731e91d53da42aea68fd4166ff\"\u003e\u003ccode\u003e639388b\u003c/code\u003e\u003c/a\u003e Bump version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/46d794711decab265e7f04c8a9a2f03f5d40b244\"\u003e\u003ccode\u003e46d7947\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/OHF-voice/piper1-gpl/issues/293\"\u003e#293\u003c/a\u003e from OHF-Voice/claude/thai-piper-training-feasibility...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/9336d103bd2aa8f94d21c8b14c3e0d7727da292c\"\u003e\u003ccode\u003e9336d10\u003c/code\u003e\u003c/a\u003e Fix Thai test collection aborting CI on a broken optional dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/fb14e09b49725af3cd806d2aba6c9f33501546ce\"\u003e\u003ccode\u003efb14e09\u003c/code\u003e\u003c/a\u003e Add Thai phonemizer (TLTK segmentation + G2P -\u0026gt; IPA + tone digits)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/850c45a3d70b5981de4d908ba98caf39796e7201\"\u003e\u003ccode\u003e850c45a\u003c/code\u003e\u003c/a\u003e fix: Phase 1 relaxed poly fallback for mobile (\u003ca href=\"https://redirect.github.com/OHF-voice/piper1-gpl/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/b2758261878e4d832acb208e33915df8954ae2d4\"\u003e\u003ccode\u003eb275826\u003c/code\u003e\u003c/a\u003e Add Chinese pinyin support – Phase 1 (monophonic dict fallback, honest scopin...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/7b8e8f7197a480047677715f00d3d78903b55a2a\"\u003e\u003ccode\u003e7b8e8f7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/OHF-voice/piper1-gpl/issues/275\"\u003e#275\u003c/a\u003e from OHF-Voice/claude/version-1-7-0-release-2b37ec\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/222159fb3a25672b1a1a6c8f4d5f9351ed68ad3d\"\u003e\u003ccode\u003e222159f\u003c/code\u003e\u003c/a\u003e Silence pylint redefined-outer-name in the phonemizer tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/af4ff76238e6aee94f95555fbff87c001ecf94bc\"\u003e\u003ccode\u003eaf4ff76\u003c/code\u003e\u003c/a\u003e Make the mypy exclude for vendored VITS code actually work\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/c0f3289b64e2eb704ac115af61cac90228e2f7d2\"\u003e\u003ccode\u003ec0f3289\u003c/code\u003e\u003c/a\u003e Release 1.7.0: add --ja setup flag and test Japanese in CI\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/OHF-voice/piper1-gpl/compare/v1.4.2...v1.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `playwright` from 1.55.0 to 1.63.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/playwright-python/releases\"\u003eplaywright's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.63.0\u003c/h2\u003e\n\u003ch2\u003e🪟 Locate across frames\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/python/docs/api/class-page#page-frame-locator\"\u003epage.frame_locator()\u003c/a\u003e and \u003ca href=\"https://playwright.dev/python/docs/api/class-frame#frame-frame-locator\"\u003eframe.frame_locator()\u003c/a\u003e called without a selector search in any frame of the\nsubtree, so you no longer need to locate the iframe first:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# Finds the button in any frame on the page.\r\npage.frame_locator().get_by_role(\u0026quot;button\u0026quot;).click()\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it\nmatches elements in several frames.\u003c/p\u003e\n\u003ch2\u003e👁️ Visible-only locators\u003c/h2\u003e\n\u003cp\u003eNew \u003ca href=\"https://playwright.dev/python/docs/api/class-locator#locator-visible\"\u003elocator.visible\u003c/a\u003e returns a locator that matches only visible elements. It is the recommended\nreplacement for the \u003ccode\u003e:visible\u003c/code\u003e CSS pseudo-class:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003epage.locator(\u0026quot;button\u0026quot;).visible.click()\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch2\u003e🖼️ Aria and screen snapshots in traces\u003c/h2\u003e\n\u003cp\u003eNew \u003ca href=\"https://playwright.dev/python/docs/api/class-tracing#tracing-start-option-aria-snapshots\"\u003e\u003ccode\u003earia_snapshots\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://playwright.dev/python/docs/api/class-tracing#tracing-start-option-screen-snapshots\"\u003e\u003ccode\u003escreen_snapshots\u003c/code\u003e\u003c/a\u003e options of\n\u003ca href=\"https://playwright.dev/python/docs/api/class-tracing#tracing-start\"\u003etracing.start()\u003c/a\u003e capture an aria snapshot and a screenshot of the page on every action:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003econtext.tracing.start(snapshots=True, aria_snapshots=True, screen_snapshots=True)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eWith aria and screen snapshots recorded, the new \u003cstrong\u003eDisplay Aria\u003c/strong\u003e mode in the trace viewer shows the action screenshot\nside by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.\u003c/p\u003e\n\u003ch2\u003eNew APIs\u003c/h2\u003e\n\u003ch3\u003eBrowser and Context\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://playwright.dev/python/docs/api/class-browser#browser-new-context-option-http-credentials\"\u003e\u003ccode\u003ehttp_credentials\u003c/code\u003e\u003c/a\u003e now also accepts an array of credentials. The first entry matching the request origin is used, and entries without an origin match any request.\u003c/li\u003e\n\u003cli\u003eNew option \u003ca href=\"https://playwright.dev/python/docs/api/class-browsercontext#browser-context-storage-state-option-opfs\"\u003e\u003ccode\u003eopfs\u003c/code\u003e\u003c/a\u003e includes the \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/File_System_API/Origin_private_file_system\"\u003eorigin private file system\u003c/a\u003e in the storage state, so it can be persisted and restored into later contexts.\u003c/li\u003e\n\u003cli\u003eNew events \u003ca href=\"https://playwright.dev/python/docs/api/class-page#page-event-dialog-closed\"\u003epage.on('dialogclosed')\u003c/a\u003e and \u003ca href=\"https://playwright.dev/python/docs/api/class-browsercontext#browser-context-event-dialog-closed\"\u003ebrowserContext.on('dialogclosed')\u003c/a\u003e are emitted when a JavaScript dialog is accepted, dismissed or closed by the user.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommand line\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eplaywright install --no-remove\u003c/code\u003e keeps the browsers of other Playwright installations instead of removing them.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eplaywright codegen --http-credentials\u003c/code\u003e records against pages behind HTTP authentication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e⚠️ Ubuntu 20.04 is not supported anymore.\u003c/li\u003e\n\u003cli\u003e🐧 On Linux arm64, Playwright now downloads the \u003ca href=\"https://developer.chrome.com/blog/chrome-for-testing\"\u003eChrome for Testing\u003c/a\u003e build of Chromium, the same build used on all other platforms.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/8cb967b3e4199bef5ce38e1cf34df1bf79cb8a8d\"\u003e\u003ccode\u003e8cb967b\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3200\"\u003e#3200\u003c/a\u003e): devops(docker): move docker publishing to Azure Pipelines\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/ab18c77c56f64b47e871bf4d8b08fd0675559377\"\u003e\u003ccode\u003eab18c77\u003c/code\u003e\u003c/a\u003e chore: roll Playwright to 1.63.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3198\"\u003e#3198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/0e66a0927e5431b0f659ff41b6544de96b0486f5\"\u003e\u003ccode\u003e0e66a09\u003c/code\u003e\u003c/a\u003e devops(pipeline): resolve pip and npm packages from DevDiv_PublicPackages fee...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/010a9cc73f8a90bc2d7b9e34591c4e2c4a4ea566\"\u003e\u003ccode\u003e010a9cc\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3176\"\u003e#3176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/154f67ced51ada646b0fcf8574897d96c9712aa3\"\u003e\u003ccode\u003e154f67c\u003c/code\u003e\u003c/a\u003e fix(sync): wait for initialize before leaving \u003cstrong\u003eenter\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3168\"\u003e#3168\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/4af2fc65fb05eb04904b69b6206e9d07ca2b4cbc\"\u003e\u003ccode\u003e4af2fc6\u003c/code\u003e\u003c/a\u003e chore: roll Playwright to 1.62.1 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3169\"\u003e#3169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/4d2e058f43f05448ad29b19e82919be5b86e8349\"\u003e\u003ccode\u003e4d2e058\u003c/code\u003e\u003c/a\u003e fix(connection): register protocol callback only after successful send (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/eab2bca195df8709bd32fc11129c268cf8963cd2\"\u003e\u003ccode\u003eeab2bca\u003c/code\u003e\u003c/a\u003e chore(deps): remove unused development dependencies (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3164\"\u003e#3164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/3b7c24c3e67dc84f7b0eddd0c5fd2ca685705021\"\u003e\u003ccode\u003e3b7c24c\u003c/code\u003e\u003c/a\u003e chore: roll Playwright to 1.62.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3161\"\u003e#3161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/1db079f769ff42c60b7bde3498fb98f638131534\"\u003e\u003ccode\u003e1db079f\u003c/code\u003e\u003c/a\u003e build(deps): bump typing-extensions from 4.15.0 to 4.16.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3162\"\u003e#3162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/playwright-python/compare/v1.55.0...v1.63.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.13.4 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `scipy` from 1.18.0 to 1.18.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/scipy/scipy/releases\"\u003escipy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eSciPy 1.18.1 Release Notes\u003c/h1\u003e\n\u003cp\u003eSciPy \u003ccode\u003e1.18.1\u003c/code\u003e is a bug-fix release with no new features\ncompared to \u003ccode\u003e1.18.0\u003c/code\u003e. This release includes binaries on\nPyPI for Python \u003ccode\u003e3.15\u003c/code\u003e, and the minimum required version\nof the GCC toolchain has been increased to \u003ccode\u003e10.3...\n\n_Description has been truncated_","html_url":"https://github.com/debpalash/friday/pull/14","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/debpalash%2Ffriday/issues/14","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/14/packages"},{"uuid":"5502511387","node_id":"PR_kwDORckIoM8AAAABEHcvOw","number":1587,"state":"open","title":"security(deps): Bump the inference-dependencies group in /evaluation with 4 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-18T17:22:40.000Z","updated_at":"2026-09-18T17:23:01.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"security(deps): Bump","group_name":"inference-dependencies","update_count":4,"packages":[{"name":"onnxscript","old_version":"0.7.1","new_version":"0.7.2","repository_url":"https://github.com/microsoft/onnxscript"},{"name":"onnxruntime-gpu","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"transformers","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tensordict","old_version":"0.14.1","new_version":"0.14.2","repository_url":"https://github.com/pytorch/tensordict"}],"path":"/evaluation","ecosystem":"pip"},"body":"Bumps the inference-dependencies group in /evaluation with 4 updates: [onnxscript](https://github.com/microsoft/onnxscript), [onnxruntime-gpu](https://github.com/microsoft/onnxruntime), [transformers](https://github.com/huggingface/transformers) and [tensordict](https://github.com/pytorch/tensordict).\n\nUpdates `onnxscript` from 0.7.1 to 0.7.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxscript/releases\"\u003eonnxscript's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.7.2\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eOptimizer and rewriter\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix constant folding dropping subgraph initializers when inlining If branches by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2825\"\u003emicrosoft/onnxscript#2825\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove Reshape and Slice folding by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2807\"\u003emicrosoft/onnxscript#2807\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTorch Lib\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[torchlib] Add \u003ccode\u003eprims::remainder\u003c/code\u003e by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2953\"\u003emicrosoft/onnxscript#2953\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGenerate new opsets up to 27 by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2958\"\u003emicrosoft/onnxscript#2958\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix incorrect rank handling in aten_repeat_interleave_self_int ONNX export \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2932\"\u003e#2932\u003c/a\u003e by \u003ca href=\"https://github.com/PratikWayase\"\u003e\u003ccode\u003e@​PratikWayase\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2936\"\u003emicrosoft/onnxscript#2936\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExport aten::relu6 as a single Clip op by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2987\"\u003emicrosoft/onnxscript#2987\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FFT export truncation by preserving dft_length in rFFT lowering by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2991\"\u003emicrosoft/onnxscript#2991\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix invalid ONNX graph from None start/end in aten_slice_scatter by \u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3006\"\u003emicrosoft/onnxscript#3006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor the dtype argument of aten::mean when exporting without dim by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3009\"\u003emicrosoft/onnxscript#3009\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix dynamo export for scalar mul on converted real tensors by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3005\"\u003emicrosoft/onnxscript#3005\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMaterialize the DFT axis default when converting opset 19 to 20 by \u003ca href=\"https://github.com/MohammedAlkindi\"\u003e\u003ccode\u003e@​MohammedAlkindi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3023\"\u003emicrosoft/onnxscript#3023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_isclose handling of infinities and equal_nan by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3026\"\u003emicrosoft/onnxscript#3026\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix float16 trunc division rounding by \u003ca href=\"https://github.com/Alphaxiaoteng\"\u003e\u003ccode\u003e@​Alphaxiaoteng\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3025\"\u003emicrosoft/onnxscript#3025\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd converter for \u003ccode\u003eaten::_grouped_mm.default\u003c/code\u003e by \u003ca href=\"https://github.com/Sid-V5\"\u003e\u003ccode\u003e@​Sid-V5\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2805\"\u003emicrosoft/onnxscript#2805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_roll for negative dims and shifts past the dimension length by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3024\"\u003emicrosoft/onnxscript#3024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[torchlib] Reimplement as_strided without an ONNX loop by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2928\"\u003emicrosoft/onnxscript#2928\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip GQA key/value repeat when query and key head counts are equal by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2957\"\u003emicrosoft/onnxscript#2957\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SplitToSequence with scalar uneven split producing incorrect equal-split output by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2858\"\u003emicrosoft/onnxscript#2858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ReshapeReshape initializer name collisions when resolving shared \u003ccode\u003e-1\u003c/code\u003e shapes by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2947\"\u003emicrosoft/onnxscript#2947\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[torchlib] add \u003ccode\u003eaten::bincount\u003c/code\u003e ONNX lowering and bool-mask \u003ccode\u003eaten::index_put\u003c/code\u003e fix with e2e coverage by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2921\"\u003emicrosoft/onnxscript#2921\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSet kernel_shape attribute on Conv/ConvTranspose in torchlib by \u003ca href=\"https://github.com/titaiwangms\"\u003e\u003ccode\u003e@​titaiwangms\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2972\"\u003emicrosoft/onnxscript#2972\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDisable Publish Docs workflow on forks by \u003ca href=\"https://github.com/take-cheeze\"\u003e\u003ccode\u003e@​take-cheeze\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2980\"\u003emicrosoft/onnxscript#2980\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_linear rank mismatch for 1D weight (missing squeeze) by \u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2984\"\u003emicrosoft/onnxscript#2984\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove integer aten_floor_divide export to drop Sign ops by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2960\"\u003emicrosoft/onnxscript#2960\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix full_like Dynamo export when memory_format is passed by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2994\"\u003emicrosoft/onnxscript#2994\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse the query dtype's lowest finite value for the causal attention mask by \u003ca href=\"https://github.com/SubhajitMitra-GH\"\u003e\u003ccode\u003e@​SubhajitMitra-GH\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2992\"\u003emicrosoft/onnxscript#2992\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAccept memory_format kwarg on rand/randn/randint _like ops by \u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3011\"\u003emicrosoft/onnxscript#3011\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEmit scalar Range bounds in aten_unfold by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3013\"\u003emicrosoft/onnxscript#3013\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs(_framework_apis): say check_model is a deliberate no-op by \u003ca href=\"https://github.com/MohammedAlkindi\"\u003e\u003ccode\u003e@​MohammedAlkindi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3012\"\u003emicrosoft/onnxscript#3012\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix arange and logit behavior for torch-nightly CI by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2974\"\u003emicrosoft/onnxscript#2974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFold Gemm beta into the fused BatchNorm bias by \u003ca href=\"https://github.com/MohammedAlkindi\"\u003e\u003ccode\u003e@​MohammedAlkindi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3027\"\u003emicrosoft/onnxscript#3027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_pow_scalar type promotion when the exponent is not floating point by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3036\"\u003emicrosoft/onnxscript#3036\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Codecov test-results upload to supported action path by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2970\"\u003emicrosoft/onnxscript#2970\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix protobuf serialization failure in ort_fusions ort_run for large models by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2955\"\u003emicrosoft/onnxscript#2955\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2995\"\u003emicrosoft/onnxscript#2995\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PratikWayase\"\u003e\u003ccode\u003e@​PratikWayase\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2936\"\u003emicrosoft/onnxscript#2936\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2984\"\u003emicrosoft/onnxscript#2984\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SubhajitMitra-GH\"\u003e\u003ccode\u003e@​SubhajitMitra-GH\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2992\"\u003emicrosoft/onnxscript#2992\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2995\"\u003emicrosoft/onnxscript#2995\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/082bfa28e959a4c0639d91b62663c6c59c4dfc42\"\u003e\u003ccode\u003e082bfa2\u003c/code\u003e\u003c/a\u003e Fix aten_pow_scalar type promotion when the exponent is not floating point (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/d1c005d158f40020597a0b35fd681c4f5286378f\"\u003e\u003ccode\u003ed1c005d\u003c/code\u003e\u003c/a\u003e [torchlib] Reimplement as_strided without an ONNX loop (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2928\"\u003e#2928\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/9b6d4cc7f19478bd9e7a61385e83a9016f291480\"\u003e\u003ccode\u003e9b6d4cc\u003c/code\u003e\u003c/a\u003e Fix aten_roll for negative dims and shifts past the dimension length (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3024\"\u003e#3024\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/9709f8a0777037c4c0a6320a64593f342aef7183\"\u003e\u003ccode\u003e9709f8a\u003c/code\u003e\u003c/a\u003e Add converter for \u003ccode\u003eaten::_grouped_mm.default\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2805\"\u003e#2805\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/b4c10fab5b65d7f15bbaadae89512ba4fba74745\"\u003e\u003ccode\u003eb4c10fa\u003c/code\u003e\u003c/a\u003e Fold Gemm beta into the fused BatchNorm bias (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3027\"\u003e#3027\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/fc4357c74d827639b72c8a7ea55d89920b1b1e2f\"\u003e\u003ccode\u003efc4357c\u003c/code\u003e\u003c/a\u003e Fix float16 trunc division rounding (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3025\"\u003e#3025\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/995ce9819494bbee2531e2d2b8cb0e7346676fed\"\u003e\u003ccode\u003e995ce98\u003c/code\u003e\u003c/a\u003e Fix aten_isclose handling of infinities and equal_nan (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3026\"\u003e#3026\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/c927620f320c37ea638e2abad20c994afa107953\"\u003e\u003ccode\u003ec927620\u003c/code\u003e\u003c/a\u003e Materialize the DFT axis default when converting opset 19 to 20 (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3023\"\u003e#3023\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/3ba2bf74970122d2a8b043765128f34cea69be8f\"\u003e\u003ccode\u003e3ba2bf7\u003c/code\u003e\u003c/a\u003e Fix arange and logit behavior for torch-nightly CI (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2974\"\u003e#2974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/0e4df17d1f21f6216f06be0a430c09360cbd3c3e\"\u003e\u003ccode\u003e0e4df17\u003c/code\u003e\u003c/a\u003e docs(_framework_apis): say check_model is a deliberate no-op (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3012\"\u003e#3012\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxscript/compare/v0.7.1...v0.7.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `onnxruntime-gpu` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxruntime/releases\"\u003eonnxruntime-gpu's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eONNX Runtime v1.30.0\u003c/h2\u003e\n\u003cp\u003eONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32168\"\u003e#32168\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32340\"\u003e#32340\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32515\"\u003e#32515\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31727\"\u003e#31727\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32277\"\u003e#32277\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32284\"\u003e#32284\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32420\"\u003e#32420\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31674\"\u003e#31674\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31973\"\u003e#31973\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32178\"\u003e#32178\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32356\"\u003e#32356\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements \u0026amp; Compatibility\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with \u003ccode\u003e-Donnxruntime_USE_FP4_QMOE=OFF\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32096\"\u003e#32096\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32163\"\u003e#32163\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and \u003ccode\u003eblock_size=32\u003c/code\u003e. Set \u003ccode\u003e-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON\u003c/code\u003e when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32324\"\u003e#32324\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCPU FP16 \u003ccode\u003eGemm\u003c/code\u003e and \u003ccode\u003eMatMul\u003c/code\u003e execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32301\"\u003e#32301\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32197\"\u003e#32197\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eWebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32287\"\u003e#32287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31960\"\u003e#31960\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31970\"\u003e#31970\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSecurity \u0026amp; Reliability\u003c/h2\u003e\n\u003ch3\u003eModel Loading, Memory, and Input Validation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimited nested model-graph depth and canonicalized external-data locations to harden model loading (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32344\"\u003e#32344\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32135\"\u003e#32135\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32010\"\u003e#32010\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32040\"\u003e#32040\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eStrengthened shape, rank, and parameter validation for \u003ccode\u003eSplit\u003c/code\u003e, \u003ccode\u003eScan\u003c/code\u003e, \u003ccode\u003eGatherND\u003c/code\u003e, \u003ccode\u003eScatterND\u003c/code\u003e, \u003ccode\u003eSpaceToDepth\u003c/code\u003e/\u003ccode\u003eDepthToSpace\u003c/code\u003e, \u003ccode\u003eCrop\u003c/code\u003e, \u003ccode\u003eConv\u003c/code\u003e, \u003ccode\u003eNormalizer\u003c/code\u003e, and pooling (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29461\"\u003e#29461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31668\"\u003e#31668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32034\"\u003e#32034\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32039\"\u003e#32039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32076\"\u003e#32076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32157\"\u003e#32157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32160\"\u003e#32160\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32161\"\u003e#32161\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32345\"\u003e#32345\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32349\"\u003e#32349\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eHardened generation and attention input handling, including attention-attribute narrowing, \u003ccode\u003eBifurcationDetector\u003c/code\u003e inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31648\"\u003e#31648\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31701\"\u003e#31701\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32009\"\u003e#32009\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32078\"\u003e#32078\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32144\"\u003e#32144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eValidated \u003ccode\u003eTreeEnsemble\u003c/code\u003e node references and bounded subtree comparison, rejected non-finite CPU \u003ccode\u003eRoiAlign\u003c/code\u003e coordinates, and required \u003ccode\u003eImageScaler\u003c/code\u003e bias to match the channel count (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32031\"\u003e#32031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32043\"\u003e#32043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32011\"\u003e#32011\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32002\"\u003e#32002\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded an allowlist of safe LoRA adapter parameter data types, validated \u003ccode\u003eMatMulFpQ4\u003c/code\u003e shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31682\"\u003e#31682\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32032\"\u003e#32032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32007\"\u003e#32007\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eGPU Bounds and Resource Lifetimes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHardened CUDA indexing and buffer-size arithmetic in \u003ccode\u003eMatMulNBits\u003c/code\u003e, \u003ccode\u003eRemovePadding\u003c/code\u003e, \u003ccode\u003eRotaryEmbedding\u003c/code\u003e, \u003ccode\u003eSparseAttention\u003c/code\u003e, Whisper beam search, NMS, QDQ, and \u003ccode\u003eGatherElements\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31643\"\u003e#31643\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31994\"\u003e#31994\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31995\"\u003e#31995\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31996\"\u003e#31996\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31998\"\u003e#31998\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32014\"\u003e#32014\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32029\"\u003e#32029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32030\"\u003e#32030\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32137\"\u003e#32137\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32330\"\u003e#32330\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31997\"\u003e#31997\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept \u003ccode\u003eCudaAsyncBuffer\u003c/code\u003e staging storage alive across CUDA graph replay (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31968\"\u003e#31968\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32121\"\u003e#32121\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32364\"\u003e#32364\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32063\"\u003e#32063\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32317\"\u003e#32317\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies and Tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29906\"\u003e#29906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32190\"\u003e#32190\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32424\"\u003e#32424\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUpdated JavaScript dependencies including \u003ccode\u003ejs-yaml\u003c/code\u003e, \u003ccode\u003ejoi\u003c/code\u003e, \u003ccode\u003efast-uri\u003c/code\u003e, and the Next.js end-to-end fixture (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32397\"\u003e#32397\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32486\"\u003e#32486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32488\"\u003e#32488\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32505\"\u003e#32505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32508\"\u003e#32508\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32176\"\u003e#32176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32005\"\u003e#32005\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32440\"\u003e#32440\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003ch3\u003eCore APIs \u0026amp; Runtime\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExtended memory importing with host-pointer support and added access to preallocated outputs through \u003ccode\u003eKernelContext::GetPreallocatedOutput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29726\"\u003e#29726\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32089\"\u003e#32089\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32283\"\u003e#32283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32321\"\u003e#32321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32312\"\u003e#32312\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded DeepSeek Engram contrib operators, \u003ccode\u003eEngramGate\u003c/code\u003e and \u003ccode\u003eNGramHashMapping\u003c/code\u003e, and expanded kernel coverage for Qwen-3.5 operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32106\"\u003e#32106\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/f2c39fe2f838cf35ce7da92824f5a5e3ee6e88a7\"\u003e\u003ccode\u003ef2c39fe\u003c/code\u003e\u003c/a\u003e [CUDA] Add INT4 paged KV cache with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32515\"\u003e#32515\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/5894ba8a53526b3aeb702bd86e6b117c9df8fa4f\"\u003e\u003ccode\u003e5894ba8\u003c/code\u003e\u003c/a\u003e Add portable random-access file reads to Env (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/a2ee3eb43052de307003e6256fc9258ce19d9c34\"\u003e\u003ccode\u003ea2ee3eb\u003c/code\u003e\u003c/a\u003e Fix CUDA plugin device discovery on WSL (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32517\"\u003e#32517\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/b652e595b04d202b7f71af1d9105a183fac2b100\"\u003e\u003ccode\u003eb652e59\u003c/code\u003e\u003c/a\u003e [WebGPU] Prepack Conv weights for the im2col-matmul path (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32420\"\u003e#32420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/0f0f29f5015f16926912ae47061e6a3eedcfbe04\"\u003e\u003ccode\u003e0f0f29f\u003c/code\u003e\u003c/a\u003e Get rid of spurious warning about not being able to find spectre mitigation (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/23dd6510fd395b4556f474c1c0079be2a8b7a8c8\"\u003e\u003ccode\u003e23dd651\u003c/code\u003e\u003c/a\u003e Register ONNX schemas only when static registration is disabled (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32353\"\u003e#32353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/33af5d32801b2e631ebece4f382f4ba775f17d8c\"\u003e\u003ccode\u003e33af5d3\u003c/code\u003e\u003c/a\u003e Release external data loaders after graph initialization (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32502\"\u003e#32502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/2e3c24d5963d62d0bd7c9d306433b19b7304d5d2\"\u003e\u003ccode\u003e2e3c24d\u003c/code\u003e\u003c/a\u003e Clarify external initializer and EP context path interaction (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32442\"\u003e#32442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/e76036b8e49515ee7dd2dd0ac39c9d8b7533d38a\"\u003e\u003ccode\u003ee76036b\u003c/code\u003e\u003c/a\u003e [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32433\"\u003e#32433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/82583c5b6398a9c37815f91e9cd1d7c165a132a7\"\u003e\u003ccode\u003e82583c5\u003c/code\u003e\u003c/a\u003e Add session option for a BNHS GroupQueryAttention Value cache layout (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32139\"\u003e#32139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxruntime/compare/v1.29.0...v1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.16.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tensordict` from 0.14.1 to 0.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/tensordict/releases\"\u003etensordict's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eTensorDict v0.14.2\u003c/h2\u003e\n\u003cp\u003eTensorDict 0.14.2 is a patch release correcting compiled shallow copies, non-tensor concatenation, and CUDA graph replay. No new public APIs, breaking changes, or deprecations are introduced.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve independent nested containers in compiled shallow copies while continuing to share tensor leaves (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/pull/1784\"\u003e#1784\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePreserve non-tensor values during concatenation, including mixed inputs and padded metadata, while retaining scalar metadata and weak-reference behavior (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/pull/1786\"\u003e#1786\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eEnsure CUDA graph replay uses updated inputs when a module writes outputs under its input keys (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/pull/1788\"\u003e#1788\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eInstall after publication: \u003ccode\u003epip install tensordict==0.14.2\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/vmoens\"\u003e\u003ccode\u003e@​vmoens\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pytorch/tensordict/compare/v0.14.1...v0.14.2\"\u003eFull changelog\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/f2b44ecd1ed86b34aad43a075a04e9f45e22c044\"\u003e\u003ccode\u003ef2b44ec\u003c/code\u003e\u003c/a\u003e [Versioning] Prepare TensorDict 0.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/72b56ac039deb19d58aa348e92132bf2d60bf8a3\"\u003e\u003ccode\u003e72b56ac\u003c/code\u003e\u003c/a\u003e [BugFix] Preserve uniform metadata during non-tensor concatenation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/1bb5136fd43119e0f8246f00a4a0f8d547853e63\"\u003e\u003ccode\u003e1bb5136\u003c/code\u003e\u003c/a\u003e [BugFix] Keep CudaGraphModule inputs bound when a module rewrites its input k...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/1f853a53e63fef528b93e8aa464058cf0be48ba7\"\u003e\u003ccode\u003e1f853a5\u003c/code\u003e\u003c/a\u003e [BugFix] Preserve non-tensor values during concatenation (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/issues/1786\"\u003e#1786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/03e16e08e271ad6d8494a80eefa8b05c6ee69225\"\u003e\u003ccode\u003e03e16e0\u003c/code\u003e\u003c/a\u003e [Compile] Preserve nested structure in shallow TensorDict copies (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/issues/1784\"\u003e#1784\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pytorch/tensordict/compare/v0.14.1...v0.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/microsoft/physical-ai-toolchain/pull/1587","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/microsoft%2Fphysical-ai-toolchain/issues/1587","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1587/packages"},{"uuid":"5481366270","node_id":"PR_kwDOS3kNmM8AAAABD2crDA","number":132,"state":"closed","title":"chore(deps)(deps): update transformers requirement from \u003e=4.35.0 to \u003e=5.17.0 in /backend","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-17T00:38:04.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-17T00:31:08.000Z","updated_at":"2026-09-17T00:38:13.000Z","time_to_close":416,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): update","packages":[{"name":"transformers","old_version":"\u003e=4.35.0","new_version":"\u003e=5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":"/backend","ecosystem":"pip"},"body":"Updates the requirements on [transformers](https://github.com/huggingface/transformers) to permit the latest version.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.35.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/health-assistant-io/health-assistant/pull/132","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/health-assistant-io%2Fhealth-assistant/issues/132","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/132/packages"},{"uuid":"5479729744","node_id":"PR_kwDOSigF3M8AAAABD1It1g","number":82,"state":"open","title":"Bump the python-minor-patch group across 1 directory with 9 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-16T20:45:44.000Z","updated_at":"2026-09-25T07:00:22.462Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"python-minor-patch","update_count":9,"packages":[{"name":"aiolimiter","old_version":"1.2.1","new_version":"1.3.0","repository_url":"https://github.com/mjpieters/aiolimiter"},{"name":"fastapi","old_version":"0.139.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"numpy","old_version":"2.5.1","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"pgvector","old_version":"0.4.2","new_version":"0.5.0","repository_url":"https://github.com/pgvector/pgvector-python"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"rapidfuzz","old_version":"3.14.5","new_version":"3.14.6","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"av","old_version":"18.0.0","new_version":"18.1.0","repository_url":"https://github.com/PyAV-Org/PyAV"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.13.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-minor-patch group with 9 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiolimiter](https://github.com/mjpieters/aiolimiter) | `1.2.1` | `1.3.0` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.0` | `0.141.1` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.1` | `2.5.3` |\n| [pgvector](https://github.com/pgvector/pgvector-python) | `0.4.2` | `0.5.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.14.5` | `3.14.6` |\n| [av](https://github.com/PyAV-Org/PyAV) | `18.0.0` | `18.1.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.13.0` | `5.17.0` |\n\n\nUpdates `aiolimiter` from 1.2.1 to 1.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mjpieters/aiolimiter/releases\"\u003eaiolimiter's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAiolimiter 1.3.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eTightened boundary checks for the \u003ccode\u003eamount\u003c/code\u003e argument to \u003ccode\u003eAsyncLimiter.acquire()\u003c/code\u003e, rejecting values outside the 0 to \u003ccode\u003emax_rate\u003c/code\u003e range. Negative values and \u003ccode\u003eNaN\u003c/code\u003e are no longer accepted. (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/760\"\u003e#760\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/313\"\u003e#313\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/655\"\u003e#655\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mjpieters/aiolimiter/blob/main/CHANGELOG.md\"\u003eaiolimiter's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eaiolimiter 1.3.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eTightened boundary checks for the \u003ccode\u003eamount\u003c/code\u003e argument to \u003ccode\u003eAsyncLimiter.acquire()\u003c/code\u003e, rejecting values outside the 0 to \u003ccode\u003emax_rate\u003c/code\u003e range. Negative values and \u003ccode\u003eNaN\u003c/code\u003e are no longer accepted. (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/760\"\u003e#760\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/313\"\u003e#313\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/655\"\u003e#655\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/f7df2d7ff4be2d2b64bb2cbf2340e5a8a28d988d\"\u003e\u003ccode\u003ef7df2d7\u003c/code\u003e\u003c/a\u003e ci: Address release process issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/be2530b0352d2382b71e6490b948356904543952\"\u003e\u003ccode\u003ebe2530b\u003c/code\u003e\u003c/a\u003e chore: fix sdist packaging\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/252b97ff8819e1ea3ffb79c676286feb0970c79e\"\u003e\u003ccode\u003e252b97f\u003c/code\u003e\u003c/a\u003e ci: unbreak prek step during releases\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/ee7f6efcd0ef8c15282e66bddda9871331585807\"\u003e\u003ccode\u003eee7f6ef\u003c/code\u003e\u003c/a\u003e Release v1.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/697643f8b768c63ade9777004b130d5203329297\"\u003e\u003ccode\u003e697643f\u003c/code\u003e\u003c/a\u003e feat: Reject negative and NaN acquisition amounts (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/760\"\u003e#760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/8438f6f458e2e00f9d3313f707af9c7abe2deb8f\"\u003e\u003ccode\u003e8438f6f\u003c/code\u003e\u003c/a\u003e chore(deps): lock file maintenance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/8ed24d146a52a961303db8b5c13691f0b4eaf212\"\u003e\u003ccode\u003e8ed24d1\u003c/code\u003e\u003c/a\u003e chore(deps): update pre-commit hook renovatebot/pre-commit-hooks to v44.65.5 ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/4c57d27f05d92f66ea4e961ff661d525db46e6b4\"\u003e\u003ccode\u003e4c57d27\u003c/code\u003e\u003c/a\u003e chore(deps): update pre-commit updates (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/759\"\u003e#759\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/6c2f96d316db42b20e0ccc7a9bf537e575cfee7e\"\u003e\u003ccode\u003e6c2f96d\u003c/code\u003e\u003c/a\u003e chore(deps): update dependency towncrier to v26\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/279fdb7780226444c2dd0f71807d45ffcd86a82d\"\u003e\u003ccode\u003e279fdb7\u003c/code\u003e\u003c/a\u003e chore(deps): update pre-commit updates (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/757\"\u003e#757\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mjpieters/aiolimiter/compare/v1.2.1...v1.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fastapi` from 0.139.0 to 0.141.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/fastapi/releases\"\u003efastapi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.141.1\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix support for background tasks and headers from dependencies in \u003ccode\u003eapp.frontend()\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16105\"\u003e#16105\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16104\"\u003e#16104\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.141.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more convenient with \u003ccode\u003efastapi dev\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16102\"\u003e#16102\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.13\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003estatus_code\u003c/code\u003e being ignored for SSE and JSONL streaming endpoints. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15937\"\u003e#15937\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Fix \u003ccode\u003eformat_sse_event\u003c/code\u003e docstring rendering of \u003ccode\u003e\\n\\n\u003c/code\u003e terminator. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15613\"\u003e#15613\u003c/a\u003e by \u003ca href=\"https://github.com/AshNicolus\"\u003e\u003ccode\u003e@​AshNicolus\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e📝 Add API reference page for fastapi.sse. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15930\"\u003e#15930\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.12\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix line splitting in \u003ccode\u003eformat_sse_event\u003c/code\u003e to comply with SSE spec. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15515\"\u003e#15515\u003c/a\u003e by \u003ca href=\"https://github.com/Zawwarsami16\"\u003e\u003ccode\u003e@​Zawwarsami16\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.11\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eresponse_model_*\u003c/code\u003e params ignored for non-generator endpoints with \u003ccode\u003eIterable[..]\u003c/code\u003e return type. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15093\"\u003e#15093\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.10\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix handling sequences with nested Annotated types. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/14874\"\u003e#14874\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Accept any base test failure as regression. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16092\"\u003e#16092\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🐛 Preserve pytest exit code in regression check. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16091\"\u003e#16091\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e✅ Test PR regressions against base code. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16090\"\u003e#16090\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.9\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eexclude_defaults\u003c/code\u003e not propagated to dict keys and values in \u003ccode\u003ejsonable_encoder\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16043\"\u003e#16043\u003c/a\u003e by \u003ca href=\"https://github.com/MBGrao\"\u003e\u003ccode\u003e@​MBGrao\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/95f8322ee1dcda7ceace7b1c4f6c9915b36d748f\"\u003e\u003ccode\u003e95f8322\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.1 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16106\"\u003e#16106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/f137944c435cff4e4b30ea7d12855ea88ddb868c\"\u003e\u003ccode\u003ef137944\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/d62354434b2e508fe89024213b220ca8e67dea5e\"\u003e\u003ccode\u003ed623544\u003c/code\u003e\u003c/a\u003e 🐛 Fix support for background tasks and headers from dependencies in `app.fron...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/1d211b9c1009d577f39fa2b19b10d9a93a72a0ed\"\u003e\u003ccode\u003e1d211b9\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/8a1f8768411e62093e70ce142ea10863a485643c\"\u003e\u003ccode\u003e8a1f876\u003c/code\u003e\u003c/a\u003e 📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16104\"\u003e#16104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/c7e7b651d6946c07cc9f675f39c9501d08319e57\"\u003e\u003ccode\u003ec7e7b65\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.0 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16103\"\u003e#16103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/6bceb84053eb2405e9c000aad30ea13367b5ee32\"\u003e\u003ccode\u003e6bceb84\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/5429fed84e84e32672c25a953eca3429b841ce90\"\u003e\u003ccode\u003e5429fed\u003c/code\u003e\u003c/a\u003e ✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more conven...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/628663f4f899c465da423bce681c7adf9a218948\"\u003e\u003ccode\u003e628663f\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.140.13 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16096\"\u003e#16096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/0b54fd00273019034dd30b120ac842e65d80690e\"\u003e\u003ccode\u003e0b54fd0\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/fastapi/compare/0.139.0...0.141.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.5.1 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.5.1...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pgvector` from 0.4.2 to 0.5.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pgvector/pgvector-python/blob/master/CHANGELOG.md\"\u003epgvector's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.5.0 (2026-07-06)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded experimental support for type hints\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003evector\u003c/code\u003e and \u003ccode\u003ehalfvec\u003c/code\u003e types to return list for Django, SQLAlchemy, SQLModel, and Peewee\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003evector\u003c/code\u003e type to return \u003ccode\u003eVector\u003c/code\u003e object for Psycopg 3, Psycopg 2, asyncpg, and pg8000\u003c/li\u003e\n\u003cli\u003eRemoved \u003ccode\u003eutils\u003c/code\u003e package (use top-level \u003ccode\u003epgvector\u003c/code\u003e package instead)\u003c/li\u003e\n\u003cli\u003eRemoved re-exported classes (use top-level \u003ccode\u003epgvector\u003c/code\u003e package instead)\u003c/li\u003e\n\u003cli\u003eRemoved dependency on NumPy\u003c/li\u003e\n\u003cli\u003eDropped support for Python \u0026lt; 3.10\u003c/li\u003e\n\u003cli\u003eDropped support for SQLAlchemy \u0026lt; 2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/60739dfd6cb9d674f32afa4184d43e6aff9dfbcf\"\u003e\u003ccode\u003e60739df\u003c/code\u003e\u003c/a\u003e Version bump to 0.5.0 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/a810f27ca93c185e81e98b05d87622d736e89568\"\u003e\u003ccode\u003ea810f27\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/45b054c53fb174ca12ecb08157f7875bd4795356\"\u003e\u003ccode\u003e45b054c\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/efa144252a96be79c695923d2717b0555bea8fcd\"\u003e\u003ccode\u003eefa1442\u003c/code\u003e\u003c/a\u003e Updated examples [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/780cc73f723fd2300cd16ae7362c9ab00453ecfc\"\u003e\u003ccode\u003e780cc73\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/9f0d6b97640486eacf858143430b40d11634a845\"\u003e\u003ccode\u003e9f0d6b9\u003c/code\u003e\u003c/a\u003e Updated examples [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/f6e113e1ad10968473e630d001bc473b6c9a62ed\"\u003e\u003ccode\u003ef6e113e\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/dc6877060099dcd2485e23c9facb04d3e6df3faf\"\u003e\u003ccode\u003edc68770\u003c/code\u003e\u003c/a\u003e Updated readme [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/0c18e0aa5de9d9a4ff1bd1ad58c8839bb5ce814c\"\u003e\u003ccode\u003e0c18e0a\u003c/code\u003e\u003c/a\u003e Addressed todo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/28191fc8b9a5702cd07b2854dbf89b1e0d263100\"\u003e\u003ccode\u003e28191fc\u003c/code\u003e\u003c/a\u003e Removed todo [skip ci]\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pgvector/pgvector-python/compare/v0.4.2...v0.5.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `rapidfuzz` from 3.14.5 to 3.14.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/releases\"\u003erapidfuzz's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 3.14.6\u003c/h2\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix some divergences in the pure Python fallback\u003c/li\u003e\n\u003cli\u003efix compatibility with new Cython versions\u003c/li\u003e\n\u003cli\u003efixed potential out of bound access inside Editops.remove_subsequence\u003c/li\u003e\n\u003cli\u003efixed handling python fallback implementation of Editops.remove_subsequence\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRemoved\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edropped support for Python 3.10\u003c/li\u003e\n\u003cli\u003edropped wheels for experimental Python 3.13 free threaded\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/blob/main/CHANGELOG.rst\"\u003erapidfuzz's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003cp\u003e[3.14.6] - 2026-08-30\n^^^^^^^^^^^^^^^^^^^^^\nFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* fix some divergences in the pure Python fallback\n* fix compatibility with new Cython versions\n* fixed potential out of bound access inside Editops.remove_subsequence\n* fixed handling python fallback implementation of Editops.remove_subsequence\n\u003cp\u003eRemoved\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edropped support for Python 3.10\u003c/li\u003e\n\u003cli\u003edropped wheels for experimental Python 3.13 free threaded\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e[3.14.5] - 2026-04-07\n^^^^^^^^^^^^^^^^^^^^^\nFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* fix release ci attempting to upload a pyodide wheel\n\u003cp\u003e[3.14.4] - 2026-04-06\n^^^^^^^^^^^^^^^^^^^^^\nAdded\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eadd risc64 wheels\u003c/li\u003e\n\u003cli\u003eadd support for taskflow 4.0.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eChanged\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* upgrade to ``Cython==3.2.4``.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* fix type hints for extractOne when no score_cutoff is provided\n\n[3.14.3] - 2025-11-01\n^^^^^^^^^^^^^^^^^^^^^\nFixed\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eadd missing pypy and freethreaded linux wheels\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eRemoved\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edrop s390x and ppc64le wheels since they are virtually unused and require extremely long to build under emulation\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e[3.14.2] - 2025-10-30\n^^^^^^^^^^^^^^^^^^^^^\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/d1b4a183f9ee445134989f4ebbf1e4acfacd4ed7\"\u003e\u003ccode\u003ed1b4a18\u003c/code\u003e\u003c/a\u003e fix cython call\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/f7be71b006ebc7bfeb836a18b7e33fc7412f699b\"\u003e\u003ccode\u003ef7be71b\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/3199c87e7309ed6a2779e658dbddcfc0ba654963\"\u003e\u003ccode\u003e3199c87\u003c/code\u003e\u003c/a\u003e fix version tag\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/7b57e516d59948d4d7e349e88ffafd99668aa2d2\"\u003e\u003ccode\u003e7b57e51\u003c/code\u003e\u003c/a\u003e update date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/15e68d7b195bca227e9992efe928a01d40bd3553\"\u003e\u003ccode\u003e15e68d7\u003c/code\u003e\u003c/a\u003e update rapidfuzz-cpp\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/b637f9f689ef12749d97be87056704cfbc4c2d7c\"\u003e\u003ccode\u003eb637f9f\u003c/code\u003e\u003c/a\u003e don't hand out references to internal elements\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/868a451a6eb8b111fd97bbd3b3413fcf14ee88e4\"\u003e\u003ccode\u003e868a451\u003c/code\u003e\u003c/a\u003e fix Editops.remove_subsequence\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/83b8b8468f3a0bef8fbee0a118c6ad85df325ac8\"\u003e\u003ccode\u003e83b8b84\u003c/code\u003e\u003c/a\u003e fix compatibility with new Cython versions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/24f2ac526bf1ec91db90e7ff02e52816e6bcb603\"\u003e\u003ccode\u003e24f2ac5\u003c/code\u003e\u003c/a\u003e Bump pypa/cibuildwheel from 4.1.1 to 4.2.0 in the github-actions group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/03a5137851aab675b430389235d73bb18873dafe\"\u003e\u003ccode\u003e03a5137\u003c/code\u003e\u003c/a\u003e Bump pypa/gh-action-pypi-publish in the github-actions group\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/compare/v3.14.5...v3.14.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `av` from 18.0.0 to 18.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/PyAV-Org/PyAV/releases\"\u003eav's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev18.1.0\u003c/h2\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInfer the specific stream and codec context types for all FFmpeg encoder names in type-checked code by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.supported_options\u003c/code\u003e to discover generic and codec-specific options by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2032\"\u003e#2032\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ePacket.rescale_ts()\u003c/code\u003e to rescale packet PTS, DTS, and duration to a new \u003ccode\u003eAVRational\u003c/code\u003e time base by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSupport reusing the thread's current CUDA context via a \u003ccode\u003ecurrent_ctx\u003c/code\u003e flag on \u003ccode\u003eCudaContext\u003c/code\u003e and \u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e, for interop with libraries like PyTorch that initialize CUDA first by \u003ca href=\"https://github.com/Yozer\"\u003e\u003ccode\u003e@​Yozer\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2339\"\u003e#2339\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e no longer requires restating \u003ccode\u003eprimary_ctx\u003c/code\u003e/\u003ccode\u003ecurrent_ctx\u003c/code\u003e when passing an explicit \u003ccode\u003ecuda_context\u003c/code\u003e; the flags are only validated when explicitly given by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSupport passing an explicit CUDA stream to FFmpeg CUDA operations, including NVENC input and output, via a \u003ccode\u003ecuda_stream\u003c/code\u003e parameter on \u003ccode\u003eCudaContext\u003c/code\u003e; currently limited to logical CUDA device 0 by \u003ca href=\"https://github.com/Yozer\"\u003e\u003ccode\u003e@​Yozer\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2360\"\u003e#2360\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eav.AVRational\u003c/code\u003e, an exact rational number stored as two int32s that mirrors FFmpeg's \u003ccode\u003eAVRational\u003c/code\u003e. \u003ccode\u003eCodec.frame_rates\u003c/code\u003e now holds these rather than \u003ccode\u003efractions.Fraction\u003c/code\u003e, and every setter that accepts a \u003ccode\u003eFraction\u003c/code\u003e also accepts an \u003ccode\u003eAVRational\u003c/code\u003e. Unset rational attributes are falsy, so test them with \u003ccode\u003eif not stream.time_base:\u003c/code\u003e rather than \u003ccode\u003eis None\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eFrame.metadata\u003c/code\u003e, the metadata FFmpeg attaches to a frame, by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.level\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eVideoCodecContext.field_order\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.save\u003c/code\u003e now forwards keyword arguments to the encoder, letting callers trade file size for speed (e.g. \u003ccode\u003epred=\u0026quot;none\u0026quot;\u003c/code\u003e or \u003ccode\u003ecompression_level=1\u003c/code\u003e for PNG, \u003ccode\u003eqscale=2\u003c/code\u003e for JPG) by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eInputContainer.start_time_realtime\u003c/code\u003e, the stream's start time in microseconds since the Unix epoch, which RTSP derives from RTCP sender reports, by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2365\"\u003e#2365\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eVideoFrame.save\u003c/code\u003e raising \u003ccode\u003eAttributeError\u003c/code\u003e when given a \u003ccode\u003ePath\u003c/code\u003e rather than a \u003ccode\u003estr\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix a frame rate assigned to a \u003ccode\u003eVideoStream\u003c/code\u003e after \u003ccode\u003eadd_stream\u003c/code\u003e being dropped from the output; the codec context's frame rate is now copied to the stream before the header is written by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2301\"\u003e#2301\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePrevent crashes and corrupted output when structural codec properties are changed after an output stream has been opened by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e, reported by \u003ca href=\"https://github.com/oakaigh\"\u003e\u003ccode\u003e@​oakaigh\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2232\"\u003e#2232\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix a crash when using a stream that has no \u003ccode\u003eCodecContext\u003c/code\u003e (a demuxed stream with no available decoder, such as one from a truncated file, or a stream created by \u003ccode\u003eadd_mux_stream\u003c/code\u003e); decoding now raises \u003ccode\u003eDecoderNotFoundError\u003c/code\u003e, encoding now raises \u003ccode\u003eEncoderNotFoundError\u003c/code\u003e, and \u003ccode\u003eBitStreamFilterContext\u003c/code\u003e accepts such a stream as \u003ccode\u003eout_stream\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e, reported by \u003ca href=\"https://github.com/justinrmiller\"\u003e\u003ccode\u003e@​justinrmiller\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2344\"\u003e#2344\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport building from source against FFmpeg 9.0 by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e. The binary wheels still ship FFmpeg 8.1.2.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Yozer\"\u003e\u003ccode\u003e@​Yozer\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/pull/2339\"\u003ePyAV-Org/PyAV#2339\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/PyAV-Org/PyAV/compare/v18.0.0...v18.1.0\"\u003ehttps://github.com/PyAV-Org/PyAV/compare/v18.0.0...v18.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/PyAV-Org/PyAV/blob/v18.1.0/CHANGELOG.rst\"\u003eav's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev18.1.0\u003c/h2\u003e\n\u003cp\u003eFeatures:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInfer the specific stream and codec context types for all FFmpeg encoder names in type-checked code by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.supported_options\u003c/code\u003e to discover generic and codec-specific options by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e (:issue:\u003ccode\u003e2032\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ePacket.rescale_ts()\u003c/code\u003e to rescale packet PTS, DTS, and duration to a new \u003ccode\u003eAVRational\u003c/code\u003e time base by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSupport reusing the thread's current CUDA context via a \u003ccode\u003ecurrent_ctx\u003c/code\u003e flag on \u003ccode\u003eCudaContext\u003c/code\u003e and \u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e, for interop with libraries like PyTorch that initialize CUDA first by :gh-user:\u003ccode\u003eYozer\u003c/code\u003e (:pr:\u003ccode\u003e2339\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e no longer requires restating \u003ccode\u003eprimary_ctx\u003c/code\u003e/\u003ccode\u003ecurrent_ctx\u003c/code\u003e when passing an explicit \u003ccode\u003ecuda_context\u003c/code\u003e; the flags are only validated when explicitly given by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSupport passing an explicit CUDA stream to FFmpeg CUDA operations, including NVENC input and output, via a \u003ccode\u003ecuda_stream\u003c/code\u003e parameter on \u003ccode\u003eCudaContext\u003c/code\u003e; currently limited to logical CUDA device 0 by :gh-user:\u003ccode\u003eYozer\u003c/code\u003e (:pr:\u003ccode\u003e2360\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eav.AVRational\u003c/code\u003e, an exact rational number stored as two int32s that mirrors FFmpeg's \u003ccode\u003eAVRational\u003c/code\u003e. \u003ccode\u003eCodec.frame_rates\u003c/code\u003e now holds these rather than \u003ccode\u003efractions.Fraction\u003c/code\u003e, and every setter that accepts a \u003ccode\u003eFraction\u003c/code\u003e also accepts an \u003ccode\u003eAVRational\u003c/code\u003e. Unset rational attributes are falsy, so test them with \u003ccode\u003eif not stream.time_base:\u003c/code\u003e rather than \u003ccode\u003eis None\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eFrame.metadata\u003c/code\u003e, the metadata FFmpeg attaches to a frame, by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.level\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eVideoCodecContext.field_order\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.save\u003c/code\u003e now forwards keyword arguments to the encoder, letting callers trade file size for speed (e.g. \u003ccode\u003epred=\u0026quot;none\u0026quot;\u003c/code\u003e or \u003ccode\u003ecompression_level=1\u003c/code\u003e for PNG, \u003ccode\u003eqscale=2\u003c/code\u003e for JPG) by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eInputContainer.start_time_realtime\u003c/code\u003e, the stream's start time in microseconds since the Unix epoch, which RTSP derives from RTCP sender reports, by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e (:issue:\u003ccode\u003e2365\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eVideoFrame.save\u003c/code\u003e raising \u003ccode\u003eAttributeError\u003c/code\u003e when given a \u003ccode\u003ePath\u003c/code\u003e rather than a \u003ccode\u003estr\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFix a frame rate assigned to a \u003ccode\u003eVideoStream\u003c/code\u003e after \u003ccode\u003eadd_stream\u003c/code\u003e being dropped from the output; the codec context's frame rate is now copied to the stream before the header is written by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e (:issue:\u003ccode\u003e2301\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eMisc.:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source against FFmpeg 9.0 by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e. The binary wheels still ship FFmpeg 8.1.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ePrevent crashes and corrupted output when structural codec properties are changed after an output stream has been opened by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e, reported by :gh-user:\u003ccode\u003eoakaigh\u003c/code\u003e (:issue:\u003ccode\u003e2232\u003c/code\u003e).\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a crash when using a stream that has no \u003ccode\u003eCodecContext\u003c/code\u003e (a demuxed stream with no available decoder, such as one from a truncated file, or a stream created by \u003ccode\u003eadd_mux_stream\u003c/code\u003e); decoding now raises \u003ccode\u003eDecoderNotFoundError\u003c/code\u003e, encoding now raises \u003ccode\u003eEncoderNotFoundError\u003c/code\u003e, and \u003ccode\u003eBitStreamFilterContext\u003c/code\u003e accepts such a stream as \u003ccode\u003eout_stream\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e, reported by :gh-user:\u003ccode\u003ejustinrmiller\u003c/code\u003e (:issue:\u003ccode\u003e2344\u003c/code\u003e).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/7e3d950a8b72062502c1a60d672f8ca565313af5\"\u003e\u003ccode\u003e7e3d950\u003c/code\u003e\u003c/a\u003e Release 18.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/842955f0cb6df927a42172ff14de186aec6e9a00\"\u003e\u003ccode\u003e842955f\u003c/code\u003e\u003c/a\u003e Changelog entries missed since 18.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/fdb4ce4e18181332b0704b78a5e655e8acc6e7e1\"\u003e\u003ccode\u003efdb4ce4\u003c/code\u003e\u003c/a\u003e Add InputContainer.start_time_realtime, closes \u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2365\"\u003e#2365\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/b9ef85f33cca825f7f47bfb04217f92f27c60b8e\"\u003e\u003ccode\u003eb9ef85f\u003c/code\u003e\u003c/a\u003e Forward encoder options from \u003ccode\u003eVideoFrame.save()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/f711ab6866f27608c8b6a1e60e4512e98a52cc75\"\u003e\u003ccode\u003ef711ab6\u003c/code\u003e\u003c/a\u003e Disable avx-512 in build-deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/883642e7e68497de5c31487deaf48a11b364135e\"\u003e\u003ccode\u003e883642e\u003c/code\u003e\u003c/a\u003e Test with ffmpeg 9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/b35726c2b80f54b572d8c95f9bbae71ffa7ec9c6\"\u003e\u003ccode\u003eb35726c\u003c/code\u003e\u003c/a\u003e FFmpeg 9.0 reorders AVCodecID\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/f6f0a5e3d975aab851e12ca881bdadfdd8f9ec74\"\u003e\u003ccode\u003ef6f0a5e\u003c/code\u003e\u003c/a\u003e Avoid probing primary context flags for no reason\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/387fca5ec3eadbdd9ba286cac2918b74a5385b42\"\u003e\u003ccode\u003e387fca5\u003c/code\u003e\u003c/a\u003e Support explicit CUDA streams\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/32e9f7de15c3ecdddd78cc17b5ed4cdafdd15149\"\u003e\u003ccode\u003e32e9f7d\u003c/code\u003e\u003c/a\u003e Refresh installation documentation\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/PyAV-Org/PyAV/compare/v18.0.0...v18.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.13.0 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.14.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#security\"\u003eSecurity\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003ch2\u003etorch.nn\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003etorch.nn.LinearCrossEntropyOptions\u003c/code\u003e no longer accepts \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e; use \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e instead (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188283\"\u003e#188283\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003e\u0026quot;balanced\u0026quot;\u003c/code\u003e policy was removed because \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e provides the same weight-gradient accumulation precision with lower memory use on CUDA, already uses the equivalent scratch layout for mixed-precision inputs on other devices, and was never selected by \u003ccode\u003e\u0026quot;auto\u0026quot;\u003c/code\u003e. Constructing the options with \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e now raises \u003ccode\u003eValueError: invalid acc_policy: 'balanced'; expected one of 'auto', 'accurate', 'compact'\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBefore:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;balanced\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n    input, linear_weight, target, options=options\r\n)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eAfter:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;compact\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/2b3ec34829036a65cd9d1398ea72a0167dc37470\"\u003e\u003ccode\u003e2b3ec34\u003c/code\u003e\u003c/a\u003e [release/2.14] Import SDPAParams in test_transformers to fix lint (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194970\"\u003e#194970\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/08187d9e0fba026dc8217405802ab5381dc88d90\"\u003e\u003ccode\u003e08187d9\u003c/code\u003e\u003c/a\u003e [cuDNN] Add guards for cuDNN SDPA decode (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194963\"\u003e#194963\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/8ceea97051dec8f6bee23d24bd7704dcb6843ade\"\u003e\u003ccode\u003e8ceea97\u003c/code\u003e\u003c/a\u003e Pin cython \u0026lt; 3.3.0 for the Windows Triton wheel build (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194931\"\u003e#194931\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/99ecebc63014f3454331b5a0914871daa063b512\"\u003e\u003ccode\u003e99ecebc\u003c/code\u003e\u003c/a\u003e [Cherry-pick][release/2.14] [inductor] Fix loop-local load CSE lifetime (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194\"\u003e#194\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/ec283a75077fa3ee24a9cda2c58d2b24d95ca98c\"\u003e\u003ccode\u003eec283a7\u003c/code\u003e\u003c/a\u003e Bump the Python 3.15 numpy pin to 2.5.2 (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194821\"\u003e#194821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/65890f364dd059ca97b9a37ada974eba8d8be772\"\u003e\u003ccode\u003e65890f3\u003c/code\u003e\u003c/a\u003e Fix docker-release validate job to use the channel matching the pushed image ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/168238882db0ad985f8904489604ff4955449fd2\"\u003e\u003ccode\u003e1682388\u003c/code\u003e\u003c/a\u003e Fix macOS py3.15 wheel builds: pin Cython \u0026lt; 3.3.0 and bump the cp315 numpy pi...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/972441861b1aee44141b60c98c7875e7e4fe23ca\"\u003e\u003ccode\u003e9724418\u003c/code\u003e\u003c/a\u003e Fix Windows py3.15 builds: constrain Cython \u0026lt; 3.3.0 and bump the cp315 numpy ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/f1b755434c258b61307de00f680bb2dc9c50d592\"\u003e\u003ccode\u003ef1b7554\u003c/code\u003e\u003c/a\u003e [MPS] Fix pin_memory() recycling buffers still in use by the GPU (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194662\"\u003e#194662\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/9f205f7b38c08544132b001948ce9109c577c6ed\"\u003e\u003ccode\u003e9f205f7\u003c/code\u003e\u003c/a\u003e [MPS] fail loudly on large reductions (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194661\"\u003e#194661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pytorch/pytorch/compare/v2.13.0...v2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.13.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.13.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/erick-ti/doppel/pull/82","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/erick-ti%2Fdoppel/issues/82","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/82/packages"},{"uuid":"5468540029","node_id":"PR_kwDOUcpWsM8AAAABDsIQAg","number":4,"state":"open","title":"Update transformers requirement from ==4.* to ==5.*","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T23:47:57.000Z","updated_at":"2026-09-15T23:47:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Update","packages":[{"name":"transformers","old_version":"==4.*","new_version":"==5.*","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Updates the requirements on [transformers](https://github.com/huggingface/transformers) to permit the latest version.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.0.0-rc-1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Ram004/ai-governance-platform/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ram004%2Fai-governance-platform/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"},{"uuid":"5468049854","node_id":"PR_kwDOQs9zJM8AAAABDrvNuw","number":6543,"state":"open","title":"chore(deps): bump the pip group across 1 directory with 18 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":5,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T22:33:23.000Z","updated_at":"2026-09-16T01:04:22.344Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"pip","update_count":18,"packages":[{"name":"python-multipart","old_version":"0.0.22","new_version":"0.0.31","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"pillow","old_version":"12.1.1","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"python-dotenv","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"pydantic-settings","old_version":"2.13.0","new_version":"2.14.2","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"transformers","old_version":"5.2.0","new_version":"5.10.1","repository_url":"https://github.com/huggingface/transformers"},{"name":"gdown","old_version":"5.2.1","new_version":"5.2.2","repository_url":"https://github.com/wkentaro/gdown"},{"name":"accelerate","old_version":"1.12.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"urllib3","old_version":"2.6.3","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"pytest","old_version":"9.0.2","new_version":"9.0.3","repository_url":"https://github.com/pytest-dev/pytest"},{"name":"idna","old_version":"3.11","new_version":"3.15","repository_url":"https://github.com/kjd/idna"},{"name":"mako","old_version":"1.3.10","new_version":"1.3.12","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"pygments","old_version":"2.19.2","new_version":"2.20.0","repository_url":"https://github.com/pygments/pygments"},{"name":"requests","old_version":"2.32.5","new_version":"2.33.0","repository_url":"https://github.com/psf/requests"},{"name":"setuptools","old_version":"82.0.0","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"soupsieve","old_version":"2.8.3","new_version":"2.8.4","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"starlette","old_version":"0.52.1","new_version":"1.3.1","repository_url":"https://github.com/Kludex/starlette"},{"name":"torch","old_version":"2.10.0","new_version":"2.13.0","repository_url":"https://github.com/pytorch/pytorch"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 18 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.22` | `0.0.31` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.1.1` | `12.3.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.1` | `1.2.2` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.13.0` | `2.14.2` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.2.0` | `5.10.1` |\n| [gdown](https://github.com/wkentaro/gdown) | `5.2.1` | `5.2.2` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.12.0` | `1.15.0` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n| [pytest](https://github.com/pytest-dev/pytest) | `9.0.2` | `9.0.3` |\n| [idna](https://github.com/kjd/idna) | `3.11` | `3.15` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.3.12` |\n| [pygments](https://github.com/pygments/pygments) | `2.19.2` | `2.20.0` |\n| [requests](https://github.com/psf/requests) | `2.32.5` | `2.33.0` |\n| [setuptools](https://github.com/pypa/setuptools) | `82.0.0` | `83.0.0` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.3` | `2.8.4` |\n| [starlette](https://github.com/Kludex/starlette) | `0.52.1` | `1.3.1` |\n| [torch](https://github.com/pytorch/pytorch) | `2.10.0` | `2.13.0` |\n\n\nUpdates `python-multipart` from 0.0.22 to 0.0.31\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/releases\"\u003epython-multipart's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.0.31\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003eKludex/python-multipart#295\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003eKludex/python-multipart#296\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate Content-Length is non-negative in parse_form by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003eKludex/python-multipart#297\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.30\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTreat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003eKludex/python-multipart#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003eKludex/python-multipart#291\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.29\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/manunio\"\u003e\u003ccode\u003e@​manunio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003eKludex/python-multipart#270\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.28\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003eKludex/python-multipart#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003eKludex/python-multipart#282\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.27\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePass parse offsets via constructors by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003eKludex/python-multipart#268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd multipart header limits by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003eKludex/python-multipart#267\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.26\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before first multipart boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003eKludex/python-multipart#262\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003eKludex/python-multipart#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.25\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply Apache-2.0 properly by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003eKludex/python-multipart#247\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003eKludex/python-multipart#252\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md\"\u003epython-multipart's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.31 (2026-06-04)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003e#295\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003e#296\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eValidate \u003ccode\u003eContent-Length\u003c/code\u003e is non-negative in \u003ccode\u003eparse_form\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003e#297\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.30 (2026-05-31)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eParse \u003ccode\u003eapplication/x-www-form-urlencoded\u003c/code\u003e bodies per the WHATWG URL standard, treating only \u003ccode\u003e\u0026amp;\u003c/code\u003e as a field separator \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003e#290\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231/5987 extended parameters (\u003ccode\u003ename*\u003c/code\u003e, \u003ccode\u003efilename*\u003c/code\u003e) in \u003ccode\u003eparse_options_header\u003c/code\u003e, keeping the plain parameter authoritative per \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc7578#section-4.2\"\u003eRFC 7578 §4.2\u003c/a\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003e#291\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.29 (2026-05-17)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003e#270\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.28 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003e#281\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003e#282\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.27 (2026-04-27)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd multipart header limits \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003e#267\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePass parse offsets via constructors \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003e#268\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.26 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before the first multipart boundary more efficiently \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003e#262\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing multipart boundary \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003e#259\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.25 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd MIME content type info to \u003ccode\u003eFile\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/143\"\u003e#143\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle CTE values case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/258\"\u003e#258\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRemove custom \u003ccode\u003eFormParser\u003c/code\u003e classes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/257\"\u003e#257\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eUPLOAD_DELETE_TMP\u003c/code\u003e to \u003ccode\u003eFormParser\u003c/code\u003e config \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/254\"\u003e#254\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEmit \u003ccode\u003efield_end\u003c/code\u003e for trailing bare field names on finalize \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/230\"\u003e#230\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003e#252\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eApply Apache-2.0 properly \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003e#247\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.24 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate \u003ccode\u003echunk_size\u003c/code\u003e in \u003ccode\u003eparse_form()\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/244\"\u003e#244\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.23 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove unused \u003ccode\u003etrust_x_headers\u003c/code\u003e parameter and \u003ccode\u003eX-File-Name\u003c/code\u003e fallback \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/196\"\u003e#196\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReturn processed length from \u003ccode\u003eQuerystringParser._internal_write\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/229\"\u003e#229\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCleanup metadata dunders from \u003ccode\u003e__init__.py\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/227\"\u003e#227\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/4cffc68a165f7a6f6b7756ce006fabf07a05b7a4\"\u003e\u003ccode\u003e4cffc68\u003c/code\u003e\u003c/a\u003e Version 0.0.31 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf\"\u003e\u003ccode\u003ec814948\u003c/code\u003e\u003c/a\u003e Reject negative \u003ccode\u003eContent-Length\u003c/code\u003e in \u003ccode\u003eparse_form\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6b837d47bc68826ed5cbbcb50c6c6a6093444494\"\u003e\u003ccode\u003e6b837d4\u003c/code\u003e\u003c/a\u003e Bound header field name size before validating (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/e0c4f9df2e737d1663fbbdd6563f80613a2089f9\"\u003e\u003ccode\u003ee0c4f9d\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/294\"\u003e#294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/b8a01bb683e8e8675fdb5d831b206a478c8215aa\"\u003e\u003ccode\u003eb8a01bb\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/293\"\u003e#293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6732164f30c58e28589a1e22213d2f6b8c6bad9f\"\u003e\u003ccode\u003e6732164\u003c/code\u003e\u003c/a\u003e Speed up multipart header parsing and callback dispatch (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/295\"\u003e#295\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/9d3ead568a259f222cff6425262ff63e88d930d4\"\u003e\u003ccode\u003e9d3ead5\u003c/code\u003e\u003c/a\u003e Version 0.0.30 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/292\"\u003e#292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/3506c15ce99cb62faf2d5ceb3c4c1e5800cb843d\"\u003e\u003ccode\u003e3506c15\u003c/code\u003e\u003c/a\u003e Ignore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/291\"\u003e#291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8\"\u003e\u003ccode\u003ed69df35\u003c/code\u003e\u003c/a\u003e Treat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/290\"\u003e#290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/1e6ff9740b09fb439755f30e2b0e2ada1d297325\"\u003e\u003ccode\u003e1e6ff97\u003c/code\u003e\u003c/a\u003e Bump idna from 3.11 to 3.15 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.31\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 12.1.1 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/12.1.1...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (#)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/607\"\u003etheskumar/python-dotenv#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eSupport for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e#790c5\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by \u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip 000 permission tests for root user by \u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/593\"\u003etheskumar/python-dotenv#593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Windows testing to CI by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/604\"\u003etheskumar/python-dotenv#604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove workflow efficiency with best practices by \u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/609\"\u003etheskumar/python-dotenv#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the use of \u003ccode\u003esh\u003c/code\u003e in tests by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/612\"\u003etheskumar/python-dotenv#612\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cpackham-atlnz\"\u003e\u003ccode\u003e@​cpackham-atlnz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/597\"\u003etheskumar/python-dotenv#597\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\"\u003ehttps://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.2] - 2026-03-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/607\"\u003e#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eDropped Support for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in [790c5c0]\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by [\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/590\"\u003e#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/36004e0e34be7665ff2b11a8a4005144f76f176d\"\u003e\u003ccode\u003e36004e0\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.1 → 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/eb202520e5933c9daf42501e1e42fdb0144002c8\"\u003e\u003ccode\u003eeb20252\u003c/code\u003e\u003c/a\u003e docs: update changelog for v1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e\u003ccode\u003e790c5c0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/43340da220fb4ca4f95357bbe21a3c7f8f1278b1\"\u003e\u003ccode\u003e43340da\u003c/code\u003e\u003c/a\u003e Remove the use of \u003ccode\u003esh\u003c/code\u003e in tests (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/612\"\u003e#612\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/09d7cee32459e7abdcb5c9d8122a552589c06a9c\"\u003e\u003ccode\u003e09d7cee\u003c/code\u003e\u003c/a\u003e docs: clarify override behavior and document FIFO support (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/610\"\u003e#610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/c8de2887c00198c22842c5ae5e92d1747467363c\"\u003e\u003ccode\u003ec8de288\u003c/code\u003e\u003c/a\u003e ci: improve workflow efficiency with best practices (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/609\"\u003e#609\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/7bd9e3dbfedc0983ad7d56d5570013035242bdf4\"\u003e\u003ccode\u003e7bd9e3d\u003c/code\u003e\u003c/a\u003e Add Windows testing to CI (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/604\"\u003e#604\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/1baaf04f336072e0ee324d5df9563ec767f14f81\"\u003e\u003ccode\u003e1baaf04\u003c/code\u003e\u003c/a\u003e Drop Python 3.9 support and update to PyPy 3.11 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/608\"\u003e#608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/4a22cf8993804aeede0c20b75bb1a29d3a99e9dc\"\u003e\u003ccode\u003e4a22cf8\u003c/code\u003e\u003c/a\u003e ci: enable testing on Python 3.14t (free-threaded) (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/e2e8e776b42e382ae38b44d3982dd649e7507dd4\"\u003e\u003ccode\u003ee2e8e77\u003c/code\u003e\u003c/a\u003e Fix license specifier (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic-settings` from 2.13.0 to 2.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic-settings/releases\"\u003epydantic-settings's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.14.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eThis is a security patch release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePrevent \u003ccode\u003eNestedSecretsSettingsSource\u003c/code\u003e from following symlinks outside \u003ccode\u003esecrets_dir\u003c/code\u003e by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/889\"\u003epydantic/pydantic-settings#889\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare release 2.14.2 by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/890\"\u003epydantic/pydantic-settings#890\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cp\u003eFixes \u003ca href=\"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j\"\u003eGHSA-4xgf-cpjx-pc3j\u003c/a\u003e: \u003ccode\u003eNestedSecretsSettingsSource\u003c/code\u003e with \u003ccode\u003esecrets_nested_subdir=True\u003c/code\u003e could follow a symbolic link inside \u003ccode\u003esecrets_dir\u003c/code\u003e pointing outside it, reading out-of-tree files into settings values and bypassing the \u003ccode\u003esecrets_dir_max_size\u003c/code\u003e cap. Affected versions: \u003ccode\u003e\u0026gt;= 2.12.0, \u0026lt; 2.14.2\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.14.2\"\u003ehttps://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.14.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.14.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/850\"\u003epydantic/pydantic-settings#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 5 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/854\"\u003epydantic/pydantic-settings#854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/853\"\u003epydantic/pydantic-settings#853\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/856\"\u003epydantic/pydantic-settings#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix field named \u003ccode\u003ecls\u003c/code\u003e conflicting with classmethod parameter by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/858\"\u003epydantic/pydantic-settings#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare release 2.14.1 by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/859\"\u003epydantic/pydantic-settings#859\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.14.0...v2.14.1\"\u003ehttps://github.com/pydantic/pydantic-settings/compare/v2.14.0...v2.14.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.14.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing env vars into Optional Strict types by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/792\"\u003epydantic/pydantic-settings#792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix RecursionError with mutually recursive models in CLI by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/794\"\u003epydantic/pydantic-settings#794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix env_file from model_config ignored in CliApp.run() (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/795\"\u003e#795\u003c/a\u003e) by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/796\"\u003epydantic/pydantic-settings#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate dependencies by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/798\"\u003epydantic/pydantic-settings#798\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Dependabot configuration by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/801\"\u003epydantic/pydantic-settings#801\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump samuelcolvin/check-python-version from 4.1 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/802\"\u003epydantic/pydantic-settings#802\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/upload-artifact from 4 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/803\"\u003epydantic/pydantic-settings#803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 4 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/804\"\u003epydantic/pydantic-settings#804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump astral-sh/setup-uv from 5 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/805\"\u003epydantic/pydantic-settings#805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/setup-python from 5 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/806\"\u003epydantic/pydantic-settings#806\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore chardet and group GitHub Actions in Dependabot by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/808\"\u003epydantic/pydantic-settings#808\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/download-artifact from 4 to 8 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/809\"\u003epydantic/pydantic-settings#809\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/810\"\u003epydantic/pydantic-settings#810\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport reading .env files from FIFOs (e.g. 1Password Environments) by \u003ca href=\"https://github.com/JacobHayes\"\u003e\u003ccode\u003e@​JacobHayes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/776\"\u003epydantic/pydantic-settings#776\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix AliasChoices ignored when changing provider priority by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/813\"\u003epydantic/pydantic-settings#813\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: resolve KeyError in run_subcommand for underscore field names by \u003ca href=\"https://github.com/bradykieffer\"\u003e\u003ccode\u003e@​bradykieffer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/799\"\u003epydantic/pydantic-settings#799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/814\"\u003epydantic/pydantic-settings#814\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eLiteral[numeric Enum]\u003c/code\u003e coercion for CLI and env vars by \u003ca href=\"https://github.com/m9810223\"\u003e\u003ccode\u003e@​m9810223\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/811\"\u003epydantic/pydantic-settings#811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix nested discriminated unions not discovered by env/CLI providers by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/816\"\u003epydantic/pydantic-settings#816\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/820\"\u003epydantic/pydantic-settings#820\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCLI ensure env nested max split internally. by \u003ca href=\"https://github.com/kschwab\"\u003e\u003ccode\u003e@​kschwab\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/821\"\u003epydantic/pydantic-settings#821\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/824\"\u003epydantic/pydantic-settings#824\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/d703bd717e5e07439fa89da2245eee6139413e9e\"\u003e\u003ccode\u003ed703bd7\u003c/code\u003e\u003c/a\u003e Prepare release 2.14.2 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/890\"\u003e#890\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/e95c30bec8cfaee88ee275138c064aea97a25bdf\"\u003e\u003ccode\u003ee95c30b\u003c/code\u003e\u003c/a\u003e Prepare release 2.14.1 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/859\"\u003e#859\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/0c8734581b6cf70a995afad603ac456631d00621\"\u003e\u003ccode\u003e0c87345\u003c/code\u003e\u003c/a\u003e Fix field named \u003ccode\u003ecls\u003c/code\u003e conflicting with classmethod parameter (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/7bd0072795a800065b42210b6dca90fc9b83daf7\"\u003e\u003ccode\u003e7bd0072\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 2 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/b03e573d017ed48e1c2774a5e0b715db9766c76b\"\u003e\u003ccode\u003eb03e573\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 3 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/853\"\u003e#853\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/eaa3b434938411ec8a3717ea646614561e713f51\"\u003e\u003ccode\u003eeaa3b43\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 5 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/854\"\u003e#854\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/9f95615c24c6813c1d7d203576581a79cb6d9e8e\"\u003e\u003ccode\u003e9f95615\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/850\"\u003e#850\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/8916beeecc6d0510e3d0532a0ed839937400ddc3\"\u003e\u003ccode\u003e8916bee\u003c/code\u003e\u003c/a\u003e Prepare release 2.14.0 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/848\"\u003e#848\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/39e551c0910c85505b608ff85a103b2c9f7396c5\"\u003e\u003ccode\u003e39e551c\u003c/code\u003e\u003c/a\u003e Fix CLI descriptions lost under \u003ccode\u003epython -OO\u003c/code\u003e by falling back to `json_schema_...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/9ed7f48ea2c90f436a03b01f721fe6656c869b14\"\u003e\u003ccode\u003e9ed7f48\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/847\"\u003e#847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.13.0...v2.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cryptography` from 46.0.5 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/46.0.5...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.2.0 to 5.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v5.10.1\u003c/h1\u003e\n\u003cp\u003ev5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!\u003c/p\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eGemma4 unified+ Gemma4 MTP\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eGemma 4 12B Unified is an \u003cstrong\u003eencoder-free\u003c/strong\u003e multimodal model with pretrained and instruction-tuned variants. Unlike \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gemma4\"\u003estandard Gemma 4\u003c/a\u003e, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.\u003c/p\u003e\n\u003cp\u003eKey differences from standard Gemma 4:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo Vision Tower\u003c/strong\u003e: Raw pixel patches are projected directly into LM space via a \u003ccode\u003eDense + LayerNorm\u003c/code\u003e pipeline with factorized 2D positional embeddings, replacing the vision encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNo Audio Tower\u003c/strong\u003e: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple \u003ccode\u003eRMSNorm → Linear\u003c/code\u003e pipeline, replacing the mel spectrogram + Conformer encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eShared Multimodal Pipeline\u003c/strong\u003e: Both vision and audio use the same \u003ccode\u003eGemma4UnifiedMultimodalEmbedder\u003c/code\u003e (RMSNorm → Linear) for the final projection to text hidden space.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou can find the original Gemma 4 12B Unified checkpoints under the \u003ca href=\"https://huggingface.co/collections/google/gemma-4\"\u003eGemma 4\u003c/a\u003e release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewho needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e) by \u003ca href=\"https://github.com/douglas-reid\"\u003e\u003ccode\u003e@​douglas-reid\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/sgerrard\"\u003e\u003ccode\u003e@​sgerrard\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/vasqu\"\u003e\u003ccode\u003e@​vasqu\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/molbap\"\u003e\u003ccode\u003e@​molbap\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSapiens2\u003c/h3\u003e\n\u003cp\u003eSapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2\"\u003eDocumentation\u003c/a\u003e | \u003ca href=\"https://huggingface.co/papers/2604.21681\"\u003ePaper\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e) by \u003ca href=\"https://github.com/guarin\"\u003e\u003ccode\u003e@​guarin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45919\"\u003e#45919\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDeepSeek-OCR-2\u003c/h3\u003e\n\u003cp\u003eDeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Deepseek-OCR-2 model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45075\"\u003e#45075\u003c/a\u003e) by \u003ca href=\"https://github.com/thisisiron\"\u003e\u003ccode\u003e@​thisisiron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45075\"\u003e#45075\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMellum\u003c/h3\u003e\n\u003cp\u003eMellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/mellum\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Add support for JetBrains' \u003ccode\u003eMellum\u003c/code\u003e v2 code generation model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46112\"\u003e#46112\u003c/a\u003e) by \u003ca href=\"https://github.com/shadeMe\"\u003e\u003ccode\u003e@​shadeMe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/46112\"\u003e#46112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBreaking changes\u003c/h2\u003e\n\u003cp\u003eThe Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 Fix float16 overflow in Gemma4 vision pooler (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46277\"\u003e#46277\u003c/a\u003e) by \u003ca href=\"https://github.com/Bluear7878\"\u003e\u003ccode\u003e@​Bluear7878\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAudio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 [ALM] Add base model without head (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45534\"\u003e#45534\u003c/a\u003e) by \u003ca href=\"https://github.com/eustlb\"\u003e\u003ccode\u003e@​eustlb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d\"\u003e\u003ccode\u003e90c3ae5\u003c/code\u003e\u003c/a\u003e Patch because we had to yank 5.10 because the release branch was not up to date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968\"\u003e\u003ccode\u003e0bd94b3\u003c/code\u003e\u003c/a\u003e v5.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897\"\u003e\u003ccode\u003e1423d22\u003c/code\u003e\u003c/a\u003e who needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98\"\u003e\u003ccode\u003e50eb20a\u003c/code\u003e\u003c/a\u003e Fix dsv4 dequant + tp/ep (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46378\"\u003e#46378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299\"\u003e\u003ccode\u003e74464e8\u003c/code\u003e\u003c/a\u003e Fix wrong changes produced by style/repo. check bot (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46371\"\u003e#46371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc\"\u003e\u003ccode\u003e1b8ec34\u003c/code\u003e\u003c/a\u003e Fix path traversal when saving Bark voice preset embeddings (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46237\"\u003e#46237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872\"\u003e\u003ccode\u003ee820678\u003c/code\u003e\u003c/a\u003e Add Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43\"\u003e\u003ccode\u003e595721c\u003c/code\u003e\u003c/a\u003e Pass library_name/version to Hub calls via a shared HfApi (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46318\"\u003e#46318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a\"\u003e\u003ccode\u003e0f0036c\u003c/code\u003e\u003c/a\u003e docs: update ACL Anthology URL in CITATION.cff (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46352\"\u003e#46352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353\"\u003e\u003ccode\u003efa6c830\u003c/code\u003e\u003c/a\u003e DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45634\"\u003e#45634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.2.0...v5.10.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `gdown` from 5.2.1 to 5.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/wkentaro/gdown/releases\"\u003egdown's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.2.2\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix path traversal vulnerability in extractall() that allowed zip/tar archives with ../ entries to write files outside the target directory (GHSA-76hw-p97h-883f)\u003c/li\u003e\n\u003cli\u003eReject symlinks, hardlinks, and special files in tar archives\u003c/li\u003e\n\u003cli\u003eUse Python 3.12+ filter=\u0026quot;data\u0026quot; for safe tar extraction when available\u003c/li\u003e\n\u003cli\u003eSanitize filenames from HTTP responses and URLs to prevent path traversal via /, , .., and null bytes\u003c/li\u003e\n\u003cli\u003eSanitize root folder name in download_folder() before building directory paths\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wkentaro/gdown/commit/af569fc6ed300b7974dee66dc51e9f01b57b4dff\"\u003e\u003ccode\u003eaf569fc\u003c/code\u003e\u003c/a\u003e fix: prevent path traversal in archive extraction and filename handling\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/wkentaro/gdown/compare/v5.2.1...v5.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.12.0 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (tru...\n\n_Description has been truncated_","html_url":"https://github.com/mikesvoboda/nemotron-v3-home-security-intelligence/pull/6543","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mikesvoboda%2Fnemotron-v3-home-security-intelligence/issues/6543","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6543/packages"}],"issue_packages":[{"old_version":"5.5.3","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-27T22:25:11.000Z","version_change":"5.5.3 → 5.17.0","issue":{"uuid":"5606816122","node_id":"PR_kwDOTdD-cs8AAAABFZcwdA","number":19,"state":"open","title":"Bump the minor-update group across 1 directory with 169 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-27T22:25:11.000Z","updated_at":"2026-09-27T22:25:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":169,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.5.3","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.128.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"mistral-common","old_version":"1.11.2","new_version":"1.12.0","repository_url":"https://github.com/mistralai/mistral-common"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.6.2.post1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"arrow","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/arrow-py/arrow"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.3","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.102","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.102","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.1.7","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.3","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.2","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.83.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastsafetensors","old_version":"0.2.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.9.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"harfile","old_version":"0.3.0","new_version":"0.5.0","repository_url":"https://github.com/schemathesis/harfile"},{"name":"hf-xet","old_version":"1.4.3","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.2","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.1","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"hypothesis-graphql","old_version":"0.11.1","new_version":"0.13.2","repository_url":"https://github.com/Stranger6667/hypothesis-graphql"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.5","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonpointer","old_version":"3.0.0","new_version":"3.1.1","repository_url":"https://github.com/stefankoegl/python-json-pointer"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.6","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.3","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.8","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.1","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.0.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.19.0.56","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.0","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.28.9","new_version":"2.32.3"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.8.0"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.18.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.4.0","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.12","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.15.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-subtests","old_version":"0.14.1","new_version":"0.15.0","repository_url":"https://github.com/pytest-dev/pytest-subtests"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"safetensors","old_version":"0.4.5","new_version":"0.8.0","repository_url":"https://github.com/huggingface/safetensors"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tomli","old_version":"2.2.1","new_version":"2.4.1","repository_url":"https://github.com/hukkin/tomli"},{"name":"triton","old_version":"3.6.0","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.15.2","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.6","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.9.1","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"zstandard","old_version":"0.23.0","new_version":"0.25.0","repository_url":"https://github.com/indygreg/python-zstandard"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.19.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"flashinfer-python","old_version":"0.6.8.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"helion","old_version":"1.0.0","new_version":"1.4.0","repository_url":"https://github.com/pytorch/helion"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 169 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.5.3` | `5.17.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.128.0` | `0.141.1` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [mistral-common](https://github.com/mistralai/mistral-common) | `1.11.2` | `1.12.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.6.2.post1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [arrow](https://github.com/arrow-py/arrow) | `1.3.0` | `1.4.0` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.3` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.102` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.102` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.1.7` | `8.5.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.3` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.2` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.83.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.2.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.1` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.9.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [harfile](https://github.com/schemathesis/harfile) | `0.3.0` | `0.5.0` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.4.3` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.2` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.1` |\n| [hypothesis-graphql](https://github.com/Stranger6667/hypothesis-graphql) | `0.11.1` | `0.13.2` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.5` | `0.2.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonpointer](https://github.com/stefankoegl/python-json-pointer) | `3.0.0` | `3.1.1` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.6` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.3` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.8` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.1` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.0.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.19.0.56` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.0` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.28.9` | `2.32.3` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.8.0` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.18.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.4.0` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.12` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.15.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-subtests](https://github.com/pytest-dev/pytest-subtests) | `0.14.1` | `0.15.0` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [safetensors](https://github.com/huggingface/safetensors) | `0.4.5` | `0.8.0` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [tomli](https://github.com/hukkin/tomli) | `2.2.1` | `2.4.1` |\n| [triton](https://github.com/triton-lang/triton) | `3.6.0` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.15.2` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.6` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.9.1` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [zstandard](https://github.com/indygreg/python-zstandard) | `0.23.0` | `0.25.0` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.19.0` | `0.29.0` |\n| [flashinfer-python](https://github.com/flashinfer-ai/flashinfer) | `0.6.8.post1` | `0.7.0` |\n| [helion](https://github.com/pytorch/helion) | `1.0.0` | `1.4.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.5.3 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.3...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2217\"\u003e#2217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/447890f84deab25794ccfdee2a877901b6893569\"\u003e\u003ccode\u003e447890f\u003c/code\u003e\u003c/a\u003e fix(python): pin the ruff rule set so a ruff release can't redden main (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2292\"\u003e#2292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/68b3ab7788b58408f37a3dc73eeabf2417d14c22\"\u003e\u003ccode\u003e68b3ab7\u003c/code\u003e\u003c/a\u003e chore(node): take node security alerts from 33 to 0 (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2287\"\u003e#2287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/74ef81f64e6d1cd4979c56d7d75f3ce21ba11992\"\u003e\u003ccode\u003e74ef81f\u003c/code\u003e\u003c/a\u003e ci: pin every action to one SHA, drop stale audit suppressions (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2291\"\u003e#2291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/b26727f1a92cdf727cd965fc1c467a7c77c63aae\"\u003e\u003ccode\u003eb26727f\u003c/code\u003e\u003c/a\u003e chore(node): drop 8 unused devDependencies (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2286\"\u003e#2286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c7cfd838fb79e76aaba6b0931898073a784fb2a\"\u003e\u003ccode\u003e7c7cfd8\u003c/code\u003e\u003c/a\u003e chore: remove stale examples (kills 50% of dependabot traffic) (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2285\"\u003e#2285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.22.2...v0.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fastapi` from 0.128.0 to 0.141.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/fastapi/releases\"\u003efastapi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.141.1\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix support for background tasks and headers from dependencies in \u003ccode\u003eapp.frontend()\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16105\"\u003e#16105\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16104\"\u003e#16104\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.141.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more convenient with \u003ccode\u003efastapi dev\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16102\"\u003e#16102\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.13\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003estatus_code\u003c/code\u003e being ignored for SSE and JSONL streaming endpoints. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15937\"\u003e#15937\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Fix \u003ccode\u003eformat_sse_event\u003c/code\u003e docstring rendering of \u003ccode\u003e\\n\\n\u003c/code\u003e terminator. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15613\"\u003e#15613\u003c/a\u003e by \u003ca href=\"https://github.com/AshNicolus\"\u003e\u003ccode\u003e@​AshNicolus\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e📝 Add API reference page for fastapi.sse. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15930\"\u003e#15930\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.12\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix line splitting in \u003ccode\u003eformat_sse_event\u003c/code\u003e to comply with SSE spec. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15515\"\u003e#15515\u003c/a\u003e by \u003ca href=\"https://github.com/Zawwarsami16\"\u003e\u003ccode\u003e@​Zawwarsami16\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.11\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eresponse_model_*\u003c/code\u003e params ignored for non-generator endpoints with \u003ccode\u003eIterable[..]\u003c/code\u003e return type. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15093\"\u003e#15093\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.10\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix handling sequences with nested Annotated types. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/14874\"\u003e#14874\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Accept any base test failure as regression. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16092\"\u003e#16092\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🐛 Preserve pytest exit code in regression check. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16091\"\u003e#16091\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e✅ Test PR regressions against base code. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16090\"\u003e#16090\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.9\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eexclude_defaults\u003c/code\u003e not propagated to dict keys and values in \u003ccode\u003ejsonable_encoder\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16043\"\u003e#16043\u003c/a\u003e by \u003ca href=\"https://github.com/MBGrao\"\u003e\u003ccode\u003e@​MBGrao\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/95f8322ee1dcda7ceace7b1c4f6c9915b36d748f\"\u003e\u003ccode\u003e95f8322\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.1 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16106\"\u003e#16106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/f137944c435cff4e4b30ea7d12855ea88ddb868c\"\u003e\u003ccode\u003ef137944\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/d62354434b2e508fe89024213b220ca8e67dea5e\"\u003e\u003ccode\u003ed623544\u003c/code\u003e\u003c/a\u003e 🐛 Fix support for background tasks and headers from dependencies in `app.fron...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/1d211b9c1009d577f39fa2b19b10d9a93a72a0ed\"\u003e\u003ccode\u003e1d211b9\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/8a1f8768411e62093e70ce142ea10863a485643c\"\u003e\u003ccode\u003e8a1f876\u003c/code\u003e\u003c/a\u003e 📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16104\"\u003e#16104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/c7e7b651d6946c07cc9f675f39c9501d08319e57\"\u003e\u003ccode\u003ec7e7b65\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.0 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16103\"\u003e#16103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/6bceb84053eb2405e9c000aad30ea13367b5ee32\"\u003e\u003ccode\u003e6bceb84\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/5429fed84e84e32672c25a953eca3429b841ce90\"\u003e\u003ccode\u003e5429fed\u003c/code\u003e\u003c/a\u003e ✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more conven...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/628663f4f899c465da423bce681c7adf9a218948\"\u003e\u003ccode\u003e628663f\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.140.13 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16096\"\u003e#16096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/0b54fd00273019034dd30b120ac842e65d80690e\"\u003e\u003ccode\u003e0b54fd0\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/fastapi/compare/0.128.0...0.141.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.13.3 to 3.14.3\nUpdates `pydantic` from 2.12.0 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirec...\n\n_Description has been truncated_","html_url":"https://github.com/Wenz20101/vllm-0.17.1w/pull/19","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Wenz20101%2Fvllm-0.17.1w/issues/19","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/19/packages"}},{"old_version":"5.14.1","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-25T01:12:52.000Z","version_change":"5.14.1 → 5.17.0","issue":{"uuid":"5576671790","node_id":"PR_kwDOTw8DQM8AAAABFCOc6w","number":18,"state":"open","title":"Bump the minor-update group across 1 directory with 194 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-25T01:12:52.000Z","updated_at":"2026-09-25T01:13:02.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":194,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.26.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"watchfiles","old_version":"1.2.0","new_version":"1.3.0","repository_url":"https://github.com/samuelcolvin/watchfiles"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.57.1","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.6","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.6","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.1","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.26.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"flashinfer-python","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"flashinfer-cubin","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.0","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"auto-round-lib","old_version":"0.14.2","new_version":"0.15.0","repository_url":"https://github.com/intel/auto-round"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"\u003e [!WARNING]\n\u003e Cooldown could not be applied because no publication date was available from the registry.\n\u003e\n\nBumps the minor-update group with 194 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.26.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.99` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.99` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.1` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.57.1` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.6` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.6` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.1` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.26.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [flashinfer-python](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [flashinfer-cubin](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.0` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.10` |\n| [auto-round-lib](https://github.com/intel/auto-round) | `0.14.2` | `0.15.0` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.14.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.14.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.26.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.26.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggi...\n\n_Description has been truncated_","html_url":"https://github.com/kuoihao/vllm-tle/pull/18","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kuoihao%2Fvllm-tle/issues/18","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/18/packages"}},{"old_version":"5.5.3","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-24T14:42:10.000Z","version_change":"5.5.3 → 5.17.0","issue":{"uuid":"5570060544","node_id":"PR_kwDOTg5ijc8AAAABE877pw","number":20,"state":"open","title":"Bump the minor-update group across 1 directory with 173 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T14:42:10.000Z","updated_at":"2026-09-24T14:42:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":173,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.5.3","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"safetensors","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/huggingface/safetensors"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.6.2.post1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.1.7","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.2","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.4.3","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"huggingface-hub","old_version":"1.10.2","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.5","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.4","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.0.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.19.0.56","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.0","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.28.9","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.18.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.6.0","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.15.2","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.23.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"nvidia-cutlass-dsl","old_version":"4.5.2","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.2","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"},{"name":"helion","old_version":"1.1.0","new_version":"1.4.0","repository_url":"https://github.com/pytorch/helion"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 173 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.5.3` | `5.17.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [safetensors](https://github.com/huggingface/safetensors) | `0.7.0` | `0.8.0` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.6.2.post1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.1.7` | `8.5.0` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.2` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.4.3` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.10.2` | `1.32.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.5` | `0.2.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.4` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.0.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.19.0.56` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.0` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.28.9` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.18.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.6.0` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.15.2` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.23.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.5.2` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.2` | `0.2.10` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n| [helion](https://github.com/pytorch/helion) | `1.1.0` | `1.4.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.5.3 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.3...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2217\"\u003e#2217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/447890f84deab25794ccfdee2a877901b6893569\"\u003e\u003ccode\u003e447890f\u003c/code\u003e\u003c/a\u003e fix(python): pin the ruff rule set so a ruff release can't redden main (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2292\"\u003e#2292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/68b3ab7788b58408f37a3dc73eeabf2417d14c22\"\u003e\u003ccode\u003e68b3ab7\u003c/code\u003e\u003c/a\u003e chore(node): take node security alerts from 33 to 0 (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2287\"\u003e#2287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/74ef81f64e6d1cd4979c56d7d75f3ce21ba11992\"\u003e\u003ccode\u003e74ef81f\u003c/code\u003e\u003c/a\u003e ci: pin every action to one SHA, drop stale audit suppressions (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2291\"\u003e#2291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/b26727f1a92cdf727cd965fc1c467a7c77c63aae\"\u003e\u003ccode\u003eb26727f\u003c/code\u003e\u003c/a\u003e chore(node): drop 8 unused devDependencies (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2286\"\u003e#2286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c7cfd838fb79e76aaba6b0931898073a784fb2a\"\u003e\u003ccode\u003e7c7cfd8\u003c/code\u003e\u003c/a\u003e chore: remove stale examples (kills 50% of dependabot traffic) (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2285\"\u003e#2285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.22.2...v0.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `safetensors` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/safetensors/releases\"\u003esafetensors's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eNews\u003c/h2\u003e\n\u003cp\u003esafetensors joins the PyTorch foundation!\u003c/p\u003e\n\n\u003cp\u003eRead more on that: \u003ca href=\"https://huggingface.co/blog/safetensors-joins-pytorch-foundation\"\u003ehttps://huggingface.co/blog/safetensors-joins-pytorch-foundation\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's changed\u003c/h2\u003e\n\u003cp\u003eSafetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.\u003c/p\u003e\n\u003ch3\u003eBreaking\u003c/h3\u003e\n\u003cp\u003eThe \u003ccode\u003eserialize\u003c/code\u003e and \u003ccode\u003eserialize_file\u003c/code\u003e functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a \u003ccode\u003eTensorSpec\u003c/code\u003e class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level \u003ccode\u003eserialize\u003c/code\u003e / \u003ccode\u003eserialize_file\u003c/code\u003e API directly; the high-level wrappers (\u003ccode\u003esafetensors.torch\u003c/code\u003e, \u003ccode\u003esafetensors.numpy\u003c/code\u003e, \u003ccode\u003esafetensors.paddle\u003c/code\u003e) are updated internally and their public API is unchanged.\u003c/p\u003e\n\u003cp\u003eThe minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eTensorIndexer::Narrow\u003c/code\u003e now carries a \u003ccode\u003estep: NonZeroUsize\u003c/code\u003e parameter, so a slice is now \u003ccode\u003estart:stop:step\u003c/code\u003e. This is a fix as this silent error was hidden behind the \u003ccode\u003eStorage::Torch\u003c/code\u003e variant which offloaded slicing logic to torch directly.\u003c/p\u003e\n\u003ch3\u003eCI\u003c/h3\u003e\n\u003cp\u003eOn the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.\u003c/p\u003e\n\u003cp\u003eAlso dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.\u003c/p\u003e\n\u003ch3\u003eNew features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDirect MPS load on Apple Silicon: tensors are directly loaded in an \u003ccode\u003eMTLBuffer\u003c/code\u003e and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.\u003c/li\u003e\n\u003cli\u003eNew \u003ccode\u003ebackend\u003c/code\u003e parameter introduced, for the addition of the \u003ccode\u003epread\u003c/code\u003e backend. We now support loading files via \u003ccode\u003epread(2)\u003c/code\u003e syscall instead of just mmap. Useful for specific archs/platforms.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eget_slice\u003c/code\u003e now handles ellipsis \u003ccode\u003e[...]\u003c/code\u003e and strided slices \u003ccode\u003e[:, ::8]\u003c/code\u003e wherever safetensors does the slicing itself (\u003ccode\u003epread\u003c/code\u003e for any framework, MPS, and \u003ccode\u003emmap\u003c/code\u003e outside torch/paddle), which silently dropped the step or rejected \u003ccode\u003e...\u003c/code\u003e before.\u003c/li\u003e\n\u003cli\u003eMUSA device support for MooreThreads GPUs.\u003c/li\u003e\n\u003cli\u003eNew dtype support includes \u003ccode\u003efloat8_e4m3fnuz\u003c/code\u003e and \u003ccode\u003efloat8_e5m2fnuz\u003c/code\u003e (AMD FNUZ FP8 formats).\u003c/li\u003e\n\u003cli\u003eThe reader is now explicitly lenient about leading whitespace in the JSON header, which keeps the door open for future page-aligned writes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements/perf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile writes on macOS now use \u003ccode\u003eF_NOCACHE\u003c/code\u003e for direct I/O, yielding roughly 30% faster \u003ccode\u003esave_file\u003c/code\u003e on Apple Silicon.\u003c/li\u003e\n\u003cli\u003eThe packaging dependency has been dropped from the \u003ccode\u003e[torch]\u003c/code\u003e extra, replaced by a simple \u003ccode\u003ehasattr\u003c/code\u003e probe for efficiency.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd arm64 windows support by \u003ca href=\"https://github.com/finnagin\"\u003e\u003ccode\u003e@​finnagin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/678\"\u003esafetensors/safetensors#678\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(backend): support musa backend for MooreThreads GPU by \u003ca href=\"https://github.com/caizhi-mt\"\u003e\u003ccode\u003e@​caizhi-mt\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/671\"\u003esafetensors/safetensors#671\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd gil free serialize_file(serialize_file_threadable) by \u003ca href=\"https://github.com/TomQunChao\"\u003e\u003ccode\u003e@​TomQunChao\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/679\"\u003esafetensors/safetensors#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: remove outdated comment by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/685\"\u003esafetensors/safetensors#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add direct io write fast path on macos by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/687\"\u003esafetensors/safetensors#687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: keep dropped reference to tensor moved from gpu to cpu by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/689\"\u003esafetensors/safetensors#689\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: bump torch to \u003ccode\u003e2.4\u003c/code\u003e by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/710\"\u003esafetensors/safetensors#710\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContribution guide security by \u003ca href=\"https://github.com/LysandreJik\"\u003e\u003ccode\u003e@​LysandreJik\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/712\"\u003esafetensors/safetensors#712\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/safetensors/safetensors/blob/main/RELEASE.md\"\u003esafetensors's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.8.0-dev.0 → 0.8.0\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nUpdate lockfiles again:\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003ecargo check\ncd bindings/python \u0026amp;amp;\u0026amp;amp; uv lock\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;Commit:\u0026lt;/p\u0026gt;\n\u0026lt;pre\u0026gt;\u0026lt;code\u0026gt;Set version to 0.8.0\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;The Python version is not set in \u0026lt;code\u0026gt;pyproject.toml\u0026lt;/code\u0026gt; directly — maturin reads it from \u0026lt;code\u0026gt;bindings/python/Cargo.toml\u0026lt;/code\u0026gt; at build time.\u0026lt;/p\u0026gt;\n\u0026lt;h3\u0026gt;4. Create the release on GitHub\u0026lt;/h3\u0026gt;\n\u0026lt;p\u0026gt;Go to the \u0026lt;a href=\u0026quot;https://github.com/huggingface/safetensors/releases\u0026quot;\u0026gt;GitHub Releases page\u0026lt;/a\u0026gt; and draft a new release:\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Choose the release branch\u0026lt;/strong\u0026gt; (e.g. \u0026lt;code\u0026gt;git_v0.8.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Create a new tag\u0026lt;/strong\u0026gt; on publish: \u0026lt;code\u0026gt;v0.8.0\u0026lt;/code\u0026gt;\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Generate release notes\u0026lt;/strong\u0026gt; from the previous tag (e.g. \u0026lt;code\u0026gt;v0.7.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Add any notable highlights at the top of the generated notes\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;Structure for manual notes:\u0026lt;/p\u0026gt;\n\u0026lt;pre lang=\u0026quot;markdown\u0026quot;\u0026gt;...\n\n_Description has been truncated_","html_url":"https://github.com/KASW-UI/cpu-vllm/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KASW-UI%2Fcpu-vllm/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"}},{"old_version":"5.16.1","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-24T02:31:55.000Z","version_change":"5.16.1 → 5.17.0","issue":{"uuid":"5562149578","node_id":"PR_kwDOT_43As8AAAABE2wmZw","number":79,"state":"open","title":"chore(deps): bump the vision-python group across 1 directory with 8 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T02:31:55.000Z","updated_at":"2026-09-24T02:32:01.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"vision-python","update_count":8,"packages":[{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"torchvision","old_version":"0.28.0","new_version":"0.29.0+cpu"},{"name":"transformers","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.30.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"numpy","old_version":"2.5.2","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"sqlalchemy","old_version":"2.0.52","new_version":"2.0.54","repository_url":"https://github.com/sqlalchemy/sqlalchemy"},{"name":"psycopg","old_version":"3.3.5","new_version":"3.3.6","repository_url":"https://github.com/psycopg/psycopg"},{"name":"boto3","old_version":"1.43.88","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"}],"path":null,"ecosystem":"pip"},"body":"\u003e [!WARNING]\n\u003e Cooldown could not be applied because no publication date was available from the registry.\n\u003e\n\nBumps the vision-python group with 8 updates in the /vision directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| torchvision | `0.28.0` | `0.29.0+cpu` |\n| [transformers](https://github.com/huggingface/transformers) | `5.16.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.30.0` | `1.32.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |\n| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.52` | `2.0.54` |\n| [psycopg](https://github.com/psycopg/psycopg) | `3.3.5` | `3.3.6` |\n| [boto3](https://github.com/boto/boto3) | `1.43.88` | `1.43.98` |\n\n\nUpdates `uvicorn` from 0.52.4 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torchvision` from 0.28.0 to 0.29.0+cpu\n\nUpdates `transformers` from 5.16.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.30.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.30.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.5.2 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.5.2...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sqlalchemy` from 2.0.52 to 2.0.54\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sqlalchemy/sqlalchemy/releases\"\u003esqlalchemy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.0.54\u003c/h1\u003e\n\u003cp\u003eReleased: September 15, 2026\u003c/p\u003e\n\u003ch2\u003eplatform\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[platform] [change]\u003c/strong\u003e Binary wheels are no longer built for Python 3.7.  PyPI now rejects wheel\nfiles whose filename does not begin with the normalized project name, and\nthe packaging tools that can be installed on Python 3.7 do not produce\nsuch a filename.  As a result, SQLAlchemy 2.0.44 was the last release to\npublish Python 3.7 wheels to PyPI, and releases 2.0.45 and later have\nbeen available on Python 3.7 only as a source distribution; the wheel\nbuilds for Python 3.7 are now removed.  Python 3.7 remains supported by\nthe 2.0 series.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[platform] [bug]\u003c/strong\u003e Fixed issue where the Cython extensions were compiled without the\n\u003ccode\u003efreethreading_compatible\u003c/code\u003e directive, so that they did not declare\nthemselves as safe to run without the GIL.  On a free-threaded Python\ninterpreter such as Python 3.13t or 3.14t, importing SQLAlchemy would\ncause the interpreter to re-enable the GIL, emitting a\n\u003ccode\u003eRuntimeWarning\u003c/code\u003e.  The directive is now set when building for Python\n3.13 and above, and a test has been added which confirms that importing\nSQLAlchemy on a free-threaded build does not enable the GIL.\u003c/p\u003e\n\u003cp\u003eReferences: \u003ca href=\"https://www.sqlalchemy.org/trac/ticket/13592\"\u003e#13592\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.0.53\u003c/h1\u003e\n\u003cp\u003eReleased: September 14, 2026\u003c/p\u003e\n\u003ch2\u003eorm\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[orm] [bug]\u003c/strong\u003e Fixed issue where an expression passed to \u003ccode\u003e_orm.with_expression()\u003c/code\u003e\nthat embedded a \u003ccode\u003e_sql.select()\u003c/code\u003e, such as a correlated\n\u003ccode\u003e_sql.exists()\u003c/code\u003e, would fail to populate the attribute correctly on\nthe second and subsequent executions of an otherwise identical\nstatement, when the \u003ccode\u003e_orm.query_expression()\u003c/code\u003e attribute was loaded\nby a relationship loader that emits a second query, i.e.\n\u003ccode\u003e_orm.selectinload()\u003c/code\u003e, \u003ccode\u003e_orm.lazyload()\u003c/code\u003e or\n\u003ccode\u003e_orm.immediateload()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eReferences: \u003ca href=\"https://www.sqlalchemy.org/trac/ticket/13560\"\u003e#13560\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e[orm] [bug]\u003c/strong\u003e Fixed memory issue where mapped classes, along with their\n\u003ccode\u003eTable\u003c/code\u003e and \u003ccode\u003e_orm.Mapper\u003c/code\u003e objects, would not be garbage\ncollected after the \u003ccode\u003e_orm.registry\u003c/code\u003e in which they were mapped had\nbeen disposed and dereferenced.  The issue would occur for mappings that\nmade use of \u003ccode\u003e_orm.relationship()\u003c/code\u003e together with constructs such as an\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sqlalchemy/sqlalchemy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `psycopg` from 3.3.5 to 3.3.6\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psycopg/psycopg/blob/master/docs/news.rst\"\u003epsycopg's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e.. currentmodule:: psycopg\u003c/p\u003e\n\u003cp\u003e.. index::\nsingle: Release notes\nsingle: News\u003c/p\u003e\n\u003ch1\u003e\u003ccode\u003epsycopg\u003c/code\u003e release notes\u003c/h1\u003e\n\u003ch2\u003eCurrent release\u003c/h2\u003e\n\u003cp\u003ePsycopg 3.3.6\n^^^^^^^^^^^^^\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for Python 3.15 (:ticket:\u003ccode\u003e[#1245](https://github.com/psycopg/psycopg/issues/1245)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDon't wait forever for a query to terminate after interrupting it, for\ninstance if the server is unresponsive. The fix requires libpq 17 or newer\n(:ticket:\u003ccode\u003e[#1371](https://github.com/psycopg/psycopg/issues/1371)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eCancel a running query upon receiving \u003ccode\u003e!SystemExit\u003c/code\u003e (:ticket:\u003ccode\u003e[#1384](https://github.com/psycopg/psycopg/issues/1384)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eReport \u003ccode\u003e!None\u003c/code\u003e instead of \u003ccode\u003e65535\u003c/code\u003e as the \u003ccode\u003eColumn.precision\u003c/code\u003e of an\n:sql:\u003ccode\u003einterval\u003c/code\u003e column declared with a fields restriction and no explicit\nprecision, such as e.g. :sql:\u003ccode\u003einterval day to second\u003c/code\u003e (:ticket:\u003ccode\u003e[#1397](https://github.com/psycopg/psycopg/issues/1397)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix dumping of nested subclasses of lists as arrays (:ticket:\u003ccode\u003e[#1398](https://github.com/psycopg/psycopg/issues/1398)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDiscard prepared statements upon :sql:\u003ccode\u003eDEALLOCATE ALL\u003c/code\u003e (:ticket:\u003ccode\u003e[#1408](https://github.com/psycopg/psycopg/issues/1408)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eBetter guards dumping large Python \u003ccode\u003e!int\u003c/code\u003e to binary numeric (:ticket:\u003ccode\u003e[#1414](https://github.com/psycopg/psycopg/issues/1414)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eImprove performance of async queries by reducing the overhead of the\n\u003ccode\u003e!wait_async()\u003c/code\u003e function (:ticket:\u003ccode\u003e[#1331](https://github.com/psycopg/psycopg/issues/1331)\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePsycopg 3.3.5\n^^^^^^^^^^^^^\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDiscard prepared statements upon :sql:\u003ccode\u003eALTER *\u003c/code\u003e or \u003ccode\u003eDISCARD *\u003c/code\u003e\n(:ticket:\u003ccode\u003e[#1307](https://github.com/psycopg/psycopg/issues/1307)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003e!ProgrammingError\u003c/code\u003e when dumping non-\u003ccode\u003e!None\u003c/code\u003e values with\nno \u003ccode\u003e!NoneType\u003c/code\u003e dumper registered in python implementation (:ticket:\u003ccode\u003e[#1325](https://github.com/psycopg/psycopg/issues/1325)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003e!wait_selector\u003c/code\u003e wait function to not raise \u003ccode\u003e!KeyError\u003c/code\u003e\n(:ticket:\u003ccode\u003e[#1327](https://github.com/psycopg/psycopg/issues/1327)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003e!DataError\u003c/code\u003e messages leaking the literal \u003ccode\u003e{...}\u003c/code\u003e placeholder instead\nof the offending value when loading a pre-year-1 :sql:\u003ccode\u003etimestamp\u003c/code\u003e or a\nmalformed binary :sql:\u003ccode\u003ejsonb\u003c/code\u003e value (:ticket:\u003ccode\u003e[#1372](https://github.com/psycopg/psycopg/issues/1372)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003e!DataError\u003c/code\u003e instead of \u003ccode\u003e!ValueError\u003c/code\u003e when \u003ccode\u003e~psycopg.rows.namedtuple_row\u003c/code\u003e\nreceives duplicate column names (:ticket:\u003ccode\u003e[#1348](https://github.com/psycopg/psycopg/issues/1348)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003e!DataError\u003c/code\u003e on inconsistent copy data (:tickets:\u003ccode\u003e[#1359](https://github.com/psycopg/psycopg/issues/1359), [#1360](https://github.com/psycopg/psycopg/issues/1360)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eHandle client encodings aliases (:ticket:\u003ccode\u003e[#1363](https://github.com/psycopg/psycopg/issues/1363)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eFix building C extension with Cython 3.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePsycopg 3.3.4\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/a67654d1e7afbf9b3a619557838f62de1c790e7c\"\u003e\u003ccode\u003ea67654d\u003c/code\u003e\u003c/a\u003e chore: bump psycopg package version to 3.3.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/443814b3b111ac678a39fd523c1a826266fb69b5\"\u003e\u003ccode\u003e443814b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/psycopg/psycopg/issues/1416\"\u003e#1416\u003c/a\u003e from dvarrazzo/wait-async-perf\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/42966e9ebbda3b9c69b15c5588543c15f2aae5dd\"\u003e\u003ccode\u003e42966e9\u003c/code\u003e\u003c/a\u003e test: add helpful comments to some tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/5e8797f0c8003d8cd12a1e5c13f05fbb94c1c1d2\"\u003e\u003ccode\u003e5e8797f\u003c/code\u003e\u003c/a\u003e test: add reasonable connect_timeout to most tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/c81ba62442dfbd69e207d6914e6ae2aa27e56886\"\u003e\u003ccode\u003ec81ba62\u003c/code\u003e\u003c/a\u003e perf: reduce the overhead of wait_async()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/d2bbfe4e2b1e36a20e72a18097f35a3db27296e3\"\u003e\u003ccode\u003ed2bbfe4\u003c/code\u003e\u003c/a\u003e refactor: use get_running_loop() in the async wait functions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/2b1484a550e01c88fda077099678f0abb9217ecb\"\u003e\u003ccode\u003e2b1484a\u003c/code\u003e\u003c/a\u003e test: add a script to measure the async wait functions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/573cf4aa70d8fdefc9d5f3eb69d5419cd6d3cd51\"\u003e\u003ccode\u003e573cf4a\u003c/code\u003e\u003c/a\u003e test: fix incorrect wait timing test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/2b68990874175b8d97269218d4963b2d5c8656f3\"\u003e\u003ccode\u003e2b68990\u003c/code\u003e\u003c/a\u003e refactor: drop leftovers of waiting with inf interval in wait_conn_async\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psycopg/psycopg/commit/60765dd8fc7d8df03cd75efcff485bfb3c83a0ed\"\u003e\u003ccode\u003e60765dd\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/psycopg/psycopg/issues/1414\"\u003e#1414\u003c/a\u003e from dvarrazzo/fix-decimal-overflow\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psycopg/psycopg/compare/3.3.5...3.3.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `boto3` from 1.43.88 to 1.43.98\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/3314d844db83f544d5e9e0a69e832c00aa5d35b4\"\u003e\u003ccode\u003e3314d84\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.98'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/3a3637ffdcfcbc372301c116fd4378bba35da85b\"\u003e\u003ccode\u003e3a3637f\u003c/code\u003e\u003c/a\u003e Bumping version to 1.43.98\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/d8023504a9d68112c34302fed9fa47256e05edac\"\u003e\u003ccode\u003ed802350\u003c/code\u003e\u003c/a\u003e Add changelog entries from botocore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/ed7de96664d52b6e04521b189462c7d43959e90a\"\u003e\u003ccode\u003eed7de96\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.97'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/fba1e41a696d49d48c1fb0d8a844515869fe832c\"\u003e\u003ccode\u003efba1e41\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.97' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/275709c0e197e696f122571d26a6d2a51d7438a7\"\u003e\u003ccode\u003e275709c\u003c/code\u003e\u003c/a\u003e Bumping version to 1.43.97\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/a5c0088fb17e49e4bb4b1ea3d1a69dc5e3ecc907\"\u003e\u003ccode\u003ea5c0088\u003c/code\u003e\u003c/a\u003e Add changelog entries from botocore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/2be9967c9214ffb4421dc9710c7f7fead47dcd33\"\u003e\u003ccode\u003e2be9967\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.96'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/bc6248938c188c427b902be1362e85e0bce2be32\"\u003e\u003ccode\u003ebc62489\u003c/code\u003e\u003c/a\u003e Merge branch 'release-1.43.96' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/boto/boto3/commit/6e1774a1ffe1d84bfd70f36c0bdff3e6dd079aaa\"\u003e\u003ccode\u003e6e1774a\u003c/code\u003e\u003c/a\u003e Bumping version to 1.43.96\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/boto/boto3/compare/1.43.88...1.43.98\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/oldmoldycake/Snagr/pull/79","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/oldmoldycake%2FSnagr/issues/79","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/79/packages"}},{"old_version":"4.57.6","new_version":"5.10.1","update_type":"major","path":null,"pr_created_at":"2026-09-22T13:47:59.000Z","version_change":"4.57.6 → 5.10.1","issue":{"uuid":"5540499012","node_id":"PR_kwDOPZl8xs8AAAABEloFHw","number":85,"state":"open","title":"chore(deps): bump transformers from 4.57.6 to 5.10.1","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T13:47:59.000Z","updated_at":"2026-09-24T06:37:02.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"transformers","old_version":"4.57.6","new_version":"5.10.1","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Bumps [transformers](https://github.com/huggingface/transformers) from 4.57.6 to 5.10.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v5.10.1\u003c/h1\u003e\n\u003cp\u003ev5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!\u003c/p\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eGemma4 unified+ Gemma4 MTP\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eGemma 4 12B Unified is an \u003cstrong\u003eencoder-free\u003c/strong\u003e multimodal model with pretrained and instruction-tuned variants. Unlike \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gemma4\"\u003estandard Gemma 4\u003c/a\u003e, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.\u003c/p\u003e\n\u003cp\u003eKey differences from standard Gemma 4:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo Vision Tower\u003c/strong\u003e: Raw pixel patches are projected directly into LM space via a \u003ccode\u003eDense + LayerNorm\u003c/code\u003e pipeline with factorized 2D positional embeddings, replacing the vision encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNo Audio Tower\u003c/strong\u003e: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple \u003ccode\u003eRMSNorm → Linear\u003c/code\u003e pipeline, replacing the mel spectrogram + Conformer encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eShared Multimodal Pipeline\u003c/strong\u003e: Both vision and audio use the same \u003ccode\u003eGemma4UnifiedMultimodalEmbedder\u003c/code\u003e (RMSNorm → Linear) for the final projection to text hidden space.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou can find the original Gemma 4 12B Unified checkpoints under the \u003ca href=\"https://huggingface.co/collections/google/gemma-4\"\u003eGemma 4\u003c/a\u003e release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewho needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e) by \u003ca href=\"https://github.com/douglas-reid\"\u003e\u003ccode\u003e@​douglas-reid\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/sgerrard\"\u003e\u003ccode\u003e@​sgerrard\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/vasqu\"\u003e\u003ccode\u003e@​vasqu\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/molbap\"\u003e\u003ccode\u003e@​molbap\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSapiens2\u003c/h3\u003e\n\u003cp\u003eSapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2\"\u003eDocumentation\u003c/a\u003e | \u003ca href=\"https://huggingface.co/papers/2604.21681\"\u003ePaper\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e) by \u003ca href=\"https://github.com/guarin\"\u003e\u003ccode\u003e@​guarin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45919\"\u003e#45919\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDeepSeek-OCR-2\u003c/h3\u003e\n\u003cp\u003eDeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Deepseek-OCR-2 model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45075\"\u003e#45075\u003c/a\u003e) by \u003ca href=\"https://github.com/thisisiron\"\u003e\u003ccode\u003e@​thisisiron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45075\"\u003e#45075\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMellum\u003c/h3\u003e\n\u003cp\u003eMellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/mellum\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Add support for JetBrains' \u003ccode\u003eMellum\u003c/code\u003e v2 code generation model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46112\"\u003e#46112\u003c/a\u003e) by \u003ca href=\"https://github.com/shadeMe\"\u003e\u003ccode\u003e@​shadeMe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/46112\"\u003e#46112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBreaking changes\u003c/h2\u003e\n\u003cp\u003eThe Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 Fix float16 overflow in Gemma4 vision pooler (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46277\"\u003e#46277\u003c/a\u003e) by \u003ca href=\"https://github.com/Bluear7878\"\u003e\u003ccode\u003e@​Bluear7878\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAudio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 [ALM] Add base model without head (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45534\"\u003e#45534\u003c/a\u003e) by \u003ca href=\"https://github.com/eustlb\"\u003e\u003ccode\u003e@​eustlb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d\"\u003e\u003ccode\u003e90c3ae5\u003c/code\u003e\u003c/a\u003e Patch because we had to yank 5.10 because the release branch was not up to date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968\"\u003e\u003ccode\u003e0bd94b3\u003c/code\u003e\u003c/a\u003e v5.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897\"\u003e\u003ccode\u003e1423d22\u003c/code\u003e\u003c/a\u003e who needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98\"\u003e\u003ccode\u003e50eb20a\u003c/code\u003e\u003c/a\u003e Fix dsv4 dequant + tp/ep (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46378\"\u003e#46378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299\"\u003e\u003ccode\u003e74464e8\u003c/code\u003e\u003c/a\u003e Fix wrong changes produced by style/repo. check bot (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46371\"\u003e#46371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc\"\u003e\u003ccode\u003e1b8ec34\u003c/code\u003e\u003c/a\u003e Fix path traversal when saving Bark voice preset embeddings (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46237\"\u003e#46237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872\"\u003e\u003ccode\u003ee820678\u003c/code\u003e\u003c/a\u003e Add Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43\"\u003e\u003ccode\u003e595721c\u003c/code\u003e\u003c/a\u003e Pass library_name/version to Hub calls via a shared HfApi (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46318\"\u003e#46318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a\"\u003e\u003ccode\u003e0f0036c\u003c/code\u003e\u003c/a\u003e docs: update ACL Anthology URL in CITATION.cff (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46352\"\u003e#46352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353\"\u003e\u003ccode\u003efa6c830\u003c/code\u003e\u003c/a\u003e DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45634\"\u003e#45634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.57.6...v5.10.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=transformers\u0026package-manager=uv\u0026previous-version=4.57.6\u0026new-version=5.10.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/manykarim/rf-mcp/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/manykarim/rf-mcp/pull/85","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/manykarim%2Frf-mcp/issues/85","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/85/packages"}},{"old_version":"5.15.0","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-22T09:58:13.000Z","version_change":"5.15.0 → 5.17.0","issue":{"uuid":"5537987472","node_id":"PR_kwDORRqaa88AAAABEjmjBg","number":155,"state":"closed","title":"build(deps): bump the python-minor-patch group across 1 directory with 22 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-23T23:48:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-22T09:58:13.000Z","updated_at":"2026-09-23T23:48:03.000Z","time_to_close":136188,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"python-minor-patch","update_count":22,"packages":[{"name":"pillow-heif","old_version":"1.5.0","new_version":"1.7.0","repository_url":"https://github.com/bigcat88/pillow_heif"},{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pyjwt","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"filelock","old_version":"3.32.4","new_version":"3.32.7","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"grpcio","old_version":"1.83.1","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"huggingface-hub","old_version":"1.29.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"hypothesis","old_version":"6.167.1","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"multidict","old_version":"6.7.1","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.25.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"onnx","old_version":"1.22.0","new_version":"1.23.0","repository_url":"https://github.com/onnx/onnx"},{"name":"propcache","old_version":"0.5.2","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"protobuf","old_version":"7.36.0","new_version":"7.36.2","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"python-discovery","old_version":"1.6.0","new_version":"1.6.1","repository_url":"https://github.com/tox-dev/python-discovery"},{"name":"regex","old_version":"2026.8.31","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"ruff","old_version":"0.16.5","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"threadpoolctl","old_version":"3.6.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"virtualenv","old_version":"21.7.7","new_version":"21.7.16","repository_url":"https://github.com/pypa/virtualenv"},{"name":"yarl","old_version":"1.24.5","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-minor-patch group with 22 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pillow-heif](https://github.com/bigcat88/pillow_heif) | `1.5.0` | `1.7.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.4` | `3.32.7` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| [grpcio](https://github.com/grpc/grpc) | `1.83.1` | `1.84.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.29.0` | `1.32.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.167.1` | `6.168.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.9.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.25.0` | `2.26.0` |\n| [onnx](https://github.com/onnx/onnx) | `1.22.0` | `1.23.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.5.2` | `0.5.4` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.36.0` | `7.36.2` |\n| [python-discovery](https://github.com/tox-dev/python-discovery) | `1.6.0` | `1.6.1` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.8.31` | `2026.9.10` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.8` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.6.0` | `3.7.0` |\n| [virtualenv](https://github.com/pypa/virtualenv) | `21.7.7` | `21.7.16` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.5` | `1.25.1` |\n\n\nUpdates `pillow-heif` from 1.5.0 to 1.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/bigcat88/pillow_heif/releases\"\u003epillow-heif's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.7.0\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing nominal diffuse white luminance HDR metadata: \u003ccode\u003enominal_diffuse_white_luminance\u003c/code\u003e key in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/468\"\u003e#468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epy.typed\u003c/code\u003e marker, the package type annotations are now visible to type checkers. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.2\u003c/code\u003e to \u003ccode\u003e1.23.3\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/470\"\u003e#470\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibde265\u003c/code\u003e was updated from the \u003ccode\u003e1.1.1\u003c/code\u003e to \u003ccode\u003e1.1.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/471\"\u003e#471\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOut-of-bounds read in \u003ccode\u003eencode()\u003c/code\u003e when \u003ccode\u003estride\u003c/code\u003e was smaller than the image row width. (GHSA-ccw6-q225-c975) Thanks to \u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e for finding this!\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTypeError\u003c/code\u003e when saving an image whose \u003ccode\u003einfo\u003c/code\u003e dictionary contains non-string keys. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.6.0\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing HDR metadata: \u003ccode\u003econtent_light_level\u003c/code\u003e, \u003ccode\u003emastering_display_colour_volume\u003c/code\u003e, \u003ccode\u003eambient_viewing_environment\u003c/code\u003e keys in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/456\"\u003e#456\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython \u003ccode\u003e3.15\u003c/code\u003e and \u003ccode\u003e3.15t\u003c/code\u003e wheels added.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.1\u003c/code\u003e to \u003ccode\u003e1.23.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/466\"\u003e#466\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse-after-free when a numpy array or the \u003ccode\u003edata\u003c/code\u003e memoryview outlived the \u003ccode\u003eHeifFile\u003c/code\u003e it was created from. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/453\"\u003e#453\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConflicting license metadata: removed the \u003ccode\u003eGPLv2\u003c/code\u003e classifier, the package license is \u003ccode\u003eBSD-3-Clause\u003c/code\u003e; bundled library licenses in wheels are described in \u003ccode\u003eLICENSES_bundled.txt\u003c/code\u003e, which was updated to match the current libraries. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/455\"\u003e#455\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/bigcat88/pillow_heif/blob/master/CHANGELOG.md\"\u003epillow-heif's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.7.0 - 2026-09-06]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing nominal diffuse white luminance HDR metadata: \u003ccode\u003enominal_diffuse_white_luminance\u003c/code\u003e key in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/468\"\u003e#468\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epy.typed\u003c/code\u003e marker, the package type annotations are now visible to type checkers. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.2\u003c/code\u003e to \u003ccode\u003e1.23.3\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/470\"\u003e#470\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibde265\u003c/code\u003e was updated from the \u003ccode\u003e1.1.1\u003c/code\u003e to \u003ccode\u003e1.1.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/471\"\u003e#471\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eOut-of-bounds read in \u003ccode\u003eencode()\u003c/code\u003e when \u003ccode\u003estride\u003c/code\u003e was smaller than the image row width. (GHSA-ccw6-q225-c975) Thanks to \u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e for finding this!\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTypeError\u003c/code\u003e when saving an image whose \u003ccode\u003einfo\u003c/code\u003e dictionary contains non-string keys. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.6.0 - 2026-08-31]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReading and writing HDR metadata: \u003ccode\u003econtent_light_level\u003c/code\u003e, \u003ccode\u003emastering_display_colour_volume\u003c/code\u003e, \u003ccode\u003eambient_viewing_environment\u003c/code\u003e keys in \u003ccode\u003einfo\u003c/code\u003e dictionary. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/456\"\u003e#456\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython \u003ccode\u003e3.15\u003c/code\u003e and \u003ccode\u003e3.15t\u003c/code\u003e wheels added.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elibheif\u003c/code\u003e was updated from the \u003ccode\u003e1.23.1\u003c/code\u003e to \u003ccode\u003e1.23.2\u003c/code\u003e version. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/466\"\u003e#466\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse-after-free when a numpy array or the \u003ccode\u003edata\u003c/code\u003e memoryview outlived the \u003ccode\u003eHeifFile\u003c/code\u003e it was created from. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/453\"\u003e#453\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConflicting license metadata: removed the \u003ccode\u003eGPLv2\u003c/code\u003e classifier, the package license is \u003ccode\u003eBSD-3-Clause\u003c/code\u003e; bundled library licenses in wheels are described in \u003ccode\u003eLICENSES_bundled.txt\u003c/code\u003e, which was updated to match the current libraries. \u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/455\"\u003e#455\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/f65a9ac77809609ad8ebb001c691b5a3ee01146b\"\u003e\u003ccode\u003ef65a9ac\u003c/code\u003e\u003c/a\u003e v1.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/a32776839dc69bc0bc7452a015fc48f145b1831e\"\u003e\u003ccode\u003ea327768\u003c/code\u003e\u003c/a\u003e feat: py.typed marker; fix the mypy errors it exposes (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/475\"\u003e#475\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/b7d8f391d67de84080d5a254268537aaa71567dc\"\u003e\u003ccode\u003eb7d8f39\u003c/code\u003e\u003c/a\u003e fix: out-of-bounds read in encode() when stride is smaller than the row (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/474\"\u003e#474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/cb0edae400111e6b83ac8af146d81da92baddcfd\"\u003e\u003ccode\u003ecb0edae\u003c/code\u003e\u003c/a\u003e chore(deps): update pypa/cibuildwheel action to v4.2.1 (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/472\"\u003e#472\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/9a255542051d9ca8ff43015a58bf5967567559dc\"\u003e\u003ccode\u003e9a25554\u003c/code\u003e\u003c/a\u003e chore(deps): update dependency strukturag/libheif to v1.23.3 (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/470\"\u003e#470\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/fb3a3842914fd3c07c3c8a93dffe35045ded2df7\"\u003e\u003ccode\u003efb3a384\u003c/code\u003e\u003c/a\u003e ci: let renovate update every bundled library version reference (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/473\"\u003e#473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/14c0c24ac81f5d2ddca17d3505efe32ea5fa6fbc\"\u003e\u003ccode\u003e14c0c24\u003c/code\u003e\u003c/a\u003e chore(deps): update dependency strukturag/libde265 to v1.1.2 (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/471\"\u003e#471\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/1460a210cced41f99788c1dc96e7a5ba49cc94a2\"\u003e\u003ccode\u003e1460a21\u003c/code\u003e\u003c/a\u003e feat: read and write nominal diffuse white luminance (ndwt) (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/468\"\u003e#468\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/e7b41516053be108ef1fb4feaac69b99bc7cc811\"\u003e\u003ccode\u003ee7b4151\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/bigcat88/pillow_heif/issues/469\"\u003e#469\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bigcat88/pillow_heif/commit/5695650dbe0d4bf5616110782697b43d57805e46\"\u003e\u003ccode\u003e5695650\u003c/code\u003e\u003c/a\u003e bump version to 1.7.0.dev0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/bigcat88/pillow_heif/compare/v1.5.0...v1.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `uvicorn` from 0.52.4 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.13.0 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ePyJWT 2.14.0\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst\"\u003e2.14.0 changelog\u003c/a\u003e for the complete release details and related security advisories.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.14.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Harden HMAC key validation against public-key material supplied as JWK,\n  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See\n  `GHSA-r6x4-923q-g947 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947\u0026gt;`__,\n  `GHSA-ffc3-869f-jxw9 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9\u0026gt;`__,\n  `GHSA-p4g4-x82p-q773 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773\u0026gt;`__,\n  and `GHSA-w2cx-738m-mc7w \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w\u0026gt;`__.\n- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing\n  redirected destinations from being treated as trusted key sources. See\n  `GHSA-9v7f-9g4p-ffgj \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj\u0026gt;`__.\n- Limit repeated JWKS refreshes caused by unknown key IDs while preserving\n  normal key-rotation behavior. See\n  `GHSA-2gx3-rcp4-g85q \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q\u0026gt;`__.\n- Handle deeply nested and malformed JWS/JWK input without uncaught recursion\n  errors or whole-set parsing failures. See\n  `GHSA-8wjv-2p76-3863 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863\u0026gt;`__\n  and `GHSA-w6j9-cwv2-h6wq \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq\u0026gt;`__.\n- Enforce compact JWS encoding rules during decoding. See\n  `GHSA-hxm8-2xgr-2p9m \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m\u0026gt;`__.\n- Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n\n  \u0026lt;https://github.com/xclow3n\u0026gt;`__ for reporting this behavior; fixed in commit\n  `37b54877 \u0026lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Apply HMAC key validation consistently when keys are loaded through\n  ``PyJWK`` and ``PyJWKClient``. See\n  `GHSA-pxh4-856f-4h89 \u0026amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89\u0026amp;gt;`__.\n- Reject empty HMAC keys when represented as JWKs.\n  See `GHSA-pxh4-856f-4h89 \u0026amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89\u0026amp;gt;`__.\n\nFixed\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eRaise the documented \u003ccode\u003ePyJWTError\u003c/code\u003e subclass instead of leaking a\u003cbr /\u003e\n\u003ccode\u003eTypeError\u003c/code\u003e when the \u003ccode\u003eexp\u003c/code\u003e, \u003ccode\u003enbf\u003c/code\u003e, or \u003ccode\u003eiat\u003c/code\u003e claim decodes to a\u003cbr /\u003e\nnon-numeric, non-string value such as a list, dict, or \u003ccode\u003enull\u003c/code\u003e.\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df\"\u003e\u003ccode\u003ec6fe464\u003c/code\u003e\u003c/a\u003e release: prepare v2.14.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42\"\u003e\u003ccode\u003ef541302\u003c/code\u003e\u003c/a\u003e style: apply Ruff formatting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95\"\u003e\u003ccode\u003e801cd12\u003c/code\u003e\u003c/a\u003e fix: reject public JWK container HMAC keys\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb\"\u003e\u003ccode\u003eaf8181c\u003c/code\u003e\u003c/a\u003e fix: reject empty HMAC keys from JWKs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1\"\u003e\u003ccode\u003eba4853a\u003c/code\u003e\u003c/a\u003e Throttle repeated PyJWKClient refreshes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499\"\u003e\u003ccode\u003e2798504\u003c/code\u003e\u003c/a\u003e fix: reject DER public keys as HMAC secrets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07\"\u003e\u003ccode\u003e8b4e233\u003c/code\u003e\u003c/a\u003e fix: reject loader-accepted PEM variants\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258\"\u003e\u003ccode\u003e1f8180a\u003c/code\u003e\u003c/a\u003e fix: format JWS tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab\"\u003e\u003ccode\u003ecff1ac5\u003c/code\u003e\u003c/a\u003e Fix redirect handler return annotation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56\"\u003e\u003ccode\u003e0a795b8\u003c/code\u003e\u003c/a\u003e Reject redirects in PyJWKClient fetches\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anyio` from 4.14.2 to 4.15.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.15.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplemented a compatibility fix for supporting direct access of \u003ccode\u003eanyio.*\u003c/code\u003e submodules from the main package even when those submodules were not directly imported first (\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311\"\u003e#1311\u003c/a\u003e \u0026lt;\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E\"\u003eagronholm/anyio#1311\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.15.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for the newer keyword-only arguments on \u003ccode\u003eanyio.Path\u003c/code\u003e methods to match the standard library \u003ccode\u003epathlib.Path\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eexists()\u003c/code\u003e (Python 3.12+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_dir()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_file()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eowner()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003egroup()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enewline\u003c/code\u003e on \u003ccode\u003eread_text()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1286\"\u003e#1286\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1293\"\u003e#1293\u003c/a\u003e; PR by \u003ca href=\"https://github.com/jaideeppyne\"\u003e\u003ccode\u003e@​jaideeppyne\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eamap\u003c/code\u003e, \u003ccode\u003egather\u003c/code\u003e, and \u003ccode\u003eas_completed\u003c/code\u003e utility functions to simplify common patterns (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1173\"\u003e#1173\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003e--anyio-mode\u003c/code\u003e command-line option as an alternative to the \u003ccode\u003eanyio_mode\u003c/code\u003e ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: \u003ccode\u003epytest_asyncio\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1242\"\u003e#1242\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003eanyio.Future\u003c/code\u003e synchronization primitive which behaves similar to \u003ccode\u003easyncio.Future\u003c/code\u003e, allowing tasks to wait for a value (or exception) from another task (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1146\"\u003e#1146\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Vizonex\"\u003e\u003ccode\u003e@​Vizonex\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded guidance for managing multiple memory object stream producers and consumers with cloned streams (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/330\"\u003e#330\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nightcityblade\"\u003e\u003ccode\u003e@​nightcityblade\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eStapledObjectStream.send_nowait()\u003c/code\u003e that delegates to the underlying \u003ccode\u003eObjectSendStream\u003c/code\u003e, if it implements it (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1241\"\u003e#1241\u003c/a\u003e; PR by \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003emove_on_at()\u003c/code\u003e and \u003ccode\u003efail_at()\u003c/code\u003e functions to complement \u003ccode\u003emove_on_after()\u003c/code\u003e and \u003ccode\u003efail_after()\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the default name for a task spawned with \u003ccode\u003eTaskGroup.create_task(func())\u003c/code\u003e to match the default task name for the analogous task spawned with \u003ccode\u003eTaskGroup.start_soon(func)\u003c/code\u003e or \u003ccode\u003eTaskGroup.start(func)\u003c/code\u003e in more situations. Previously, the default name of a \u003ccode\u003eTaskGroup.create_task\u003c/code\u003e task never included the module name. (The default name for a task spawned with \u003ccode\u003eTaskGroup.start_soon\u003c/code\u003e or \u003ccode\u003eTaskGroup.start\u003c/code\u003e typically includes the module name.) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1234\"\u003e#1234\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the \u003ccode\u003eanyio\u003c/code\u003e and \u003ccode\u003eanyio.abc\u003c/code\u003e modules to lazily (much like \u003ccode\u003e810\u003c/code\u003e) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the \u003ccode\u003eif TYPE_CHECKING:\u003c/code\u003e block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1169\"\u003e#1169\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to \u003ccode\u003estart_blocking_portal()\u003c/code\u003e and \u003ccode\u003eanyio.to_thread.run_sync()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1224\"\u003e#1224\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eSpooledTemporaryFile.readinto()\u003c/code\u003e and \u003ccode\u003ereadinto1()\u003c/code\u003e reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1215\"\u003e#1215\u003c/a\u003e; PR by \u003ca href=\"https://github.com/c-tonneslan\"\u003e\u003ccode\u003e@​c-tonneslan\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded a \u003ccode\u003ereason\u003c/code\u003e parameter to \u003ccode\u003efail_after\u003c/code\u003e (and the new \u003ccode\u003efail_at\u003c/code\u003e) allowing for added exception context when raising \u003ccode\u003eTimeoutError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1227\"\u003e#1227\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the default \u003ccode\u003eTaskHandle.name\u003c/code\u003e missing part of the task name for tasks started with \u003ccode\u003eTaskGroup.start\u003c/code\u003e on Trio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1231\"\u003e#1231\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.run\u003c/code\u003e leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a \u003ccode\u003eRunVar\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1203\"\u003e#1203\u003c/a\u003e; PR by \u003ca href=\"https://github.com/tapetersen\"\u003e\u003ccode\u003e@​tapetersen\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.Path.with_stem()\u003c/code\u003e silently producing a wrong path (e.g. \u003ccode\u003ePath(\u0026quot;.txt\u0026quot;)\u003c/code\u003e) instead of raising \u003ccode\u003eValueError\u003c/code\u003e when given an empty stem on a path with a non-empty suffix, unlike \u003ccode\u003epathlib.PurePath.with_stem\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1200\"\u003e#1200\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Sanjays2402\"\u003e\u003ccode\u003e@​Sanjays2402\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eUNIXSocketStream.aclose()\u003c/code\u003e raising \u003ccode\u003easyncio.InvalidStateError\u003c/code\u003e when a concurrent receive or send operation had just been cancelled on the asyncio backend (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1267\"\u003e#1267\u003c/a\u003e; PR by \u003ca href=\"https://github.com/alloutflo\"\u003e\u003ccode\u003e@​alloutflo\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the pytest plugin importing the deprecated \u003ccode\u003e_pytest.python.CallSpec2\u003c/code\u003e alias, which triggers \u003ccode\u003ePytestRemovedIn10Warning\u003c/code\u003e on \u003ccode\u003epytest\u0026gt;=9.2\u003c/code\u003e and crashes pytest at startup when \u003ccode\u003efilterwarnings = error\u003c/code\u003e is configured (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1271\"\u003e#1271\u003c/a\u003e; PR by \u003ca href=\"https://github.com/matthewfeickert\"\u003e\u003ccode\u003e@​matthewfeickert\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed an asyncio worker thread race that could raise \u003ccode\u003eRuntimeError\u003c/code\u003e when the event loop closed between checking its state and scheduling the worker result (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1265\"\u003e#1265\u003c/a\u003e; PR by \u003ca href=\"https://github.com/hansu650\"\u003e\u003ccode\u003e@​hansu650\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens when \u003ccode\u003etotal_tokens\u003c/code\u003e was raised while the limiter was over-subscribed (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1223\"\u003e#1223\u003c/a\u003e; PR by \u003ca href=\"https://github.com/zelinewang\"\u003e\u003ccode\u003e@​zelinewang\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703\"\u003e\u003ccode\u003effcd154\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f\"\u003e\u003ccode\u003e0ecf5ed\u003c/code\u003e\u003c/a\u003e Added a workaround for third party code accessing unimported submodules (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f\"\u003e\u003ccode\u003e9283662\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d\"\u003e\u003ccode\u003ed137692\u003c/code\u003e\u003c/a\u003e Improved the instructions for AI agents\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265\"\u003e\u003ccode\u003e033fc52\u003c/code\u003e\u003c/a\u003e Shield TemporaryDirectory cleanup from cancellation (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc\"\u003e\u003ccode\u003e942e9a6\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1305\"\u003e#1305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704\"\u003e\u003ccode\u003eb825c3b\u003c/code\u003e\u003c/a\u003e Fixed pyproject.toml changes not triggering the test suite\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af\"\u003e\u003ccode\u003e9727dc5\u003c/code\u003e\u003c/a\u003e Fixed start inconsistencies between trio and asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1198\"\u003e#1198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8\"\u003e\u003ccode\u003eb05fe6d\u003c/code\u003e\u003c/a\u003e Fixed wrong type in move_on_after (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153\"\u003e\u003ccode\u003e44d0c93\u003c/code\u003e\u003c/a\u003e Fixed asyncio task group coroutine cleanup (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1275\"\u003e#1275\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.14.2...4.15.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `filelock` from 3.32.4 to 3.32.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/py-filelock/releases\"\u003efilelock's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.32.7\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix final symlink test on musl by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/737\"\u003etox-dev/filelock#737\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say acquire() falls back to the lock's blocking attribute by \u003ca href=\"https://github.com/hxperl\"\u003e\u003ccode\u003e@​hxperl\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/733\"\u003etox-dev/filelock#733\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hxperl\"\u003e\u003ccode\u003e@​hxperl\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/733\"\u003etox-dev/filelock#733\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.6...3.32.7\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.6...3.32.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix(lease): reject a duration no marker can carry by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/723\"\u003etox-dev/filelock#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(soft-rw): reject non-finite timing options by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/724\"\u003etox-dev/filelock#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve exception notes when copying and pickling by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(soft-rw): reuse existing test module by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/730\"\u003etox-dev/filelock#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: respect ACL write access when the owner write bit is absent by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/728\"\u003etox-dev/filelock#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SoftReadWriteLock state lock timeout by \u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.5\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(fork): report where a stalled fork stops by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/715\"\u003etox-dev/filelock#715\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say that mode is read-only in the thread-local section by \u003ca href=\"https://github.com/Gares95\"\u003e\u003ccode\u003e@​Gares95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/716\"\u003etox-dev/filelock#716\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(lease): clear token after failed acquire by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst\"\u003efilelock's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e###########\nChangelog\n###########\u003c/p\u003e\n\u003cp\u003e.. towncrier-draft-entries:: Unreleased\u003c/p\u003e\n\u003cp\u003e.. towncrier release notes start\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.1 (2026-09-19)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epoll_interval\u003c/code\u003e is now validated at construction, on the setter, and on \u003ccode\u003eacquire()\u003c/code\u003e: a negative, non-finite, or\nnon-numeric value raises :class:\u003ccode\u003eValueError\u003c/code\u003e/:class:\u003ccode\u003eTypeError\u003c/code\u003e immediately instead of failing inside \u003ccode\u003etime.sleep\u003c/code\u003e. :pr:\u003ccode\u003e739\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.0 (2026-09-17)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eThe :class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e on-disk protocol is a generation log under \u003ccode\u003e\u0026lt;path\u0026gt;.rw\u003c/code\u003e, and a process\nrunning an earlier release does not see it: an old and a new participant on one lock path do not exclude each\nother. Stop every participant, upgrade them all, then restart them; the new code ignores leftover \u003ccode\u003e.state\u003c/code\u003e,\n\u003ccode\u003e.write\u003c/code\u003e and \u003ccode\u003e.readers/\u003c/code\u003e files, and you can delete them. The filesystem must provide no-replace hard links, as\nit must for :class:\u003ccode\u003e~filelock.StrictSoftFileLock\u003c/code\u003e, so a runtime without \u003ccode\u003eos.link\u003c/code\u003e raises\n:class:\u003ccode\u003e~filelock.SoftFileLockProtocolError\u003c/code\u003e on acquire. Constructing a singleton again with a different\n\u003ccode\u003eon_compromise\u003c/code\u003e, or with \u003ccode\u003epoll_interval\u003c/code\u003e at or above \u003ccode\u003estale_threshold\u003c/code\u003e, now raises :class:\u003ccode\u003eValueError\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e exposes :attr:\u003ccode\u003e~filelock.SoftReadWriteLock.generation\u003c/code\u003e as a fencing token for\nthe protected resource and reports a lost hold through \u003ccode\u003eon_compromise\u003c/code\u003e and\n:attr:\u003ccode\u003e~filelock.SoftReadWriteLock.compromise\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e no longer deadlocks when a holder dies on another host mid-transition, and\n\u003ccode\u003erelease()\u003c/code\u003e no longer waits on a mutex a dead host left behind (:pr:\u003ccode\u003e725\u003c/code\u003e, :pr:\u003ccode\u003e735\u003c/code\u003e). The state mutex is gone.\nEach transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock\nrather than an \u003ccode\u003emtime\u003c/code\u003e read against another host's. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.7 (2026-09-16)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eValidate final-symlink refusal by error number so the test works across libc implementations. :pr:\u003ccode\u003e737\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocument that :meth:\u003ccode\u003e~filelock.BaseFileLock.acquire\u003c/code\u003e reads \u003ccode\u003eblocking=None\u003c/code\u003e as the lock's \u003ccode\u003eblocking\u003c/code\u003e attribute and\nraises :class:\u003ccode\u003e~filelock.Timeout\u003c/code\u003e after one attempt when \u003ccode\u003eblocking=False\u003c/code\u003e. :pr:\u003ccode\u003e733\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.6 (2026-09-08)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSoftFileLease\u003c/code\u003e and \u003ccode\u003eAsyncSoftFileLease\u003c/code\u003e now reject a boolean or non-finite \u003ccode\u003elease_duration\u003c/code\u003e, which used to\npublish an owner record their own \u003ccode\u003eowner\u003c/code\u003e property reads back as malformed. :pr:\u003ccode\u003e723\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eReject non-finite heartbeat, stale, and polling intervals in \u003ccode\u003eSoftReadWriteLock\u003c/code\u003e and \u003ccode\u003eAsyncSoftReadWriteLock\u003c/code\u003e,\nincluding cached singleton construction and overflow in the default stale threshold. :pr:\u003ccode\u003e724\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/20929f7d1439d5fa1df158fcac87b60815f5d422\"\u003e\u003ccode\u003e20929f7\u003c/code\u003e\u003c/a\u003e Release 3.32.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/35f07c48009c41faecfa7182939e5b7e1c78ae71\"\u003e\u003ccode\u003e35f07c4\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/736\"\u003e#736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e860d3905d369b4753de5759d1cd70d0ca639d1f\"\u003e\u003ccode\u003ee860d39\u003c/code\u003e\u003c/a\u003e 📝 docs: say acquire() falls back to the lock's blocking attribute (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/c530efec2ee5012eeaa742c196c3623d478888ba\"\u003e\u003ccode\u003ec530efe\u003c/code\u003e\u003c/a\u003e Fix final symlink test on musl (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/737\"\u003e#737\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d\"\u003e\u003ccode\u003e4efd93e\u003c/code\u003e\u003c/a\u003e Release 3.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1\"\u003e\u003ccode\u003e7b7b7a8\u003c/code\u003e\u003c/a\u003e Fix SoftReadWriteLock state lock timeout (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2\"\u003e\u003ccode\u003ef2f7b86\u003c/code\u003e\u003c/a\u003e fix: respect ACL write access when the owner write bit is absent (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153\"\u003e\u003ccode\u003ee947a69\u003c/code\u003e\u003c/a\u003e test(soft-rw): reuse existing test module (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88\"\u003e\u003ccode\u003eda3ae2b\u003c/code\u003e\u003c/a\u003e fix: preserve exception notes when copying and pickling (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812\"\u003e\u003ccode\u003eae9cb5b\u003c/code\u003e\u003c/a\u003e 🐛 fix(soft-rw): reject non-finite timing options (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tox-dev/py-filelock/compare/3.32.4...3.32.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fonttools` from 4.63.0 to 4.65.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fonttools/fonttools/releases\"\u003efonttools's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.65.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[glyf] Add \u003ccode\u003e__iter__\u003c/code\u003e, \u003ccode\u003eitems\u003c/code\u003e and \u003ccode\u003evalues\u003c/code\u003e methods to the \u003ccode\u003eglyf\u003c/code\u003e table to make it more dict-like (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4156\"\u003e#4156\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Escape the anonymous block tag when scanning for its terminator, so tags containing regex metacharacters are matched literally (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4167\"\u003e#4167\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib] Strip directory components from \u003ccode\u003e\u0026lt;variable-font name=\u0026quot;...\u0026quot;/\u0026gt;\u003c/code\u003e when deriving the output filename in the \u003ccode\u003evarLib\u003c/code\u003e command line, so a designspace cannot write outside the output directory (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4168\"\u003e#4168\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Fix tracking of the current script and language across redundant \u003ccode\u003escript\u003c/code\u003e statements. Rules following a \u003ccode\u003escript\u003c/code\u003e statement that names the first declared language system no longer end up under the \u003ccode\u003eDFLT\u003c/code\u003e script, and a \u003ccode\u003escript\u003c/code\u003e statement naming the already-current script still narrows the language systems and terminates the current lookup while leaving the \u003ccode\u003elookupflag\u003c/code\u003e alone, matching makeotf (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1824\"\u003e#1824\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/2522\"\u003e#2522\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4169\"\u003e#4169\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.interpolatable] Escape glyph names in the HTML report (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4172\"\u003e#4172\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[otlLib] Fix overflow handling when building contextual lookups: offset overflows now raise \u003ccode\u003eOTLOffsetOverflowError\u003c/code\u003e instead of \u003ccode\u003eAttributeError\u003c/code\u003e so another contextual format can be tried (regression from \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3439\"\u003e#3439\u003c/a\u003e). When all formats overflow, split the ruleset in halves until it fits (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4171\"\u003e#4171\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.64.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[feaLib] Fix name-table parsing for multibyte Mac encodings (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1196\"\u003e#1196\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4092\"\u003e#4092\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttProgram] Also indent TrueType assembly following \u003ccode\u003eIDEF[ ]\u003c/code\u003e, like function definitions (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4093\"\u003e#4093\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Keep East Asian spacing \u003ccode\u003epalt\u003c/code\u003e by default (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4094\"\u003e#4094\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Bug fix for MATH table in which constructions for glyphs that are only added during MATH closure were kept (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4096\"\u003e#4096\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ufoLib] Make glyph-to-group construction accessible outside of lookup function (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4102\"\u003e#4102\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[glyf] Use reverse glyph map for O(1) \u003ccode\u003e__setitem__\u003c/code\u003e membership (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4103\"\u003e#4103\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Fix \u003ccode\u003efixLookupOverFlows()\u003c/code\u003e reporting success when it had not promoted any lookup to Extension, masking unresolvable overflows.\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for TrueType Collection version 2 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4100\"\u003e#4100\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Pin a single head.modified timestamp across \u003ccode\u003eTTCollection.save\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4111\"\u003e#4111\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Give an actionable error when LookupList overflow is unrecoverable (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4109\"\u003e#4109\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for the AAT bitmap tables \u003ccode\u003ebhed\u003c/code\u003e, \u003ccode\u003ebdat\u003c/code\u003e, \u003ccode\u003ebloc\u003c/code\u003e, variants of \u003ccode\u003ehead\u003c/code\u003e, \u003ccode\u003eEBDT\u003c/code\u003e, \u003ccode\u003eEBLC\u003c/code\u003e used in legacy Apple bitmap-only fonts (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4115\"\u003e#4115\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Check \u003ccode\u003eOS/2\u003c/code\u003e fsSelection/macStyle consistency against \u003ccode\u003ebhed\u003c/code\u003e as well as \u003ccode\u003ehead\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4118\"\u003e#4118\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4119\"\u003e#4119\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.roundTools] Add types and documentation (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4123\"\u003e#4123\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Instance the \u003ccode\u003eBASE\u003c/code\u003e table (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4137\"\u003e#4137\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Fix Private-dict \u003ccode\u003evsindex\u003c/code\u003e handling in \u003ccode\u003einstantiateCFF2\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4129\"\u003e#4129\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4132\"\u003e#4132\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Fix crash instancing CFF2 fonts without a VariationStore (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4130\"\u003e#4130\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4131\"\u003e#4131\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[sfnt] Raise \u003ccode\u003eTTLibError\u003c/code\u003e instead of \u003ccode\u003eAssertionError\u003c/code\u003e or \u003ccode\u003estruct.error\u003c/code\u003e when reading a font truncated within the table directory or a table entry (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4147\"\u003e#4147\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4149\"\u003e#4149\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.xmlWriter] Escape the \u003ccode\u003e]]\u0026gt;\u003c/code\u003e terminator inside CDATA sections, so an SVG document containing it can no longer smuggle markup past a TTX round trip (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4139\"\u003e#4139\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.instancer] Implement avar2 partial-instancing: the avar version 2 ItemVariationStore is adjusted so that remaining axes behave the same after limiting the designspace (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4045\"\u003e#4045\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Add shorthand for the value at the default location in a variable scalar: \u003ccode\u003e(100 wght=900:120)\u003c/code\u003e means \u003ccode\u003e(wght=400:100 wght=900:120)\u003c/code\u003e when the wght default is 400 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4024\"\u003e#4024\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[cmap] Raise \u003ccode\u003eTTLibError\u003c/code\u003e for a truncated or out-of-bounds cmap subtable header (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4151\"\u003e#4151\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[designspaceLib] Reject conflicting duplicate inputs in axis maps instead of silently keeping the last one (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4153\"\u003e#4153\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[designspaceLib] Read an empty \u003ccode\u003e\u0026lt;lib\u0026gt;\u003c/code\u003e element as an empty lib instead of raising \u003ccode\u003eIndexError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4142\"\u003e#4142\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4144\"\u003e#4144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[colorLib] Raise a legible error when a COLRv0 layer, or a COLRv1 PaintGlyph or PaintColrGlyph, references a glyph missing from the glyphMap, instead of failing obscurely later (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/2629\"\u003e#2629\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4141\"\u003e#4141\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[cmap] Don't drop subtables in unsupported formats when compiling or dumping a font read from binary (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4136\"\u003e#4136\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Implement \u003ccode\u003esplitSinglePos\u003c/code\u003e so GPOS lookup type 1 offset overflows can be recovered by splitting the subtable (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4091\"\u003e#4091\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4108\"\u003e#4108\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[cmap] Round-trip empty Macintosh format 2 subtables (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3663\"\u003e#3663\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4117\"\u003e#4117\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[glyf] Raise \u003ccode\u003eTTLibError\u003c/code\u003e instead of \u003ccode\u003eRecursionError\u003c/code\u003e when \u003ccode\u003erecalcBounds()\u003c/code\u003e hits a composite-component reference cycle (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3899\"\u003e#3899\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4116\"\u003e#4116\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[svgLib] Fix crash parsing an SVG path with consecutive closepath commands (\u003ccode\u003eZ Z\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4122\"\u003e#4122\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Fix \u003ccode\u003eDefaultTable\u003c/code\u003e type annotations (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4126\"\u003e#4126\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for the \u003ccode\u003eEBSC\u003c/code\u003e (Embedded Bitmap Scaling) table (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4113\"\u003e#4113\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[svgLib] Suppress spurious close segments caused by floating-point drift in relative path commands (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3860\"\u003e#3860\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4127\"\u003e#4127\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[qu2cu] Fix \u003ccode\u003eTypeError\u003c/code\u003e in the Cython-compiled build when \u003ccode\u003eQu2CuPen\u003c/code\u003e passes tuple splines (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4160\"\u003e#4160\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[mort] Add semantic decompilation, TTX, and compilation support for rearrangement, contextual-substitution, ligature, and insertion subtables (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4158\"\u003e#4158\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4159\"\u003e#4159\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4161\"\u003e#4161\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[svgLib] Start a new subpath at the just-closed subpath's initial point when a drawto command follows a closepath, per SVG spec (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4154\"\u003e#4154\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4155\"\u003e#4155\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.filesystem] \u003cstrong\u003eSECURITY\u003c/strong\u003e Reject paths that resolve outside the filesystem root: a malicious UFO could read arbitrary files via \u003ccode\u003e..\u003c/code\u003e components in \u003ccode\u003econtents.plist\u003c/code\u003e, and a crafted \u003ccode\u003e.ufoz\u003c/code\u003e could create files outside its temporary mirror (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4124\"\u003e#4124\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] \u003cstrong\u003eSECURITY\u003c/strong\u003e Sanitise glyph names used as filenames in EBDT/CBDT \u003ccode\u003ettx -z extfile\u003c/code\u003e export, preventing arbitrary file writes from untrusted fonts (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4128\"\u003e#4128\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[misc.etree] \u003cstrong\u003eSECURITY\u003c/strong\u003e Don't resolve external XML entities in \u003ccode\u003eXMLParser\u003c/code\u003e when lxml is used, preventing XXE file disclosure on lxml \u0026lt; 5.0 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4145\"\u003e#4145\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Fully prune \u003ccode\u003eVARC\u003c/code\u003e auxiliary data: collect and remap variation indices referenced by condition tables when subsetting the \u003ccode\u003eMultiVarStore\u003c/code\u003e, and drop the \u003ccode\u003eAxisIndicesList\u003c/code\u003e, \u003ccode\u003eConditionList\u003c/code\u003e, and \u003ccode\u003eMultiVarStore\u003c/code\u003e when they end up empty (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4162\"\u003e#4162\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fonttools/fonttools/blob/main/NEWS.rst\"\u003efonttools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.65.0 (released 2026-09-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[glyf] Add \u003ccode\u003e__iter__\u003c/code\u003e, \u003ccode\u003eitems\u003c/code\u003e and \u003ccode\u003evalues\u003c/code\u003e methods to the \u003ccode\u003eglyf\u003c/code\u003e table\nto make it more dict-like (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4156\"\u003e#4156\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Escape the anonymous block tag when scanning for its terminator, so tags\ncontaining regex metacharacters are matched literally (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4167\"\u003e#4167\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib] Strip directory components from \u003ccode\u003e\u0026lt;variable-font name=\u0026quot;...\u0026quot;/\u0026gt;\u003c/code\u003e when\nderiving the output filename in the \u003ccode\u003evarLib\u003c/code\u003e command line, so a designspace\ncannot write outside the output directory (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4168\"\u003e#4168\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[feaLib] Fix tracking of the current script and language across redundant\n\u003ccode\u003escript\u003c/code\u003e statements. Rules following a \u003ccode\u003escript\u003c/code\u003e statement that names the\nfirst declared language system no longer end up under the \u003ccode\u003eDFLT\u003c/code\u003e script, and\na \u003ccode\u003escript\u003c/code\u003e statement naming the already-current script still narrows the\nlanguage systems and terminates the current lookup while leaving the\n\u003ccode\u003elookupflag\u003c/code\u003e alone, matching makeotf (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1824\"\u003e#1824\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/2522\"\u003e#2522\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4169\"\u003e#4169\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[varLib.interpolatable] Escape glyph names in the HTML report (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4172\"\u003e#4172\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[otlLib] Fix overflow handling when building contextual lookups: offset overflows\nnow raise \u003ccode\u003eOTLOffsetOverflowError\u003c/code\u003e instead of \u003ccode\u003eAttributeError\u003c/code\u003e so another\ncontextual format can be tried (regression from \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/3439\"\u003e#3439\u003c/a\u003e). When all formats\noverflow, split the ruleset in halves until it fits (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4171\"\u003e#4171\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.64.0 (released 2026-08-31)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[feaLib] Fix name-table parsing for multibyte Mac encodings (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/1196\"\u003e#1196\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4092\"\u003e#4092\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttProgram] Also indent TrueType assembly following \u003ccode\u003eIDEF[ ]\u003c/code\u003e, like function\ndefinitions (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4093\"\u003e#4093\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Keep East Asian spacing \u003ccode\u003epalt\u003c/code\u003e by default (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4094\"\u003e#4094\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[subset] Bug fix for MATH table in which constructions for glyphs that are only\nadded during MATH closure were kept (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4096\"\u003e#4096\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ufoLib] Make glyph-to-group construction accessible outside of lookup function\n(\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4102\"\u003e#4102\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[glyf] Use reverse glyph map for O(1) \u003ccode\u003e__setitem__\u003c/code\u003e membership (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4103\"\u003e#4103\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Fix \u003ccode\u003efixLookupOverFlows()\u003c/code\u003e reporting success when it had not promoted\nany lookup to Extension, masking unresolvable overflows.\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for TrueType Collection version 2 (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4100\"\u003e#4100\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Pin a single head.modified timestamp across \u003ccode\u003eTTCollection.save\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4111\"\u003e#4111\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Give an actionable error when LookupList overflow is unrecoverable (\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4109\"\u003e#4109\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Add support for the AAT bitmap tables \u003ccode\u003ebhed\u003c/code\u003e, \u003ccode\u003ebdat\u003c/code\u003e, \u003ccode\u003ebloc\u003c/code\u003e,\nvariants of \u003ccode\u003ehead\u003c/code\u003e, \u003ccode\u003eEBDT\u003c/code\u003e, \u003ccode\u003eEBLC\u003c/code\u003e used in legacy Apple bitmap-only fonts\n(\u003ca href=\"https://redirect.github.com/fonttools/fonttools/issues/4115\"\u003e#4115\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e[ttLib] Check \u003ccode\u003eOS/2\u003c/code\u003e fsSelection/macStyle consistency against \u003ccode\u003ebhed\u003c/code...\n\n_Description has been truncated_","html_url":"https://github.com/ncoevoet/facet/pull/155","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ncoevoet%2Ffacet/issues/155","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/155/packages"}},{"old_version":"4.53.3","new_version":"5.17.0","update_type":"major","path":null,"pr_created_at":"2026-09-22T06:23:30.000Z","version_change":"4.53.3 → 5.17.0","issue":{"uuid":"5536027477","node_id":"PR_kwDONC03Hc8AAAABEiBuuw","number":4260,"state":"open","title":"build(deps): bump the python group with 85 updates","user":"dependabot[bot]","labels":["backport:skip","dependencies","python:uv","first-time-contributor"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T06:23:30.000Z","updated_at":"2026-09-22T06:33:34.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"python","update_count":85,"packages":[{"name":"pin-pink","old_version":"4.3.0","new_version":"4.4.0","repository_url":"https://github.com/stephane-caron/pink"},{"name":"reactivex","old_version":"4.1.0","new_version":"5.1.0","repository_url":"https://github.com/ReactiveX/RxPY"},{"name":"pydantic","old_version":"2.12.5","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"packaging","old_version":"25.0","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"filelock","old_version":"3.23.0","new_version":"3.32.6","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"plum-dispatch","old_version":"2.5.7","new_version":"2.10.1","repository_url":"https://github.com/beartype/plum"},{"name":"gitpython","old_version":"3.1.52","new_version":"3.1.62","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"structlog","old_version":"25.5.0","new_version":"26.1.0","repository_url":"https://github.com/hynek/structlog"},{"name":"opencv-contrib-python","old_version":"4.13.0.92","new_version":"5.0.0.93","repository_url":"https://github.com/opencv/opencv-python"},{"name":"pydantic-settings","old_version":"2.12.0","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"textual","old_version":"3.7.1","new_version":"8.2.8","repository_url":"https://github.com/Textualize/textual"},{"name":"terminaltexteffects","old_version":"0.12.2","new_version":"0.15.0","repository_url":"https://github.com/ChrisBuilds/terminaltexteffects"},{"name":"typer","old_version":"0.23.1","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"ipython","old_version":"8.38.0","new_version":"8.39.0","repository_url":"https://github.com/ipython/ipython"},{"name":"plotext","old_version":"5.3.2","new_version":"6.1.0","repository_url":"https://github.com/piccolomo/plotext"},{"name":"numba","old_version":"0.63.1","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"llvmlite","old_version":"0.46.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"rerun-sdk","old_version":"0.32.0","new_version":"0.37.2","repository_url":"https://github.com/rerun-io/rerun"},{"name":"protobuf","old_version":"6.33.5","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"ipykernel","old_version":"7.2.0","new_version":"7.3.0","repository_url":"https://github.com/ipython/ipykernel"},{"name":"open-clip-torch","old_version":"3.2.0","new_version":"3.3.0","repository_url":"https://github.com/mlfoundations/open_clip"},{"name":"gdown","old_version":"6.0.0","new_version":"6.2.0","repository_url":"https://github.com/wkentaro/gdown"},{"name":"tensorboard","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/tensorflow/tensorboard"},{"name":"portal","old_version":"3.7.4","new_version":"3.8.1","repository_url":"https://github.com/danijar/portal"},{"name":"bosdyn-client","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-api","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-core","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"pyarrow","old_version":"23.0.0","new_version":"25.0.1","repository_url":"https://github.com/apache/arrow"},{"name":"langchain-core","old_version":"1.3.3","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-openai","old_version":"1.1.6","new_version":"1.6.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-huggingface","old_version":"1.2.0","new_version":"1.2.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-ollama","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"ollama","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/ollama/ollama-python"},{"name":"openai","old_version":"2.21.0","new_version":"3.14.0","repository_url":"https://github.com/openai/openai-python"},{"name":"sounddevice","old_version":"0.5.5","new_version":"0.5.6","repository_url":"https://github.com/spatialaudio/python-sounddevice"},{"name":"fastapi","old_version":"0.129.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"python-socketio","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/sponsors/miguelgrinberg"},{"name":"python-multipart","old_version":"0.0.27","new_version":"0.0.32","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"sse-starlette","old_version":"3.2.0","new_version":"3.4.11","repository_url":"https://github.com/sysid/sse-starlette"},{"name":"uvicorn","old_version":"0.40.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"soundfile","old_version":"0.13.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"timm","old_version":"1.0.24","new_version":"1.0.29","repository_url":"https://github.com/huggingface/pytorch-image-models"},{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"lap","old_version":"0.5.12","new_version":"0.5.13","repository_url":"https://github.com/gatagat/lap"},{"name":"transformers","old_version":"4.53.3","new_version":"5.17.0"},{"name":"moondream","old_version":"0.2.0","new_version":"2.3.0","repository_url":"https://github.com/vikhyat/moondream"},{"name":"omegaconf","old_version":"2.3.0","new_version":"2.3.1","repository_url":"https://github.com/omry/omegaconf"},{"name":"hydra-core","old_version":"1.3.2","new_version":"1.3.7","repository_url":"https://github.com/facebookresearch/hydra"},{"name":"unitree-webrtc-connect","old_version":"2.1.2","new_version":"2.2.0","repository_url":"https://github.com/legion1581/unitree_webrtc_connect"},{"name":"cyclonedds","old_version":"0.10.5","new_version":"11.0.1","repository_url":"https://github.com/eclipse-cyclonedds/cyclonedds-python"},{"name":"mcap","old_version":"1.3.1","new_version":"1.4.0","repository_url":"https://github.com/foxglove/mcap"},{"name":"piper-sdk","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/agilexrobotics/piper_sdk"},{"name":"xarm-python-sdk","old_version":"1.17.3","new_version":"1.18.4","repository_url":"https://github.com/xArm-Developer/xArm-Python-SDK"},{"name":"roboplan","old_version":"0.6.0","new_version":"0.6.1","repository_url":"https://github.com/open-planning/roboplan"},{"name":"matplotlib","old_version":"3.10.8","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"cupy-cuda12x","old_version":"13.6.0","new_version":"14.2.0","repository_url":"https://github.com/cupy/cupy"},{"name":"mujoco","old_version":"3.10.0","new_version":"3.13.0","repository_url":"https://github.com/google-deepmind/mujoco"},{"name":"gtsam-extended","old_version":"4.3a1.post1","new_version":"4.3a2.post202608240418"},{"name":"aiortc","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/aiortc/aiortc"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"reportlab","old_version":"4.5.0","new_version":"5.0.1"},{"name":"manifold3d","old_version":"3.5.1","new_version":"3.5.3","repository_url":"https://github.com/elalish/manifold"},{"name":"coacd","old_version":"1.0.11","new_version":"1.0.14","repository_url":"https://github.com/SarahWeiii/CoACD"},{"name":"usd-core","old_version":"26.5","new_version":"26.8","repository_url":"https://github.com/PixarAnimationStudios/OpenUSD"},{"name":"ruff","old_version":"0.14.3","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"},{"name":"pytest","old_version":"8.3.5","new_version":"9.1.1","repository_url":"https://github.com/pytest-dev/pytest"},{"name":"pytest-mock","old_version":"3.15.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-env","old_version":"1.1.5","new_version":"1.7.1","repository_url":"https://github.com/pytest-dev/pytest-env"},{"name":"pytest-rerunfailures","old_version":"16.4","new_version":"16.6.1","repository_url":"https://github.com/pytest-dev/pytest-rerunfailures"},{"name":"coverage","old_version":"7.13.4","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"pre-commit","old_version":"4.2.0","new_version":"4.6.2","repository_url":"https://github.com/pre-commit/pre-commit"},{"name":"py-spy","old_version":"0.4.1","new_version":"0.4.2","repository_url":"https://github.com/benfred/py-spy"},{"name":"maturin","old_version":"1.13.3","new_version":"1.15.0","repository_url":"https://github.com/pyo3/maturin"},{"name":"python-lsp-server","old_version":"1.14.0","new_version":"1.15.0"},{"name":"python-lsp-ruff","old_version":"2.3.0","new_version":"2.3.4","repository_url":"https://github.com/python-lsp/python-lsp-ruff"},{"name":"playwright","old_version":"1.61.0","new_version":"1.62.0","repository_url":"https://github.com/microsoft/playwright-python"},{"name":"mypy","old_version":"1.19.0","new_version":"2.3.1","repository_url":"https://github.com/python/mypy"},{"name":"types-pyyaml","old_version":"6.0.12.20250915","new_version":"6.0.12.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"types-reportlab","old_version":"4.5.0.20260509","new_version":"5.0.0.20260911","repository_url":"https://github.com/python/typeshed"},{"name":"types-requests","old_version":"2.32.4.20260107","new_version":"2.33.0.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"pybind11","old_version":"3.0.4","new_version":"3.1.0","repository_url":"https://github.com/pybind/pybind11"},{"name":"optuna","old_version":"4.9.0","new_version":"5.0.0","repository_url":"https://github.com/optuna/optuna"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python group with 85 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pin-pink](https://github.com/stephane-caron/pink) | `4.3.0` | `4.4.0` |\n| [reactivex](https://github.com/ReactiveX/RxPY) | `4.1.0` | `5.1.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [packaging](https://github.com/pypa/packaging) | `25.0` | `26.3` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.23.0` | `3.32.6` |\n| [plum-dispatch](https://github.com/beartype/plum) | `2.5.7` | `2.10.1` |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.52` | `3.1.62` |\n| [structlog](https://github.com/hynek/structlog) | `25.5.0` | `26.1.0` |\n| [opencv-contrib-python](https://github.com/opencv/opencv-python) | `4.13.0.92` | `5.0.0.93` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.12.0` | `2.15.0` |\n| [textual](https://github.com/Textualize/textual) | `3.7.1` | `8.2.8` |\n| [terminaltexteffects](https://github.com/ChrisBuilds/terminaltexteffects) | `0.12.2` | `0.15.0` |\n| [typer](https://github.com/fastapi/typer) | `0.23.1` | `0.27.2` |\n| [ipython](https://github.com/ipython/ipython) | `8.38.0` | `8.39.0` |\n| [plotext](https://github.com/piccolomo/plotext) | `5.3.2` | `6.1.0` |\n| [numba](https://github.com/numba/numba) | `0.63.1` | `0.67.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.46.0` | `0.49.0` |\n| [rerun-sdk](https://github.com/rerun-io/rerun) | `0.32.0` | `0.37.2` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `6.33.5` | `7.36.1` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.1` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [ipykernel](https://github.com/ipython/ipykernel) | `7.2.0` | `7.3.0` |\n| [open-clip-torch](https://github.com/mlfoundations/open_clip) | `3.2.0` | `3.3.0` |\n| [gdown](https://github.com/wkentaro/gdown) | `6.0.0` | `6.2.0` |\n| [tensorboard](https://github.com/tensorflow/tensorboard) | `2.20.0` | `2.21.0` |\n| [portal](https://github.com/danijar/portal) | `3.7.4` | `3.8.1` |\n| [bosdyn-client](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-api](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-core](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [pyarrow](https://github.com/apache/arrow) | `23.0.0` | `25.0.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.3.3` | `1.6.3` |\n| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.6` | `1.6.2` |\n| [langchain-huggingface](https://github.com/langchain-ai/langchain) | `1.2.0` | `1.2.2` |\n| [langchain-ollama](https://github.com/langchain-ai/langchain) | `1.0.1` | `1.1.0` |\n| [ollama](https://github.com/ollama/ollama-python) | `0.6.1` | `0.6.2` |\n| [openai](https://github.com/openai/openai-python) | `2.21.0` | `3.14.0` |\n| [sounddevice](https://github.com/spatialaudio/python-sounddevice) | `0.5.5` | `0.5.6` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.129.0` | `0.141.1` |\n| [python-socketio](https://github.com/sponsors/miguelgrinberg) | `5.16.1` | `5.17.0` |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.27` | `0.0.32` |\n| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.2.0` | `3.4.11` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.53.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.13.1` | `0.14.0` |\n| [timm](https://github.com/huggingface/pytorch-image-models) | `1.0.24` | `1.0.29` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.2.0` | `12.3.0` |\n| [lap](https://github.com/gatagat/lap) | `0.5.12` | `0.5.13` |\n| [transformers[torch]](https://github.com/huggingface/transformers) | `4.53.3` | `5.17.0` |\n| [moondream](https://github.com/vikhyat/moondream) | `0.2.0` | `2.3.0` |\n| [omegaconf](https://github.com/omry/omegaconf) | `2.3.0` | `2.3.1` |\n| [hydra-core](https://github.com/facebookresearch/hydra) | `1.3.2` | `1.3.7` |\n| [unitree-webrtc-connect](https://github.com/legion1581/unitree_webrtc_connect) | `2.1.2` | `2.2.0` |\n| [cyclonedds](https://github.com/eclipse-cyclonedds/cyclonedds-python) | `0.10.5` | `11.0.1` |\n| [mcap](https://github.com/foxglove/mcap) | `1.3.1` | `1.4.0` |\n| [piper-sdk](https://github.com/agilexrobotics/piper_sdk) | `0.6.1` | `0.6.2` |\n| [xarm-python-sdk](https://github.com/xArm-Developer/xArm-Python-SDK) | `1.17.3` | `1.18.4` |\n| [roboplan](https://github.com/open-planning/roboplan) | `0.6.0` | `0.6.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.10.8` | `3.10.9` |\n| [cupy-cuda12x](https://github.com/cupy/cupy) | `13.6.0` | `14.2.0` |\n| [mujoco](https://github.com/google-deepmind/mujoco) | `3.10.0` | `3.13.0` |\n| [gtsam-extended](https://gtsam.org/) | `4.3a1.post1` | `4.3a2.post202608240418` |\n| [aiortc](https://github.com/aiortc/aiortc) | `1.14.0` | `1.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [reportlab](https://www.reportlab.com/) | `4.5.0` | `5.0.1` |\n| [manifold3d](https://github.com/elalish/manifold) | `3.5.1` | `3.5.3` |\n| [coacd](https://github.com/SarahWeiii/CoACD) | `1.0.11` | `1.0.14` |\n| [usd-core](https://github.com/PixarAnimationStudios/OpenUSD) | `26.5` | `26.8` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.14.3` | `0.16.7` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.3.5` | `9.1.1` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.0` | `3.15.1` |\n| [pytest-env](https://github.com/pytest-dev/pytest-env) | `1.1.5` | `1.7.1` |\n| [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.4` | `16.6.1` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.13.4` | `7.16.1` |\n| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.2.0` | `4.6.2` |\n| [py-spy](https://github.com/benfred/py-spy) | `0.4.1` | `0.4.2` |\n| [maturin](https://github.com/pyo3/maturin) | `1.13.3` | `1.15.0` |\n| [python-lsp-server[all]](https://github.com/python-lsp/python-lsp-server) | `1.14.0` | `1.15.0` |\n| [python-lsp-ruff](https://github.com/python-lsp/python-lsp-ruff) | `2.3.0` | `2.3.4` |\n| [playwright](https://github.com/microsoft/playwright-python) | `1.61.0` | `1.62.0` |\n| [mypy](https://github.com/python/mypy) | `1.19.0` | `2.3.1` |\n| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20250915` | `6.0.12.20260906` |\n| [types-reportlab](https://github.com/python/typeshed) | `4.5.0.20260509` | `5.0.0.20260911` |\n| [types-requests](https://github.com/python/typeshed) | `2.32.4.20260107` | `2.33.0.20260906` |\n| [pybind11](https://github.com/pybind/pybind11) | `3.0.4` | `3.1.0` |\n| [optuna](https://github.com/optuna/optuna) | `4.9.0` | `5.0.0` |\n\nUpdates `pin-pink` from 4.3.0 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/stephane-caron/pink/releases\"\u003epin-pink's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cp\u003eThis release allows custom boundaries in velocity limits, allowing bounds on joints that can't have a limit from their URDF model (such as continuous joints).\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pink-kinematics/pink/blob/main/CHANGELOG.md\"\u003epin-pink's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.4.0] - 2026-09-09\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/c14d0ae62f4fb744bbe84e35f9e16f1b680b20c0\"\u003e\u003ccode\u003ec14d0ae\u003c/code\u003e\u003c/a\u003e Release v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/5c890570ee42d397f03d1cf8e1b8f4a9797bde97\"\u003e\u003ccode\u003e5c89057\u003c/code\u003e\u003c/a\u003e doc: Add context to configuration limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/7df4f5a323c423b591ff3c35c7e66df40ff9c197\"\u003e\u003ccode\u003e7df4f5a\u003c/code\u003e\u003c/a\u003e Update link to CBF note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/bfd30c7aec222b66fb36629c20439bedb223d161\"\u003e\u003ccode\u003ebfd30c7\u003c/code\u003e\u003c/a\u003e lint: Apply pylint recos in FrameTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/e71a42bd424680b039b782de1392b0b7ec2307d9\"\u003e\u003ccode\u003ee71a42b\u003c/code\u003e\u003c/a\u003e lint: Fix pylint recos in ManipulabilityTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/a7ac5aa23b591fc203fbdc636d88c1a9b410375c\"\u003e\u003ccode\u003ea7ac5aa\u003c/code\u003e\u003c/a\u003e pixi: Group linting tasks, add format task\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/771c0e0a5d80107771525321927eebb28fbc3400\"\u003e\u003ccode\u003e771c0e0\u003c/code\u003e\u003c/a\u003e lint: Fix two pylint errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/f568e80536549a3b7f627468eb29526d3404c85b\"\u003e\u003ccode\u003ef568e80\u003c/code\u003e\u003c/a\u003e Update type of velocity_limit attribute\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/232c9c0b76db644c212c1e9caa33bda345cb4dd2\"\u003e\u003ccode\u003e232c9c0\u003c/code\u003e\u003c/a\u003e minor: Removed comes before Fixed in Keep a Changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/3b60614b5f25ed8c1ed0f1fc596ec19133665035\"\u003e\u003ccode\u003e3b60614\u003c/code\u003e\u003c/a\u003e Update the changelog\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/stephane-caron/pink/compare/v4.3.0...v4.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `reactivex` from 4.1.0 to 5.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/releases\"\u003ereactivex's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.1.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0rc2\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0a2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix title header by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/744\"\u003eReactiveX/RxPY#744\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0a1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGive run a scheduler parameter by \u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid use of asyncio.get_event_loop (3.14) by \u003ca href=\"https://github.com/traylenator\"\u003e\u003ccode\u003e@​traylenator\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/728\"\u003eReactiveX/RxPY#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to uv by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/738\"\u003eReactiveX/RxPY#738\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to ruff by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/739\"\u003eReactiveX/RxPY#739\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade pyright by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/740\"\u003eReactiveX/RxPY#740\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix subscribe_on not forwarding scheduler to the source  by \u003ca href=\"https://github.com/jcafhe\"\u003e\u003ccode\u003e@​jcafhe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/726\"\u003eReactiveX/RxPY#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade deps by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/741\"\u003eReactiveX/RxPY#741\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify what you can do with the .subscribe Disposable by \u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRxPY v5 by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/743\"\u003eReactiveX/RxPY#743\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003ereactivex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.1.0 - 2026-07-27\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Add tap as an alias for do_action (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/804\"\u003e#804\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/95c54ac3652aed2bf78035c9846cb5867ee58172\"\u003e95c54ac3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(gtk)\u003c/em\u003e Call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e2b9e3f33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Accept concurrent.futures.Future wherever futures are accepted (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/806\"\u003e#806\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e19da6ac1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(scheduler)\u003c/em\u003e Use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e361951c7\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd..b286407307ace6670f6f0072a8438bc912165d43\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(scripts)\u003c/em\u003e Keep uv.lock in sync and scope the version sed to [project] (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/802\"\u003e#802\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003e10ccc0a3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/915311e3e002b933f2eb4d59c9eac1cab327ff78..10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.2 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Reset retry budget per subscription to fix retry+repeat (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/765\"\u003e#765\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/c3f19d5e83403f70d44331daf0b5a86d410f76d4\"\u003ec3f19d5e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/2975deb528c9eec73c76cf8bb53fc8780f31de45..915311e3e002b933f2eb4d59c9eac1cab327ff78\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.1 - 2026-04-20\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/8b59bc7394f1b6a8a78e2fc4b5efe200d4f47f89..2975deb528c9eec73c76cf8bb53fc8780f31de45\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Added \u003ccode\u003eAction\u003c/code\u003e and \u003ccode\u003eStartableFactory\u003c/code\u003e to \u003ccode\u003ereactivex.typing.__all__\u003c/code\u003e,\nmaking them part of the explicit public API surface.\u003c/li\u003e\n\u003cli\u003eDocs: Added missing docstring to \u003ccode\u003eon_error_resume_next\u003c/code\u003e operator.\u003c/li\u003e\n\u003cli\u003eOperators: Fixed scheduler forwarding in \u003ccode\u003epairwise\u003c/code\u003e, \u003ccode\u003eto_marbles\u003c/code\u003e, and\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e (subscription-delay path). These operators now pass the\n\u003ccode\u003escheduler\u003c/code\u003e argument through to \u003ccode\u003esource.subscribe(...)\u003c/code\u003e and, in the case of\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e, to the subscription-delay observable, consistent with\nall other pipeable operators. Closes \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/480\"\u003e#480\u003c/a\u003e (partial — the operators listed\nin the issue that were not yet fixed).\u003c/li\u003e\n\u003cli\u003eCI: Skip \u003ccode\u003etests/test_scheduler/test_mainloop/test_tkinterscheduler.py\u003c/code\u003e on\nPyPy (all platforms). The module creates a Tk root at import time; PyPy's\n\u003ccode\u003e_tkinter\u003c/code\u003e finalizer calls \u003ccode\u003ethreading.notify_all\u003c/code\u003e during interpreter\nshutdown and aborts the xdist worker, failing whichever unrelated test\nwas running. Previously guarded only on macOS+PyPy.\u003c/li\u003e\n\u003cli\u003eFix: \u003ccode\u003ereactivex.timer(duetime, period)\u003c/code\u003e now correctly resets the initial\ndelay on each resubscription (e.g. via \u003ccode\u003erepeat()\u003c/code\u003e). Previously `nonlocal\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/bbfecfbf83605f2bb2beb8b887dfe5b5fb322a67\"\u003e\u003ccode\u003ebbfecfb\u003c/code\u003e\u003c/a\u003e chore: release reactivex@5.1.0 (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/805\"\u003e#805\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b286407307ace6670f6f0072a8438bc912165d43\"\u003e\u003ccode\u003eb286407\u003c/code\u003e\u003c/a\u003e docs: correct and expand the GIL free-threading note (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/811\"\u003e#811\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/93a4f0417fe5d1d187dbd2d0dfdf2ef3b481c45c\"\u003e\u003ccode\u003e93a4f04\u003c/code\u003e\u003c/a\u003e docs: explain how to parallelize work within a single stream (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/810\"\u003e#810\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2271867415d4beaed62e6f0441fd3312e47079aa\"\u003e\u003ccode\u003e2271867\u003c/code\u003e\u003c/a\u003e Revise GIL section for Python 3.13 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/742\"\u003e#742\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e\u003ccode\u003e361951c\u003c/code\u003e\u003c/a\u003e fix(scheduler): use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b809222be63e235f439f65794dd1d4291556d072\"\u003e\u003ccode\u003eb809222\u003c/code\u003e\u003c/a\u003e docs: read version from pyproject instead of git tags (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/808\"\u003e#808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19e808000610335b4f6d0e0c739b59372b8b5a5f\"\u003e\u003ccode\u003e19e8080\u003c/code\u003e\u003c/a\u003e ci(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/807\"\u003e#807\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/dd9b8ec0185ade72dcb3aac983cd495f21ca0a6d\"\u003e\u003ccode\u003edd9b8ec\u003c/code\u003e\u003c/a\u003e refactor(combine-latest): simplify logic by removing redundant loops … (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/736\"\u003e#736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e\u003ccode\u003e19da6ac\u003c/code\u003e\u003c/a\u003e fix(operators): accept concurrent.futures.Future wherever futures are accepte...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e\u003ccode\u003e2b9e3f3\u003c/code\u003e\u003c/a\u003e fix(gtk): call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.12.5 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 2026-05-06\u003c/h2\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.3 2026-04-20\u003c/h2\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.2 2026-04-17\u003c/h2\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.1 2026-04-15\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.4\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.3\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.2\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.1 (2026-04-15)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.12.5...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `packaging` from 25.0 to 26.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/releases\"\u003epackaging's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e26.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd a public \u003ccode\u003eVersionRange\u003c/code\u003e API and \u003ccode\u003eSpecifierSet.to_range()\u003c/code\u003e, representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. \u003ccode\u003eVersionRange.to_specifier_set()\u003c/code\u003e converts a range back to a \u003ccode\u003eSpecifierSet\u003c/code\u003e where a PEP 440 form exists. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1267\"\u003e#1267\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1270\"\u003e#1270\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1194\"\u003e#1194\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1220\"\u003e#1220\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer source distributions over wheels for selected packages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1334\"\u003e#1334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epure_python_tags()\u003c/code\u003e to generate the pure-Python tags for a Python version without touching the running platform. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eSpecifierSet.is_subset()\u003c/code\u003e, \u003ccode\u003eSpecifierSet.is_superset()\u003c/code\u003e, and \u003ccode\u003eSpecifierSet.is_disjoint()\u003c/code\u003e, which compare the versions two specifier sets accept. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1313\"\u003e#1313\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior adaptations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1157\"\u003e#1157\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e tags on Linux. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for versions and specifiers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a non-string. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1319\"\u003e#1319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to \u003ccode\u003eVersion.from_parts\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1241\"\u003e#1241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1242\"\u003e#1242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary intersections. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1257\"\u003e#1257\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for requirements and markers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for trailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and \u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in sets and dicts. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1232\"\u003e#1232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize requested extra names before comparing or hashing requirements. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/644\"\u003e#644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve a \u003ccode\u003eRequirement\u003c/code\u003e's specifier \u003ccode\u003eprereleases\u003c/code\u003e override across a pickle round trip. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1204\"\u003e#1204\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of \u003ccode\u003eInvalidSpecifier\u003c/code\u003e when a requirement contains an invalid specifier. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1332\"\u003e#1332\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eClarify the error for post-release prefix wildcards like \u003ccode\u003e==1.0.post1.*\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1299\"\u003e#1299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the parentheses of a nested group when serializing markers. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1316\"\u003e#1316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize \u003ccode\u003eextra\u003c/code\u003e and \u003ccode\u003edependency_groups\u003c/code\u003e values in nested markers at parse time. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1246\"\u003e#1246\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1310\"\u003e#1310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedComparison\u003c/code\u003e when a set-valued variable like \u003ccode\u003eextras\u003c/code\u003e is used outside the membership form. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedEnvironmentName\u003c/code\u003e (a \u003ccode\u003eKeyError\u003c/code\u003e subclass) for missing environment keys during marker evaluation. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1276\"\u003e#1276\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWrap malformed string literal errors in \u003ccode\u003eInvalidMarker\u003c/code\u003e / \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of leaking a low-level error. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1249\"\u003e#1249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject requirements and markers with a trailing line break. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1345\"\u003e#1345\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for metadata and licenses\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCollect all \u003ccode\u003efrom_email\u003c/code\u003e validation errors into one \u003ccode\u003eExceptionGroup\u003c/code\u003e instead of raising the first. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1268\"\u003e#1268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAccept the UTF-8 charset case-insensitively in email payloads. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1330\"\u003e#1330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject malformed \u003ccode\u003eDescription-Content-Type\u003c/code\u003e values. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1329\"\u003e#1329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't rewrite user values that contain \u003ccode\u003e{field}\u003c/code\u003e placeholders in error messages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1327\"\u003e#1327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRoute multipart email payloads to \u003ccode\u003eunparsed\u003c/code\u003e instead of asserting. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1247\"\u003e#1247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMake \u003ccode\u003eInvalidMetadata\u003c/code\u003e and \u003ccode\u003eCyclicDependencyGroup\u003c/code\u003e picklable. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1328\"\u003e#1328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFold every line boundary \u003ccode\u003estr.splitlines\u003c/code\u003e recognizes when writing a header with \u003ccode\u003eRFC822Message\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/blob/main/CHANGELOG.rst\"\u003epackaging's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e26.3 - 2026-08-03\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nFeatures:\n\u003cul\u003e\n\u003cli\u003eAdd a public :class:\u003ccode\u003e~packaging.ranges.VersionRange\u003c/code\u003e API and\u003cbr /\u003e\n:meth:\u003ccode\u003eSpecifierSet.to_range() \u0026amp;lt;packaging.specifiers.SpecifierSet.to_range\u0026amp;gt;\u003c/code\u003e,\u003cbr /\u003e\nrepresenting the versions a specifier set accepts as an interval set that\u003cbr /\u003e\nsupports intersection, union, difference, complement, set relations,\u003cbr /\u003e\nmembership tests, and filtering.\u003cbr /\u003e\n:meth:\u003ccode\u003e~packaging.ranges.VersionRange.to_specifier_set\u003c/code\u003e converts a range back\u003cbr /\u003e\nto a :class:\u003ccode\u003e~packaging.specifiers.SpecifierSet\u003c/code\u003e where a PEP 440 form exists.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1267\u003c/code\u003e, :pull:\u003ccode\u003e1270\u003c/code\u003e, :pull:\u003ccode\u003e1298\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (:pull:\u003ccode\u003e1194\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets.\u003cbr /\u003e\n(:issue:\u003ccode\u003e1220\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer\u003cbr /\u003e\nsource distributions over wheels for selected packages. (:pull:\u003ccode\u003e1334\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :func:\u003ccode\u003e~packaging.tags.pure_python_tags\u003c/code\u003e to generate the pure-Python\u003cbr /\u003e\ntags for a Python version without touching the running platform.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1346\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :meth:\u003ccode\u003eSpecifierSet.is_subset() \u0026amp;lt;packaging.specifiers.SpecifierSet.is_subset\u0026amp;gt;\u003c/code\u003e, :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_superset\u003c/code\u003e,\u003cbr /\u003e\nand :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_disjoint\u003c/code\u003e, which compare the\u003cbr /\u003e\nversions two specifier sets accept. (:pull:\u003ccode\u003e1313\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBehavior adaptations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1157\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e\u003cbr /\u003e\ntags on Linux. (:issue:\u003ccode\u003e160\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for versions and specifiers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a\u003cbr /\u003e\nnon-string. (:pull:\u003ccode\u003e1319\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to\u003cbr /\u003e\n\u003ccode\u003eVersion.from_parts\u003c/code\u003e. (:pull:\u003ccode\u003e1241\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1242\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary\u003cbr /\u003e\nintersections. (:pull:\u003ccode\u003e1257\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for requirements and markers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for\u003cbr /\u003e\ntrailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and\u003cbr /\u003e\n\u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in\u003cbr /\u003e\nsets and dicts. (:pull:\u003ccode\u003e1232\u003c/code\u003e)\u003cbr /\u003e\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/929fd4b1410ac7ef61ef3f45b2f5d7e87711a9b5\"\u003e\u003ccode\u003e929fd4b\u003c/code\u003e\u003c/a\u003e Bump for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f300ebf0c155e1f7ea6d62fba11dba4bac3d1944\"\u003e\u003ccode\u003ef300ebf\u003c/code\u003e\u003c/a\u003e chore(deps): bump the pre-commit group with 5 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1357\"\u003e#1357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f91d97566a966177ad7ea5a7c703b12a7273e3b1\"\u003e\u003ccode\u003ef91d975\u003c/code\u003e\u003c/a\u003e ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1361\"\u003e#1361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/b1a7124fe3d40c3302c029e9eb01ac3fc3496a54\"\u003e\u003ccode\u003eb1a7124\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 7 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1358\"\u003e#1358\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/2d873eb6002021a8c007c933fbdab58b37a5079b\"\u003e\u003ccode\u003e2d873eb\u003c/code\u003e\u003c/a\u003e fix(metadata): fold every line boundary when writing headers (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/413d006fadf5b9b14d78ad444201d8189bff8c64\"\u003e\u003ccode\u003e413d006\u003c/code\u003e\u003c/a\u003e docs: changelog for 26.3 (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1343\"\u003e#1343\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/4eb0753dba8fcaaac8eb75463374e448f0931558\"\u003e\u003ccode\u003e4eb0753\u003c/code\u003e\u003c/a\u003e docs(metadata): explain selective field validation (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1342\"\u003e#1342\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/77e9ed42b6db9c5c011a5148047a356ebe42692a\"\u003e\u003ccode\u003e77e9ed4\u003c/code\u003e\u003c/a\u003e feat(tags): add pure Python tag generator (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/7cea5e88671ed14016e9ab3dd08eab064f596564\"\u003e\u003ccode\u003e7cea5e8\u003c/code\u003e\u003c/a\u003e ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/45a8b3402db5ff82158f2d0eabaf8447aa7a50bf\"\u003e\u003ccode\u003e45a8b34\u003c/code\u003e\u003c/a\u003e docs: add missing versionadded/versionchanged directives (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1344\"\u003e#1344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/packaging/compare/25.0...26.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `filelock` from 3.23.0 to 3.32.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/py-filelock/releases\"\u003efilelock's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.32.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix(lease): reject a duration no marker can carry by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/723\"\u003etox-dev/filelock#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(soft-rw): reject non-finite timing options by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/724\"\u003etox-dev/filelock#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve exception notes when copying and pickling by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(soft-rw): reuse existing test module by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/730\"\u003etox-dev/filelock#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: respect ACL write access when the owner write bit is absent by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/728\"\u003etox-dev/filelock#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SoftReadWriteLock state lock timeout by \u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.5\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(fork): report where a stalled fork stops by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/715\"\u003etox-dev/filelock#715\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say that mode is read-only in the thread-local section by \u003ca href=\"https://github.com/Gares95\"\u003e\u003ccode\u003e@​Gares95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/716\"\u003etox-dev/filelock#716\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(lease): clear token after failed acquire by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.4\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix: retry transient denials on open and claim read by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/705\"\u003etox-dev/filelock#705\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: deflake six scheduled-run failures by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/704\"\u003etox-dev/filelock#704\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: cover a reclaimed private record for real by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/706\"\u003etox-dev/filelock#706\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test(fork): fork once the event loop has closed by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/714\"\u003etox-dev/filelock#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/713\"\u003etox-dev/filelock#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eescape the hostname every marker publishes by \u003ca href=\"https://github.com/dxbjavid\"\u003e\u003ccode\u003e@​dxbjavid\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/709\"\u003etox-dev/filelock#709\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(strict): deflake close-fault injections on graalpy by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/697\"\u003etox-dev/filelock#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📄 docs: publish llms.txt from the docs build by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/700\"\u003etox-dev/filelock#700\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst\"\u003efilelock's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e###########\nChangelog\n###########\u003c/p\u003e\n\u003cp\u003e.. towncrier-draft-entries:: Unreleased\u003c/p\u003e\n\u003cp\u003e.. towncrier release notes start\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.1 (2026-09-19)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epoll_interval\u003c/code\u003e is now validated at construction, on the setter, and on \u003ccode\u003eacquire()\u003c/code\u003e: a negative, non-finite, or\nnon-numeric value raises :class:\u003ccode\u003eValueError\u003c/code\u003e/:class:\u003ccode\u003eTypeError\u003c/code\u003e immediately instead of failing inside \u003ccode\u003etime.sleep\u003c/code\u003e. :pr:\u003ccode\u003e739\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.0 (2026-09-17)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eThe :class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e on-disk protocol is a generation log under \u003ccode\u003e\u0026lt;path\u0026gt;.rw\u003c/code\u003e, and a process\nrunning an earlier release does not see it: an old and a new participant on one lock path do not exclude each\nother. Stop every participant, upgrade them all, then restart them; the new code ignores leftover \u003ccode\u003e.state\u003c/code\u003e,\n\u003ccode\u003e.write\u003c/code\u003e and \u003ccode\u003e.readers/\u003c/code\u003e files, and you can delete them. The filesystem must provide no-replace hard links, as\nit must for :class:\u003ccode\u003e~filelock.StrictSoftFileLock\u003c/code\u003e, so a runtime without \u003ccode\u003eos.link\u003c/code\u003e raises\n:class:\u003ccode\u003e~filelock.SoftFileLockProtocolError\u003c/code\u003e on acquire. Constructing a singleton again with a different\n\u003ccode\u003eon_compromise\u003c/code\u003e, or with \u003ccode\u003epoll_interval\u003c/code\u003e at or above \u003ccode\u003estale_threshold\u003c/code\u003e, now raises :class:\u003ccode\u003eValueError\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e exposes :attr:\u003ccode\u003e~filelock.SoftReadWriteLock.generation\u003c/code\u003e as a fencing token for\nthe protected resource and reports a lost hold through \u003ccode\u003eon_compromise\u003c/code\u003e and\n:attr:\u003ccode\u003e~filelock.SoftReadWriteLock.compromise\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e no longer deadlocks when a holder dies on another host mid-transition, and\n\u003ccode\u003erelease()\u003c/code\u003e no longer waits on a mutex a dead host left behind (:pr:\u003ccode\u003e725\u003c/code\u003e, :pr:\u003ccode\u003e735\u003c/code\u003e). The state mutex is gone.\nEach transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock\nrather than an \u003ccode\u003emtime\u003c/code\u003e read against another host's. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.7 (2026-09-16)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eValidate final-symlink refusal by error number so the test works across libc implementations. :pr:\u003ccode\u003e737\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocument that :meth:\u003ccode\u003e~filelock.BaseFileLock.acquire\u003c/code\u003e reads \u003ccode\u003eblocking=None\u003c/code\u003e as the lock's \u003ccode\u003eblocking\u003c/code\u003e attribute and\nraises :class:\u003ccode\u003e~filelock.Timeout\u003c/code\u003e after one attempt when \u003ccode\u003eblocking=False\u003c/code\u003e. :pr:\u003ccode\u003e733\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.6 (2026-09-08)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSoftFileLease\u003c/code\u003e and \u003ccode\u003eAsyncSoftFileLease\u003c/code\u003e now reject a boolean or non-finite \u003ccode\u003elease_duration\u003c/code\u003e, which used to\npublish an owner record their own \u003ccode\u003eowner\u003c/code\u003e property reads back as malformed. :pr:\u003ccode\u003e723\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eReject non-finite heartbeat, stale, and polling intervals in \u003ccode\u003eSoftReadWriteLock\u003c/code\u003e and \u003ccode\u003eAsyncSoftReadWriteLock\u003c/code\u003e,\nincluding cached singleton construction and overflow in the default stale threshold. :pr:\u003ccode\u003e724\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d\"\u003e\u003ccode\u003e4efd93e\u003c/code\u003e\u003c/a\u003e Release 3.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1\"\u003e\u003ccode\u003e7b7b7a8\u003c/code\u003e\u003c/a\u003e Fix SoftReadWriteLock state lock timeout (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2\"\u003e\u003ccode\u003ef2f7b86\u003c/code\u003e\u003c/a\u003e fix: respect ACL write access when the owner write bit is absent (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153\"\u003e\u003ccode\u003ee947a69\u003c/code\u003e\u003c/a\u003e test(soft-rw): reuse existing test module (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88\"\u003e\u003ccode\u003eda3ae2b\u003c/code\u003e\u003c/a\u003e fix: preserve exception notes when copying and pickling (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812\"\u003e\u003ccode\u003eae9cb5b\u003c/code\u003e\u003c/a\u003e 🐛 fix(soft-rw): reject non-finite timing options (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/d00f9bbd709fbe92a99a38cb1e32b6690813e5a8\"\u003e\u003ccode\u003ed00f9bb\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/727\"\u003e#727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/82f66d7b0aaa83755f8d71d0b0da88408b58ec4a\"\u003e\u003ccode\u003e82f66d7\u003c/code\u003e\u003c/a\u003e 🐛 fix(lease): reject a duration no marker can carry (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1d9e9e7e43a1089c57d7c6f20d6a2268235a4745\"\u003e\u003ccode\u003e1d9e9e7\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/722\"\u003e#722\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9\"\u003e\u003ccode\u003e1585dfe\u003c/code\u003e\u003c/a\u003e Release 3.32.5\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tox-dev/py-filelock/compare/3.23.0...3.32.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `plum-dispatch` from 2.5.7 to 2.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beartype/plum/releases\"\u003eplum-dispatch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOptimise \u003ccode\u003e_wrap_type_hint\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/310\"\u003e#310\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eBuild macOS arm64 mypyc wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/320\"\u003e#320\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/beartype/plum/issues/317\"\u003e#317\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/318\"\u003e#318\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCompile more things with \u003ccode\u003emypyc\u003c/code\u003e for faster dispatch (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/287\"\u003e#287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/beartype/plum/issues/288\"\u003e#288\u003c/a\u003e, and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/289\"\u003e#289\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake concurrent dispatch resolution thread safe (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/281\"\u003e#281\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix support for \u003ccode\u003ebeartype\u0026gt;=0.23\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/296\"\u003e#296\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove typing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/268\"\u003e#268\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove \u003ccode\u003eVal\u003c/code\u003e, which was deprecated in v0.5.0 in favour of \u003ccode\u003etyping.Literal\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/269\"\u003e#269\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport union aliases in Python 3.14 and later (\u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.0\u003c/h2\u003e\n\u003cp\u003eStarting this release, Plum will be available on PyPI as both \u003ccode\u003eplum-dispatch\u003c/code\u003e and \u003ccode\u003eplum\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003ev2.7.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003efaithful\u003c/code\u003e keyword to \u003ccode\u003eModuleType\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e All imports should now go through \u003ccode\u003eplum\u003c/code\u003e directly! That is, not \u003ccode\u003eplum.signature.Signature\u003c/code\u003e, but \u003ccode\u003eplum.Signature\u003c/code\u003e. Please do open an issue if this release breaks something that shouldn't break.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSignificantly improve typing of the internals (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/179\"\u003e#179\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/242\"\u003e#242\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003euv\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/218\"\u003e#218\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake modules private for public/private separation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/241\"\u003e#241\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003esrc\u003c/code\u003e layout (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/249\"\u003e#249\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove config (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/248\"\u003e#248\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003emypyc\u003c/code\u003e builds for better performance (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/247\"\u003e#247\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e)!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.6.1\u003c/h2\u003e\n\u003cp\u003eThis release features numerous very helpful contributions and improvements by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse dependency groups (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/195\"\u003e#195\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTreat \u003ccode\u003etyping_extensions\u003c/code\u003e as standard library and make more use of it (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/226\"\u003e#226\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/232\"\u003e#232\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eComplete deprecation cycles (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/230\"\u003e#230\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/236\"\u003e#236\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTurn various arguments into positional-only (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/229\"\u003e#229\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove unnecessary path manipulation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/233\"\u003e#233\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRework tests with a \u003ccode\u003edispatch\u003c/code\u003e fixture (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/234\"\u003e#234\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAvoid using a deprecated NumPy module (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/231\"\u003e#231\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDrops support for Python 3.9 (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImport exports from \u003ccode\u003emethods.py\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/237\"\u003e#237\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixes an incorrect \u003ccode\u003eoverload\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/238\"\u003e#238\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003enox\u003c/code\u003e for testing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/235\"\u003e#235\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/240\"\u003e#240\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e also fixes an important bug to do with the handling of unions (CC \u003ca href=\"https://github.com/davidwyld\"\u003e\u003ccode\u003e@​davidwyld\u003c/code\u003e\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beartype/plum/commit/c835c8cf5ebea4f00ee304a647e026739034e63b\"\u003e\u003ccode\u003ec835c8c\u003c/code\u003e\u003c/a\u003e fix(mypyc): keep \u003ccode\u003eFunction\u003c/code\u003e weak-referenceable on the compiled wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c...\n\n_Description has been truncated_","html_url":"https://github.com/dimensionalOS/dimos/pull/4260","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dimensionalOS%2Fdimos/issues/4260","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4260/packages"}},{"old_version":"5.15.0","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-22T01:41:11.000Z","version_change":"5.15.0 → 5.17.0","issue":{"uuid":"5534319114","node_id":"PR_kwDOS8i2VM8AAAABEgrTaA","number":119,"state":"open","title":"Bump the minor-update group with 191 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T01:41:11.000Z","updated_at":"2026-09-22T01:41:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":191,"packages":[{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.28.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"mcp","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"tpu-inference","old_version":"0.28.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"fastsafetensors","old_version":"0.3.3","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.2","new_version":"4.7.1","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.9","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.11.1","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpcore2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"httpx2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.19","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mcp-types","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.0","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.10","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.2","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.4","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.13.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 191 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.28.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.28.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.3` | `0.4.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.2` | `4.7.1` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.9` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.11.1` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mcp-types](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.0` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.10` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.2` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.4` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.13.0.0` | `2.14.0.0` |\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.28.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.28.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/iss...\n\n_Description has been truncated_","html_url":"https://github.com/yhfgyyf/vllm-deepseek-v4-sm89/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/yhfgyyf%2Fvllm-deepseek-v4-sm89/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"}},{"old_version":"4.56.2","new_version":"5.10.1","update_type":"major","path":null,"pr_created_at":"2026-09-21T20:06:35.000Z","version_change":"4.56.2 → 5.10.1","issue":{"uuid":"5531897537","node_id":"PR_kwDOS3rmoM8AAAABEev6_Q","number":2,"state":"closed","title":"Bump the pip group across 1 directory with 6 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-21T20:07:30.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-21T20:06:35.000Z","updated_at":"2026-09-21T20:07:32.000Z","time_to_close":55,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":6,"packages":[{"name":"setuptools","old_version":"59.6.0","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"wheel","old_version":"0.45.1","new_version":"0.46.2","repository_url":"https://github.com/pypa/wheel"},{"name":"accelerate","old_version":"1.10.1","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"torch","old_version":"2.8.0","new_version":"2.13.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"4.56.2","new_version":"5.10.1","repository_url":"https://github.com/huggingface/transformers"},{"name":"pytest","old_version":"8.4.2","new_version":"9.0.3","repository_url":"https://github.com/pytest-dev/pytest"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 6 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [setuptools](https://github.com/pypa/setuptools) | `59.6.0` | `83.0.0` |\n| [wheel](https://github.com/pypa/wheel) | `0.45.1` | `0.46.2` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.10.1` | `1.15.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.8.0` | `2.13.0` |\n| [transformers](https://github.com/huggingface/transformers) | `4.56.2` | `5.10.1` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.4.2` | `9.0.3` |\n\n\nUpdates `setuptools` from 59.6.0 to 83.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/setuptools/blob/main/NEWS.rst\"\u003esetuptools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev83.0.0\u003c/h1\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRequire Python 3.10 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eMANIFEST.in\u003c/code\u003e matching (via \u003ccode\u003eFileList\u003c/code\u003e) is now insensitive to Unicode\nnormalization form. A pattern authored in one form (e.g. NFC, as typically\nsaved by editors) now matches a file whose name is stored on disk in another\n(e.g. NFD, as produced by macOS APFS/HFS+). Previously an \u003ccode\u003eexclude\u003c/code\u003e,\n\u003ccode\u003eglobal-exclude\u003c/code\u003e, \u003ccode\u003erecursive-exclude\u003c/code\u003e, or \u003ccode\u003eprune\u003c/code\u003e rule could silently\nfail to drop a non-ASCII-named file from the source distribution, publishing\nit despite the exclusion -- see GHSA-h35f-9h28-mq5c.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epypa/distutils#334\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ev82.0.1\u003c/h1\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix the loading of \u003ccode\u003elauncher manifest.xml\u003c/code\u003e file. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5047\"\u003e#5047\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaced deprecated \u003ccode\u003ejson.__version__\u003c/code\u003e with fixture in tests. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5186\"\u003e#5186\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd advice about how to improve predictability when installing sdists. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5168\"\u003e#5168\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/4941\"\u003e#4941\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5157\"\u003e#5157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5169\"\u003e#5169\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5175\"\u003e#5175\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ev82.0.0\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/6519f728c6f23c992df81a5691ef7655184a20eb\"\u003e\u003ccode\u003e6519f72\u003c/code\u003e\u003c/a\u003e Bump version: 82.0.1 → 83.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/d1151b125b29a6ee1c7db860f7ee6c365d525b5f\"\u003e\u003ccode\u003ed1151b1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5250\"\u003e#5250\u003c/a\u003e from pypa/feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2df31e6a741b0fe775969618fe6a3a3d032e900\"\u003e\u003ccode\u003ea2df31e\u003c/code\u003e\u003c/a\u003e Capture removal of dry_run parameter in changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/00144dc3fb6d023fd81cdc26c380a012b084df9b\"\u003e\u003ccode\u003e00144dc\u003c/code\u003e\u003c/a\u003e Moved newsfragment to the release where it occurred.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a4a5a2b160357be77626aa077ddd1d8ee53be50f\"\u003e\u003ccode\u003ea4a5a2b\u003c/code\u003e\u003c/a\u003e Add news fragment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/77470c23c35031c9e37d7512694ac5ca52bfcaac\"\u003e\u003ccode\u003e77470c2\u003c/code\u003e\u003c/a\u003e Merge \u003ca href=\"https://github.com/pypa/distutils\"\u003ehttps://github.com/pypa/distutils\u003c/a\u003e into feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/3c43897420f25a1be1afe6eaa905d056009cc736\"\u003e\u003ccode\u003e3c43897\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5247\"\u003e#5247\u003c/a\u003e from pypa/copilot/fix-pypy-version-issue\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/bb6ea66b4bd01cb35d7c68a1bc61b96d59190269\"\u003e\u003ccode\u003ebb6ea66\u003c/code\u003e\u003c/a\u003e Bump PyPy from 3.10 to 3.11 in CI workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2bc3aca2f55eb9b93ea633e58ba68170ce14451\"\u003e\u003ccode\u003ea2bc3ac\u003c/code\u003e\u003c/a\u003e Fix broken intersphinx reference to build's installation docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/2d6a739c64cfedc65e1f635af7b52340aac8d99b\"\u003e\u003ccode\u003e2d6a739\u003c/code\u003e\u003c/a\u003e Use stacked parametrize decorators instead of itertools.product\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/setuptools/compare/v59.6.0...v83.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `wheel` from 0.45.1 to 0.46.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/wheel/releases\"\u003ewheel's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.46.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestored the \u003ccode\u003ebdist_wheel\u003c/code\u003e command for compatibility with \u003ccode\u003esetuptools\u003c/code\u003e older than v70.1\u003c/li\u003e\n\u003cli\u003eImporting \u003ccode\u003ewheel.bdist_wheel\u003c/code\u003e now emits a \u003ccode\u003eFutureWarning\u003c/code\u003e instead of a \u003ccode\u003eDeprecationWarning\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel unpack\u003c/code\u003e potentially altering the permissions of files outside of the destination tree with maliciously crafted wheels (CVE-2026-24049)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.46.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTemporarily restored the \u003ccode\u003ewheel.macosx_libfile\u003c/code\u003e module (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/659\"\u003e#659\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.46.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.8\u003c/li\u003e\n\u003cli\u003eRemoved the \u003ccode\u003ebdist_wheel\u003c/code\u003e setuptools command implementation and entry point. The \u003ccode\u003ewheel.bdist_wheel\u003c/code\u003e module is now just an alias to \u003ccode\u003esetuptools.command.bdist_wheel\u003c/code\u003e, emitting a deprecation warning on import.\u003c/li\u003e\n\u003cli\u003eRemoved vendored \u003ccode\u003epackaging\u003c/code\u003e in favor of a run-time dependency on it\u003c/li\u003e\n\u003cli\u003eMade the \u003ccode\u003ewheel.metadata\u003c/code\u003e module private (with a deprecation warning if it's imported\u003c/li\u003e\n\u003cli\u003eMade the \u003ccode\u003ewheel.cli\u003c/code\u003e package private (no deprecation warning)\u003c/li\u003e\n\u003cli\u003eFixed an exception when calling the \u003ccode\u003econvert\u003c/code\u003e command with an empty description field\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/wheel/blob/main/docs/news.rst\"\u003ewheel's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease Notes\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eUNRELEASED\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel pack --build-number\u003c/code\u003e accepting build tags that are invalid in a\nwheel file name (not starting with a digit, or containing \u003ccode\u003e-\u003c/code\u003e), the same\nvalidation \u003ccode\u003ewheel tags --build\u003c/code\u003e already performs\u003c/li\u003e\n\u003cli\u003eFixed the macOS platform-tag warning always using the plural \u0026quot;these files\u0026quot;\nwording, even when only a single library required a higher deployment target\n(\u003ccode\u003e[#697](https://github.com/pypa/wheel/issues/697) \u0026lt;https://github.com/pypa/wheel/pull/697\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.48.0 (2026-08-12)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003e--local-version\u003c/code\u003e option to \u003ccode\u003ewheel pack\u003c/code\u003e to add, replace, or remove a\nPEP 440 local version identifier from a wheel\n(\u003ccode\u003e[#570](https://github.com/pypa/wheel/issues/570) \u0026lt;https://github.com/pypa/wheel/issues/570\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel convert\u003c/code\u003e unnecessarily upgrading compatible core metadata versions\n(\u003ccode\u003e[#643](https://github.com/pypa/wheel/issues/643) \u0026lt;https://github.com/pypa/wheel/issues/643\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel tags\u003c/code\u003e producing invalid archives when retagging wheels whose\nentries use ZIP64, by dropping the central-directory ZIP64 extra field that is\nnot valid in a local file header\n(\u003ccode\u003e[#692](https://github.com/pypa/wheel/issues/692) \u0026lt;https://github.com/pypa/wheel/issues/692\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel convert\u003c/code\u003e writing the converted wheel outside the destination\ndirectory when the input archive contained a maliciously crafted project name\nor version with path separators (arbitrary file write / path traversal)\n(\u003ccode\u003eGHSA-vgq5-9859-3mmw \u0026lt;https://github.com/pypa/wheel/security/advisories/GHSA-vgq5-9859-3mmw\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.47.0 (2026-04-22)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded the \u003ccode\u003ewheel info\u003c/code\u003e subcommand to display metadata about wheel files without\nunpacking them (\u003ccode\u003e[#639](https://github.com/pypa/wheel/issues/639) \u0026lt;https://github.com/pypa/wheel/issues/639\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eWheelFile\u003c/code\u003e raising \u003ccode\u003eMissing RECORD file\u003c/code\u003e when the wheel filename contains\nuppercase characters (e.g. \u003ccode\u003eDjango-3.2.5.whl\u003c/code\u003e) but the \u003ccode\u003e.dist-info\u003c/code\u003e directory\ninside uses normalized lowercase naming\n(\u003ccode\u003e[#411](https://github.com/pypa/wheel/issues/411) \u0026lt;https://github.com/pypa/wheel/issues/411\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.46.3 (2026-01-22)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eImportError: cannot import name '_setuptools_logging' from 'wheel'\u003c/code\u003e when\ninstalled alongside an old version of setuptools and running the \u003ccode\u003ebdist_wheel\u003c/code\u003e\ncommand (\u003ccode\u003e[#676](https://github.com/pypa/wheel/issues/676) \u0026lt;https://github.com/pypa/wheel/issues/676\u0026gt;\u003c/code\u003e_)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e0.46.2 (2026-01-22)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRestored the \u003ccode\u003ebdist_wheel\u003c/code\u003e command for compatibility with \u003ccode\u003esetuptools\u003c/code\u003e older than\nv70.1\u003c/li\u003e\n\u003cli\u003eImporting \u003ccode\u003ewheel.bdist_wheel\u003c/code\u003e now emits a \u003ccode\u003eFutureWarning\u003c/code\u003e instead of a\n\u003ccode\u003eDeprecationWarning\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003ewheel unpack\u003c/code\u003e potentially altering the permissions of files outside of the\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/eba4036ccaca4e2d0c5b5bf3e3be59b2b2877d6b\"\u003e\u003ccode\u003eeba4036\u003c/code\u003e\u003c/a\u003e Updated the version number for v0.46.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/557fb5425036ccca95330b2c8875e54c9f4483cf\"\u003e\u003ccode\u003e557fb54\u003c/code\u003e\u003c/a\u003e Created a new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef\"\u003e\u003ccode\u003e7a7d2de\u003c/code\u003e\u003c/a\u003e Fixed security issue around wheel unpack (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/675\"\u003e#675\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/41418fac233d6973ea8798d620df4aa5b3aa1b66\"\u003e\u003ccode\u003e41418fa\u003c/code\u003e\u003c/a\u003e Fixed test failures due to metadata normalization changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/c1d442bec6c634fcfb89e5d58698dd226685bd14\"\u003e\u003ccode\u003ec1d442b\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/674\"\u003e#674\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/0bac8820ec90b1aaa0695d79a56563137b48686d\"\u003e\u003ccode\u003e0bac882\u003c/code\u003e\u003c/a\u003e Update github actions environments (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/673\"\u003e#673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/be9f45b4ee1210b2a815d2eefea56b71efd99d63\"\u003e\u003ccode\u003ebe9f45b\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/667\"\u003e#667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/6244f08bb92d7569da6c2fbea23de0846ad34ff3\"\u003e\u003ccode\u003e6244f08\u003c/code\u003e\u003c/a\u003e Update pre-commit ruff legacy alias (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/668\"\u003e#668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/15b7577654e8bcd23e009c6bac036b65c11d8d8f\"\u003e\u003ccode\u003e15b7577\u003c/code\u003e\u003c/a\u003e PEP 639 compliance (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/670\"\u003e#670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/wheel/commit/fc8cb4163e4f48d86092cb2a16076f1b3efcd10f\"\u003e\u003ccode\u003efc8cb41\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Removed redundant Python version from the publish workflow (\u003ca href=\"https://redirect.github.com/pypa/wheel/issues/666\"\u003e#666\u003c/a\u003e)\u0026quot;\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/wheel/compare/0.45.1...0.46.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.10.1 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/6afc1e5ee217051fde702b23de2813344dc0fd33\"\u003e\u003ccode\u003e6afc1e5\u003c/code\u003e\u003c/a\u003e Release: v1.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/636a9343b4265db1212b04c778b8910b5cbfa713\"\u003e\u003ccode\u003e636a934\u003c/code\u003e\u003c/a\u003e Fix nightly CI: tensor parallel size detection and DeepSpeed warmup steps (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/385d9fb40bdb92b0cb34775ad0ef493c171e559f\"\u003e\u003ccode\u003e385d9fb\u003c/code\u003e\u003c/a\u003e docs: fix three dead links left by the docs restructure (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4230\"\u003e#4230\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/c424d0b82d4ed61672bf30f1a81ce80370fd945a\"\u003e\u003ccode\u003ec424d0b\u003c/code\u003e\u003c/a\u003e docs: fix garbled sentence in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4231\"\u003e#4231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/0f7e35fe7902cc6ba8dc01b146d6447900464b88\"\u003e\u003ccode\u003e0f7e35f\u003c/code\u003e\u003c/a\u003e Clip grad norm support for dtensors (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/b2ac5095f04585043e21d295afe3aaaacdcc8357\"\u003e\u003ccode\u003eb2ac509\u003c/code\u003e\u003c/a\u003e Fix FSDP2/ PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/33e8bc499254e7f3886db3f8a277d05a4ad2667e\"\u003e\u003ccode\u003e33e8bc4\u003c/code\u003e\u003c/a\u003e Fix load_accelerator_state only restoring one RNG backend (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4217\"\u003e#4217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/50de3ad45f4da279819529e443ba746eb5b3b187\"\u003e\u003ccode\u003e50de3ad\u003c/code\u003e\u003c/a\u003e Treat MPS out-of-memory errors as OOM in find_executable_batch_size (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4227\"\u003e#4227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/ab5fe8e507366f814fee59138eb96b9879cb05d6\"\u003e\u003ccode\u003eab5fe8e\u003c/code\u003e\u003c/a\u003e feat: add the neuron device branch in state (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4218\"\u003e#4218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/9baf95be958c3fd8b2449d1463e6a89e14f61e7d\"\u003e\u003ccode\u003e9baf95b\u003c/code\u003e\u003c/a\u003e Fix MLFLOW_NESTED_RUN never being able to turn nesting off (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4223\"\u003e#4223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/accelerate/compare/v1.10.1...v1.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.8.0 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.13.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eTracked Regressions\u003c/h1\u003e\n\u003ch3\u003eROCm wheels break \u003ccode\u003etorch.compile\u003c/code\u003e on CPU in environments without a GPU\u003c/h3\u003e\n\u003cp\u003eRunning a \u003ccode\u003etorch==2.13.0+rocm7.2\u003c/code\u003e wheel in an environment where no GPU is available (\u003ccode\u003etorch.cuda.is_available()\u003c/code\u003e is \u003ccode\u003eFalse\u003c/code\u003e) breaks \u003ccode\u003etorch.compile\u003c/code\u003e on the CPU path: the first compile raises \u003ccode\u003eRuntimeError: Can't detect vectorized ISA for CPU\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/189194\"\u003e#189194\u003c/a\u003e). This is a regression from \u003ccode\u003etorch==2.12.1+rocm7.2\u003c/code\u003e, which compiles CPU code fine (detecting e.g. \u003ccode\u003eVecAVX2\u003c/code\u003e) in the same setup. The 2.13 ROCm wheel appears to rely on something present in the ROCm builder image to detect the CPU vectorized ISA, so it works when run on a ROCm image but fails on a plain CPU-only image.\u003c/p\u003e\n\u003cp\u003eWorkaround: run the \u003ccode\u003e+rocm\u003c/code\u003e wheel on a ROCm image, or install a standard CPU/CUDA build for GPU-less environments.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eStop building CPython 3.13t (free-threaded) binaries (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/182951\"\u003e#182951\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eUpstream \u003ccode\u003epypa/manylinux\u003c/code\u003e removed CPython 3.13t (free-threaded) on 2026-05-07, because 3.13t\nwas experimental and has been superseded by the now-non-experimental CPython 3.14t. As a result,\nPyTorch 2.13 no longer ships \u003ccode\u003ecp313t\u003c/code\u003e wheels (Linux, Triton, and related artifacts). Users on the\nfree-threaded interpreter should move to Python 3.14t.\u003c/p\u003e\n\u003cp\u003ePyTorch 2.12:\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003e# cp313t (free-threaded 3.13) wheels were available\r\npython3.13t -m pip install torch\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003ePyTorch 2.13:\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/cf30153c4c131c8164ee7798e5022d810682e2cb\"\u003e\u003ccode\u003ecf30153\u003c/code\u003e\u003c/a\u003e [release/2.13] Strip +PTX from CUDA arch list on release/RC builds (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188914\"\u003e#188914\u003c/a\u003e) ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/3e3e24bd95b010f8f74915f0c30476906e60d4fc\"\u003e\u003ccode\u003e3e3e24b\u003c/code\u003e\u003c/a\u003e [release/2.13] Restrict cuda-bindings to Python \u0026lt; 3.15 for CUDA 12.9 builds (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/7986b068032abf5e22ea51fe7fea63ef5bcaf3b1\"\u003e\u003ccode\u003e7986b06\u003c/code\u003e\u003c/a\u003e [release/2.13] Bump binary build timeout 280 -\u0026gt; 400 minutes (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188551\"\u003e#188551\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/0bdbc268e08fba9debac8f35a8a12e9c008ec0fd\"\u003e\u003ccode\u003e0bdbc26\u003c/code\u003e\u003c/a\u003e [release/2.13] Add CUDA 12.9 to TORCH_CUDA_ARCH_LIST tables (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188443\"\u003e#188443\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/9cabb45ca6e6ed3bb4645c929bcfd07691651f74\"\u003e\u003ccode\u003e9cabb45\u003c/code\u003e\u003c/a\u003e [release/2.13] Update manywheel docker image pin to 78e737ad (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188409\"\u003e#188409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/78e737ad29420ffc4800e677c51e2a852caf8359\"\u003e\u003ccode\u003e78e737a\u003c/code\u003e\u003c/a\u003e [release/2.13] Revert \u0026quot;Tighten generalized scatter graph target (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/184075\"\u003e#184075\u003c/a\u003e)\u0026quot; (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/0bb9b5bc24bed3278488372d62d9f2235e9e77e3\"\u003e\u003ccode\u003e0bb9b5b\u003c/code\u003e\u003c/a\u003e [release/2.13] Revert \u0026quot;dynamo: round-trip torch.cuda.stream ctx mgr across gr...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/aaac2bfe460c04a4d41e83e03452d2347f7142b9\"\u003e\u003ccode\u003eaaac2bf\u003c/code\u003e\u003c/a\u003e [release/2.13] Revert \u0026quot;[Reland] Port D104346887/PR 182675 for index_add fast ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/933081368c3ab64fa2e953217e413b3ba52844e3\"\u003e\u003ccode\u003e9330813\u003c/code\u003e\u003c/a\u003e Fix build_with_debinfo.py broken by CONFIGURE_DEPENDS globbing (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188192\"\u003e#188192\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/4e077a7dcf29167db9e97d86cc62f431905e09f7\"\u003e\u003ccode\u003e4e077a7\u003c/code\u003e\u003c/a\u003e Remove setuptools upper bound (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188190\"\u003e#188190\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pytorch/pytorch/compare/v2.8.0...v2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 4.56.2 to 5.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v5.10.1\u003c/h1\u003e\n\u003cp\u003ev5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!\u003c/p\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eGemma4 unified+ Gemma4 MTP\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eGemma 4 12B Unified is an \u003cstrong\u003eencoder-free\u003c/strong\u003e multimodal model with pretrained and instruction-tuned variants. Unlike \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gemma4\"\u003estandard Gemma 4\u003c/a\u003e, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.\u003c/p\u003e\n\u003cp\u003eKey differences from standard Gemma 4:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo Vision Tower\u003c/strong\u003e: Raw pixel patches are projected directly into LM space via a \u003ccode\u003eDense + LayerNorm\u003c/code\u003e pipeline with factorized 2D positional embeddings, replacing the vision encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNo Audio Tower\u003c/strong\u003e: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple \u003ccode\u003eRMSNorm → Linear\u003c/code\u003e pipeline, replacing the mel spectrogram + Conformer encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eShared Multimodal Pipeline\u003c/strong\u003e: Both vision and audio use the same \u003ccode\u003eGemma4UnifiedMultimodalEmbedder\u003c/code\u003e (RMSNorm → Linear) for the final projection to text hidden space.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou can find the original Gemma 4 12B Unified checkpoints under the \u003ca href=\"https://huggingface.co/collections/google/gemma-4\"\u003eGemma 4\u003c/a\u003e release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewho needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e) by \u003ca href=\"https://github.com/douglas-reid\"\u003e\u003ccode\u003e@​douglas-reid\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/sgerrard\"\u003e\u003ccode\u003e@​sgerrard\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/vasqu\"\u003e\u003ccode\u003e@​vasqu\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/molbap\"\u003e\u003ccode\u003e@​molbap\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSapiens2\u003c/h3\u003e\n\u003cp\u003eSapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2\"\u003eDocumentation\u003c/a\u003e | \u003ca href=\"https://huggingface.co/papers/2604.21681\"\u003ePaper\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e) by \u003ca href=\"https://github.com/guarin\"\u003e\u003ccode\u003e@​guarin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45919\"\u003e#45919\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDeepSeek-OCR-2\u003c/h3\u003e\n\u003cp\u003eDeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Deepseek-OCR-2 model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45075\"\u003e#45075\u003c/a\u003e) by \u003ca href=\"https://github.com/thisisiron\"\u003e\u003ccode\u003e@​thisisiron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45075\"\u003e#45075\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMellum\u003c/h3\u003e\n\u003cp\u003eMellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/mellum\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Add support for JetBrains' \u003ccode\u003eMellum\u003c/code\u003e v2 code generation model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46112\"\u003e#46112\u003c/a\u003e) by \u003ca href=\"https://github.com/shadeMe\"\u003e\u003ccode\u003e@​shadeMe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/46112\"\u003e#46112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBreaking changes\u003c/h2\u003e\n\u003cp\u003eThe Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 Fix float16 overflow in Gemma4 vision pooler (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46277\"\u003e#46277\u003c/a\u003e) by \u003ca href=\"https://github.com/Bluear7878\"\u003e\u003ccode\u003e@​Bluear7878\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAudio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 [ALM] Add base model without head (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45534\"\u003e#45534\u003c/a\u003e) by \u003ca href=\"https://github.com/eustlb\"\u003e\u003ccode\u003e@​eustlb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d\"\u003e\u003ccode\u003e90c3ae5\u003c/code\u003e\u003c/a\u003e Patch because we had to yank 5.10 because the release branch was not up to date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968\"\u003e\u003ccode\u003e0bd94b3\u003c/code\u003e\u003c/a\u003e v5.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897\"\u003e\u003ccode\u003e1423d22\u003c/code\u003e\u003c/a\u003e who needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98\"\u003e\u003ccode\u003e50eb20a\u003c/code\u003e\u003c/a\u003e Fix dsv4 dequant + tp/ep (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46378\"\u003e#46378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299\"\u003e\u003ccode\u003e74464e8\u003c/code\u003e\u003c/a\u003e Fix wrong changes produced by style/repo. check bot (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46371\"\u003e#46371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc\"\u003e\u003ccode\u003e1b8ec34\u003c/code\u003e\u003c/a\u003e Fix path traversal when saving Bark voice preset embeddings (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46237\"\u003e#46237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872\"\u003e\u003ccode\u003ee820678\u003c/code\u003e\u003c/a\u003e Add Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43\"\u003e\u003ccode\u003e595721c\u003c/code\u003e\u003c/a\u003e Pass library_name/version to Hub calls via a shared HfApi (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46318\"\u003e#46318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a\"\u003e\u003ccode\u003e0f0036c\u003c/code\u003e\u003c/a\u003e docs: update ACL Anthology URL in CITATION.cff (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46352\"\u003e#46352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353\"\u003e\u003ccode\u003efa6c830\u003c/code\u003e\u003c/a\u003e DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45634\"\u003e#45634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.56.2...v5.10.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pytest` from 8.4.2 to 9.0.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytest-dev/pytest/releases\"\u003epytest's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.0.3\u003c/h2\u003e\n\u003ch1\u003epytest 9.0.3 (2026-04-07)\u003c/h1\u003e\n\u003ch2\u003eBug fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/12444\"\u003e#12444\u003c/a\u003e: Fixed \u003ccode\u003epytest.approx\u003c/code\u003e which now correctly takes into account \u003ccode\u003e~collections.abc.Mapping\u003c/code\u003e keys order to compare them.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13634\"\u003e#13634\u003c/a\u003e: Blocking a \u003ccode\u003econftest.py\u003c/code\u003e file using the \u003ccode\u003e-p no:\u003c/code\u003e option is now explicitly disallowed.\u003c/p\u003e\n\u003cp\u003ePreviously this resulted in an internal assertion failure during plugin loading.\u003c/p\u003e\n\u003cp\u003ePytest now raises a clear \u003ccode\u003eUsageError\u003c/code\u003e explaining that conftest files are not plugins and cannot be disabled via \u003ccode\u003e-p\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13734\"\u003e#13734\u003c/a\u003e: Fixed crash when a test raises an exceptiongroup with \u003ccode\u003e__tracebackhide__ = True\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14195\"\u003e#14195\u003c/a\u003e: Fixed an issue where non-string messages passed to \u003c!-- raw HTML omitted --\u003eunittest.TestCase.subTest()\u003c!-- raw HTML omitted --\u003e were not printed.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14343\"\u003e#14343\u003c/a\u003e: Fixed use of insecure temporary directory (CVE-2025-71176).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13388\"\u003e#13388\u003c/a\u003e: Clarified documentation for \u003ccode\u003e-p\u003c/code\u003e vs \u003ccode\u003ePYTEST_PLUGINS\u003c/code\u003e plugin loading and fixed an incorrect \u003ccode\u003e-p\u003c/code\u003e example.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13731\"\u003e#13731\u003c/a\u003e: Clarified that capture fixtures (e.g. \u003ccode\u003ecapsys\u003c/code\u003e and \u003ccode\u003ecapfd\u003c/code\u003e) take precedence over the \u003ccode\u003e-s\u003c/code\u003e / \u003ccode\u003e--capture=no\u003c/code\u003e command-line options in \u003ccode\u003eAccessing captured output from a test function \u0026lt;accessing-captured-output\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14088\"\u003e#14088\u003c/a\u003e: Clarified that the default \u003ccode\u003epytest_collection\u003c/code\u003e hook sets \u003ccode\u003esession.items\u003c/code\u003e before it calls \u003ccode\u003epytest_collection_finish\u003c/code\u003e, not after.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14255\"\u003e#14255\u003c/a\u003e: TOML integer log levels must be quoted: Updating reference documentation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributor-facing changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/12689\"\u003e#12689\u003c/a\u003e: The test reports are now published to Codecov from GitHub Actions.\nThe test statistics is visible \u003ca href=\"https://app.codecov.io/gh/pytest-dev/pytest/tests\"\u003eon the web interface\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e-- by \u003ccode\u003ealeguy02\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e9.0.2\u003c/h2\u003e\n\u003ch1\u003epytest 9.0.2 (2025-12-06)\u003c/h1\u003e\n\u003ch2\u003eBug fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13896\"\u003e#13896\u003c/a\u003e: The terminal progress feature added in pytest 9.0.0 has been disabled by default, except on Windows, due to compatibility issues with some terminal emulators.\u003c/p\u003e\n\u003cp\u003eYou may enable it again by passing \u003ccode\u003e-p terminalprogress\u003c/code\u003e. We may enable it by default again once compatibility improves in the future.\u003c/p\u003e\n\u003cp\u003eAdditionally, when the environment variable \u003ccode\u003eTERM\u003c/code\u003e is \u003ccode\u003edumb\u003c/code\u003e, the escape codes are no longer emitted, even if the plugin is enabled.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13904\"\u003e#13904\u003c/a\u003e: Fixed the TOML type of the \u003ccode\u003etmp_path_retention_count\u003c/code\u003e settings in the API reference from number to string.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/13946\"\u003e#13946\u003c/a\u003e: The private \u003ccode\u003econfig.inicfg\u003c/code\u003e attribute was changed in a breaking manner in pytest 9.0.0.\nDue to its usage in the ecosystem, it is now restored to working order using a compatibility shim.\nIt will be deprecated in pytest 9.1 and removed in pytest 10.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/a7d58d7a21b78581e636bbbdea13c66ad1657c1e\"\u003e\u003ccode\u003ea7d58d7\u003c/code\u003e\u003c/a\u003e Prepare release version 9.0.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/089d98199c253d8f89a040243bc4f2aa6cd5ab22\"\u003e\u003ccode\u003e089d981\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14366\"\u003e#14366\u003c/a\u003e from bluetech/revert-14193-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/8127eaf4ab7f6b2fdd0dc1b38343ec97aeef05ac\"\u003e\u003ccode\u003e8127eaf\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Fix: assertrepr_compare respects dict insertion order (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14050\"\u003e#14050\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14193\"\u003e#14193\u003c/a\u003e)\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/99a7e6029e7a6e8d53e5df114b1346e035370241\"\u003e\u003ccode\u003e99a7e60\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14363\"\u003e#14363\u003c/a\u003e from pytest-dev/patchback/backports/9.0.x/95d8423bd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/ddee02a578da30dd43aedc39c1c1f1aaadfcee95\"\u003e\u003ccode\u003eddee02a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14343\"\u003e#14343\u003c/a\u003e from bluetech/cve-2025-71176-simple\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/74eac6916fee34726cb194f16c516e96fbd29619\"\u003e\u003ccode\u003e74eac69\u003c/code\u003e\u003c/a\u003e doc: Update training info (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14298\"\u003e#14298\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14301\"\u003e#14301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/f92dee777cfdb77d1c43633d02766ddf1f07c869\"\u003e\u003ccode\u003ef92dee7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14267\"\u003e#14267\u003c/a\u003e from pytest-dev/patchback/backports/9.0.x/d6fa26c62...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/7ee58acc8777c31ac6cf388d01addf5a414a7439\"\u003e\u003ccode\u003e7ee58ac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/12378\"\u003e#12378\u003c/a\u003e from Pierre-Sassoulas/fix-implicit-str-concat-and-d...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/37da870d37e3a2f5177cae075c7b9ae279432bf8\"\u003e\u003ccode\u003e37da870\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14259\"\u003e#14259\u003c/a\u003e from mitre88/patch-4 (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14268\"\u003e#14268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytest-dev/pytest/commit/c34bfa3b7acb65b594707c714f1d8461b0304eed\"\u003e\u003ccode\u003ec34bfa3\u003c/code\u003e\u003c/a\u003e Add explanation for string context diffs (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14257\"\u003e#14257\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pytest-dev/pytest/issues/14266\"\u003e#14266\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pytest-dev/pytest/compare/8.4.2...9.0.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Ekotik15/Determining_the_toxicity_of_comments-/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Ekotik15/Determining_the_toxicity_of_comments-/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ekotik15%2FDetermining_the_toxicity_of_comments-/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"5.15.1","new_version":"5.17.0","update_type":"minor","path":"/libs/langchain-db2","pr_created_at":"2026-09-21T19:26:32.000Z","version_change":"5.15.1 → 5.17.0","issue":{"uuid":"5531481688","node_id":"PR_kwDOMTmvWs8AAAABEeaQrw","number":344,"state":"open","title":"chore(deps-dev): bump the minor-and-patch group in /libs/langchain-db2 with 4 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-21T19:26:32.000Z","updated_at":"2026-09-21T19:26:55.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps-dev): bump","group_name":"minor-and-patch","update_count":4,"packages":[{"name":"ruff","old_version":"0.16.4","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"langsmith","old_version":"0.11.1","new_version":"0.13.0","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"transformers","old_version":"5.15.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"urllib3","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"}],"path":"/libs/langchain-db2","ecosystem":"pip"},"body":"Bumps the minor-and-patch group in /libs/langchain-db2 with 4 updates: [ruff](https://github.com/astral-sh/ruff), [langsmith](https://github.com/langchain-ai/langsmith-sdk), [transformers](https://github.com/huggingface/transformers) and [urllib3](https://github.com/urllib3/urllib3).\n\nUpdates `ruff` from 0.16.4 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/releases\"\u003eruff's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.8\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-16.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eVisit functional \u003ccode\u003eTypedDict\u003c/code\u003e keyword arguments correctly (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28584\"\u003e#28584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Detect nested \u003ccode\u003easync with\u003c/code\u003e under sync parent (\u003ccode\u003eSIM117\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27821\"\u003e#27821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Preserve operand order in \u003ccode\u003eSIM109\u003c/code\u003e fix (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27824\"\u003e#27824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Preserve required parentheses in multiline \u003ccode\u003eUP040\u003c/code\u003e fixes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28164\"\u003e#28164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Skip \u003ccode\u003eTypeVarTuple\u003c/code\u003e and \u003ccode\u003eParamSpec\u003c/code\u003e conversions with bounds or constraints (\u003ccode\u003eUP040\u003c/code\u003e, \u003ccode\u003eUP046\u003c/code\u003e, \u003ccode\u003eUP047\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28505\"\u003e#28505\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28459\"\u003e#28459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize PEP-728 \u003ccode\u003eTypedDict\u003c/code\u003e class keywords (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28533\"\u003e#28533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize quoted types in \u003ccode\u003etyping.TypeForm\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28507\"\u003e#28507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport conditional assignment to \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28491\"\u003e#28491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-type-checking\u003c/code\u003e] Prefer lazy imports over \u003ccode\u003eTYPE_CHECKING\u003c/code\u003e on Python 3.15 and later (\u003ccode\u003eTC001\u003c/code\u003e, \u003ccode\u003eTC002\u003c/code\u003e, \u003ccode\u003eTC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28541\"\u003e#28541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Make the fix for \u003ccode\u003eUP040\u003c/code\u003e always unsafe (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28526\"\u003e#28526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending deprecated \u003ccode\u003eByteString\u003c/code\u003e aliases (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28498\"\u003e#28498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e, \u003ccode\u003eflake8-use-pathlib\u003c/code\u003e] Recognize the \u003ccode\u003eparent_mode\u003c/code\u003e argument (\u003ccode\u003eRUF064\u003c/code\u003e, \u003ccode\u003ePTH103\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28528\"\u003e#28528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Detect \u003ccode\u003e\\Z\u003c/code\u003e in \u003ccode\u003epytest.raises()\u003c/code\u003e match patterns (\u003ccode\u003eRUF043\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28598\"\u003e#28598\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse rule name and code in formatter incompatibility warnings (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28571\"\u003e#28571\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eConfiguration\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Add \u003ccode\u003eextend-banned-api\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28644\"\u003e#28644\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/VedantMadane\"\u003e\u003ccode\u003e@​VedantMadane\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alzeph\"\u003e\u003ccode\u003e@​alzeph\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fredrikblau\"\u003e\u003ccode\u003e@​fredrikblau\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Aniket-a14\"\u003e\u003ccode\u003e@​Aniket-a14\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r-b-1\"\u003e\u003ccode\u003e@​r-b-1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eInstall ruff 0.16.8\u003c/h2\u003e\n\u003ch3\u003eInstall prebuilt binaries via shell script\u003c/h3\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003ecurl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md\"\u003eruff's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.8\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-16.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eVisit functional \u003ccode\u003eTypedDict\u003c/code\u003e keyword arguments correctly (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28584\"\u003e#28584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Detect nested \u003ccode\u003easync with\u003c/code\u003e under sync parent (\u003ccode\u003eSIM117\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27821\"\u003e#27821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-simplify\u003c/code\u003e] Preserve operand order in \u003ccode\u003eSIM109\u003c/code\u003e fix (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27824\"\u003e#27824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Preserve required parentheses in multiline \u003ccode\u003eUP040\u003c/code\u003e fixes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28164\"\u003e#28164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Skip \u003ccode\u003eTypeVarTuple\u003c/code\u003e and \u003ccode\u003eParamSpec\u003c/code\u003e conversions with bounds or constraints (\u003ccode\u003eUP040\u003c/code\u003e, \u003ccode\u003eUP046\u003c/code\u003e, \u003ccode\u003eUP047\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28505\"\u003e#28505\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28459\"\u003e#28459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize PEP-728 \u003ccode\u003eTypedDict\u003c/code\u003e class keywords (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28533\"\u003e#28533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize quoted types in \u003ccode\u003etyping.TypeForm\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28507\"\u003e#28507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport conditional assignment to \u003ccode\u003e__lazy_modules__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28491\"\u003e#28491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-type-checking\u003c/code\u003e] Prefer lazy imports over \u003ccode\u003eTYPE_CHECKING\u003c/code\u003e on Python 3.15 and later (\u003ccode\u003eTC001\u003c/code\u003e, \u003ccode\u003eTC002\u003c/code\u003e, \u003ccode\u003eTC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28541\"\u003e#28541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Make the fix for \u003ccode\u003eUP040\u003c/code\u003e always unsafe (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28526\"\u003e#28526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending deprecated \u003ccode\u003eByteString\u003c/code\u003e aliases (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28498\"\u003e#28498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e, \u003ccode\u003eflake8-use-pathlib\u003c/code\u003e] Recognize the \u003ccode\u003eparent_mode\u003c/code\u003e argument (\u003ccode\u003eRUF064\u003c/code\u003e, \u003ccode\u003ePTH103\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28528\"\u003e#28528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Detect \u003ccode\u003e\\Z\u003c/code\u003e in \u003ccode\u003epytest.raises()\u003c/code\u003e match patterns (\u003ccode\u003eRUF043\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28598\"\u003e#28598\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUse rule name and code in formatter incompatibility warnings (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28571\"\u003e#28571\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eConfiguration\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Add \u003ccode\u003eextend-banned-api\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28644\"\u003e#28644\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/VedantMadane\"\u003e\u003ccode\u003e@​VedantMadane\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alzeph\"\u003e\u003ccode\u003e@​alzeph\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fredrikblau\"\u003e\u003ccode\u003e@​fredrikblau\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Aniket-a14\"\u003e\u003ccode\u003e@​Aniket-a14\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r-b-1\"\u003e\u003ccode\u003e@​r-b-1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/62914c4b9b79a9e5004374a9c482ad2ed69290e1\"\u003e\u003ccode\u003e62914c4\u003c/code\u003e\u003c/a\u003e Bump version to 0.16.8 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28648\"\u003e#28648\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/c47e0cdc665f56536ce7f7a8ac40fa0ff3f79482\"\u003e\u003ccode\u003ec47e0cd\u003c/code\u003e\u003c/a\u003e [ty] Bound aliased intersection expansion during inference (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28546\"\u003e#28546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/ff4747b509ab4fffbe5689fcae39caa7503d1dcf\"\u003e\u003ccode\u003eff4747b\u003c/code\u003e\u003c/a\u003e renovate: update uv hashes correctly with setup-uv (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28621\"\u003e#28621\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/94efeaa28630d80b2a74adf3c3963de99ed4ee29\"\u003e\u003ccode\u003e94efeaa\u003c/code\u003e\u003c/a\u003e [ty] Compact reachable binding and declaration histories (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28349\"\u003e#28349\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/50020fb1e8aa83b0826fa6f5f33a1e93c10cc60e\"\u003e\u003ccode\u003e50020fb\u003c/code\u003e\u003c/a\u003e [ty] Avoid storing constraint nodes twice (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28375\"\u003e#28375\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/446bb68da50014bb75f5ce1504a80c5883e3b0b2\"\u003e\u003ccode\u003e446bb68\u003c/code\u003e\u003c/a\u003e [ty] Compare bound-method receivers before signatures (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28384\"\u003e#28384\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/304ab86be5de6507e276ab09f5b43f44aeb92469\"\u003e\u003ccode\u003e304ab86\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eflake8-type-checking\u003c/code\u003e] Prefer lazy imports over \u003ccode\u003eTYPE_CHECKING\u003c/code\u003e on 3.15+ (`...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/d940b244f7512427b0d87c7953e88c60e69f9bdf\"\u003e\u003ccode\u003ed940b24\u003c/code\u003e\u003c/a\u003e [ty] Watch script dependencies in CLI watch mode (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28125\"\u003e#28125\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/fe9f065a504127b11da72c2ff6d7813ddf3ce8ac\"\u003e\u003ccode\u003efe9f065\u003c/code\u003e\u003c/a\u003e [flake8-tidy-imports] Add \u003ccode\u003eextend-banned-api\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28644\"\u003e#28644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/31131db44f057cce68fa6b95552b7db54167b0b3\"\u003e\u003ccode\u003e31131db\u003c/code\u003e\u003c/a\u003e [ty] Support \u003ccode\u003etype[A \u0026amp; B]\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/27124\"\u003e#27124\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/astral-sh/ruff/compare/0.16.4...0.16.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langsmith` from 0.11.1 to 0.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/releases\"\u003elangsmith's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.13.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(evaluate): add disable_evaluator_tracing toggle to evaluate() and aevaluate() by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3547\"\u003elangchain-ai/langsmith-sdk#3547\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(openwiki): open the update PR with gh instead of a third-party action by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3545\"\u003elangchain-ai/langsmith-sdk#3545\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(sandbox): deprecate no_proxy in proxy config helpers by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3512\"\u003elangchain-ai/langsmith-sdk#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): preserve the 403 JSON error body in raiseForStatus by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3548\"\u003elangchain-ai/langsmith-sdk#3548\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sandbox): support AWS IAM roles in Python and JavaScript helpers by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3536\"\u003elangchain-ai/langsmith-sdk#3536\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sandbox): run_config, stdin EOF, and native file search/range ops by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3522\"\u003elangchain-ai/langsmith-sdk#3522\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(js): add disableEvaluatorTracing option to evaluate() by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3549\"\u003elangchain-ai/langsmith-sdk#3549\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sandbox): stream commands over the SSE exec API behind a feature flag by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3553\"\u003elangchain-ai/langsmith-sdk#3553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(py,js): log which source the client resolved its API URL from by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3557\"\u003elangchain-ai/langsmith-sdk#3557\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.13.0 by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3555\"\u003elangchain-ai/langsmith-sdk#3555\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.6...v0.13.0\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.12.6...v0.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003erelease(js): 0.10.4 by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3542\"\u003elangchain-ai/langsmith-sdk#3542\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add OpenWiki, with a weekly refresh workflow by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3541\"\u003elangchain-ai/langsmith-sdk#3541\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(livekit): preserve system instructions with history by \u003ca href=\"https://github.com/carolinedivittorio\"\u003e\u003ccode\u003e@​carolinedivittorio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3544\"\u003elangchain-ai/langsmith-sdk#3544\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.12.6 by \u003ca href=\"https://github.com/carolinedivittorio\"\u003e\u003ccode\u003e@​carolinedivittorio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3546\"\u003elangchain-ai/langsmith-sdk#3546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.5...v0.12.6\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.12.5...v0.12.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: preserve sandbox API error IDs by \u003ca href=\"https://github.com/langchain-infra\"\u003e\u003ccode\u003e@​langchain-infra\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3515\"\u003elangchain-ai/langsmith-sdk#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): avoid stored reasoning in OpenAI integration tests by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3519\"\u003elangchain-ai/langsmith-sdk#3519\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): update vulnerable test dependencies by \u003ca href=\"https://github.com/linted\"\u003e\u003ccode\u003e@​linted\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3525\"\u003elangchain-ai/langsmith-sdk#3525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump js-yaml from 3.15.1 to 4.3.1 in /js/internal/environment_tests/test-exports-metro in the npm_and_yarn group across 1 directory by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3526\"\u003elangchain-ai/langsmith-sdk#3526\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): patch vulnerable Vitest and Hono dependencies by \u003ca href=\"https://github.com/jkennedyvz\"\u003e\u003ccode\u003e@​jkennedyvz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3516\"\u003elangchain-ai/langsmith-sdk#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(js): 0.10.3 by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3509\"\u003elangchain-ai/langsmith-sdk#3509\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js,py): tag guardrail/subagent structurally in openai-agents integration by \u003ca href=\"https://github.com/ybathula707\"\u003e\u003ccode\u003e@​ybathula707\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3523\"\u003elangchain-ai/langsmith-sdk#3523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(py,js): report the configured tracing sample rate on runs by \u003ca href=\"https://github.com/thibautlehmann\"\u003e\u003ccode\u003e@​thibautlehmann\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3492\"\u003elangchain-ai/langsmith-sdk#3492\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(js): upgrade vulnerable js-yaml and sharp by \u003ca href=\"https://github.com/linted\"\u003e\u003ccode\u003e@​linted\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3535\"\u003elangchain-ai/langsmith-sdk#3535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(py): stop sandbox run() from waiting ~1s on the server's TCP close after exit by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3538\"\u003elangchain-ai/langsmith-sdk#3538\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(py): carry the ADK tool call ids into traced messages [LSDK-509] by \u003ca href=\"https://github.com/zduric-langchain\"\u003e\u003ccode\u003e@​zduric-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3506\"\u003elangchain-ai/langsmith-sdk#3506\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.12.5 by \u003ca href=\"https://github.com/emil-lc\"\u003e\u003ccode\u003e@​emil-lc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3540\"\u003elangchain-ai/langsmith-sdk#3540\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/linted\"\u003e\u003ccode\u003e@​linted\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3525\"\u003elangchain-ai/langsmith-sdk#3525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zduric-langchain\"\u003e\u003ccode\u003e@​zduric-langchain\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3506\"\u003elangchain-ai/langsmith-sdk#3506\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.4...v0.12.5\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.12.4...v0.12.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(livekit): support agents 1.7 and 1.8 telemetry [Closes LSDK-506] by \u003ca href=\"https://github.com/carolinedivittorio\"\u003e\u003ccode\u003e@​carolinedivittorio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3510\"\u003elangchain-ai/langsmith-sdk#3510\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/e6863ca150cc678b737a236736ec878c1ee3c573\"\u003e\u003ccode\u003ee6863ca\u003c/code\u003e\u003c/a\u003e release(py): 0.13.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3555\"\u003e#3555\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/d0357078254706001f03bcdfa695a3a76b365e2d\"\u003e\u003ccode\u003ed035707\u003c/code\u003e\u003c/a\u003e feat(py,js): log which source the client resolved its API URL from (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3557\"\u003e#3557\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/47b85327a6a951d87bcdaa6b0751c1b85c0df02e\"\u003e\u003ccode\u003e47b8532\u003c/code\u003e\u003c/a\u003e feat(sandbox): stream commands over the SSE exec API behind a feature flag (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/e4370d68031f088764424a996e213329d763138e\"\u003e\u003ccode\u003ee4370d6\u003c/code\u003e\u003c/a\u003e feat(js): add disableEvaluatorTracing option to evaluate() (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3549\"\u003e#3549\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/69406a65e87c4945c0ff1b507f778e4389adbb45\"\u003e\u003ccode\u003e69406a6\u003c/code\u003e\u003c/a\u003e feat(sandbox): run_config, stdin EOF, and native file search/range ops (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3522\"\u003e#3522\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/529f970494887b75aa7daf50230e65f4be565851\"\u003e\u003ccode\u003e529f970\u003c/code\u003e\u003c/a\u003e feat(sandbox): support AWS IAM roles in Python and JavaScript helpers (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3536\"\u003e#3536\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/cc38f3cbb16af77b9faf9bbc49040d3f4563daae\"\u003e\u003ccode\u003ecc38f3c\u003c/code\u003e\u003c/a\u003e fix(js): preserve the 403 JSON error body in raiseForStatus (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3548\"\u003e#3548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/6bf054e09c225fa46abd1e4ead6825a09d683a26\"\u003e\u003ccode\u003e6bf054e\u003c/code\u003e\u003c/a\u003e refactor(sandbox): deprecate no_proxy in proxy config helpers (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3512\"\u003e#3512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/68342eae8047a39379c1f848390a7c5995a9166d\"\u003e\u003ccode\u003e68342ea\u003c/code\u003e\u003c/a\u003e ci(openwiki): open the update PR with gh instead of a third-party action (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3545\"\u003e#3545\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/b771c204344e33e913094517bfca43309a1a92c5\"\u003e\u003ccode\u003eb771c20\u003c/code\u003e\u003c/a\u003e feat(evaluate): add disable_evaluator_tracing toggle to evaluate() and aevalu...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.7.0 to 2.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/releases\"\u003eurllib3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.8.0\u003c/h2\u003e\n\u003ch2\u003e🚀 urllib3 is fundraising for HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support\"\u003eurllib3 is raising ~$40,000 USD\u003c/a\u003e to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects \u003ca href=\"https://opencollective.com/urllib3\"\u003eplease consider contributing financially\u003c/a\u003e to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.\u003c/p\u003e\n\u003cp\u003eThank you for your support.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eFixed the following security issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eread_chunked()\u003c/code\u003e could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)\u003c/li\u003e\n\u003cli\u003eChunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\nurllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.\u003c/p\u003e\n\u003cp\u003eConfigure proxy CA certificates and client certificates in \u003ccode\u003eproxy_ssl_context\u003c/code\u003e, and proxy identity checks with \u003ccode\u003eproxy_assert_hostname\u003c/code\u003e or \u003ccode\u003eproxy_assert_fingerprint\u003c/code\u003e. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nCVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eDeprecations \u0026amp; Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecated using an empty collection as the \u003ccode\u003eRetry\u003c/code\u003e option \u003ccode\u003eallowed_methods\u003c/code\u003e to retry any verb. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5044\"\u003e#5044\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eUrl.auth_decoded\u003c/code\u003e and \u003ccode\u003eUrl.auth_decoded_joined\u003c/code\u003e convenience properties to the result of \u003ccode\u003eparse_url()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4945\"\u003e#4945\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003ebasic_auth_encoding\u003c/code\u003e and \u003ccode\u003eproxy_basic_auth_encoding\u003c/code\u003e parameters to \u003ccode\u003eurllib3.util.make_headers()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5092\"\u003e#5092\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFixed response header handling to replace obsolete folded header lines (\u003ccode\u003eobs-fold\u003c/code\u003e) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as \u003ccode\u003eSet-Cookie\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/1362\"\u003e#1362\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed usage of \u003ccode\u003eproxy_ssl_context\u003c/code\u003e with \u003ccode\u003eProxyManager\u003c/code\u003e when \u003ccode\u003euse_forwarding_for_https=True\u003c/code\u003e. Passing \u003ccode\u003essl_context\u003c/code\u003e instead of \u003ccode\u003eproxy_ssl_context\u003c/code\u003e for HTTPS proxies in this configuration now emits a \u003ccode\u003eFutureWarning\u003c/code\u003e and will raise an error in v3.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/2577\"\u003e#2577\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged behavior of the default \u003ccode\u003eConnectionPool.pool\u003c/code\u003e initialization. \u003ccode\u003eLifoQueue\u003c/code\u003e is now resolved from the \u003ccode\u003equeue\u003c/code\u003e module after the \u003ccode\u003eConnectionPool\u003c/code\u003e is instantiated instead of using the default cached \u003ccode\u003eQueueCls\u003c/code\u003e class property. This is done because sometimes the \u003ccode\u003equeue.LifoQueue\u003c/code\u003e is monkey-patched late in the program, such as by gevent. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3289\"\u003e#3289\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRaised \u003ccode\u003eUnrewindableBodyError\u003c/code\u003e instead of \u003ccode\u003eValueError\u003c/code\u003e when retrying a request whose body had \u003ccode\u003etell()\u003c/code\u003e but not \u003ccode\u003eseek()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3779\"\u003e#3779\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDecoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3785\"\u003e#3785\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e to discard unread response data in 64 KiB chunks (same as the default \u003ccode\u003eamt\u003c/code\u003e when doing \u003ccode\u003eHTTPResponse.stream(...)\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5019\"\u003e#5019\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eis_ipaddress()\u003c/code\u003e to detect non-standard IPv4 forms accepted by \u003ccode\u003esocket.connect\u003c/code\u003e, such as hex (\u003ccode\u003e0x7f000001\u003c/code\u003e), octal (\u003ccode\u003e0177.0.0.1\u003c/code\u003e), and decimal integers (\u003ccode\u003e2130706433\u003c/code\u003e), ensuring SSL certificate verification uses the correct mode for these addresses. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5029\"\u003e#5029\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPConnectionPool.urlopen\u003c/code\u003e raising a misleading \u003ccode\u003eFullPoolError\u003c/code\u003e instead of \u003ccode\u003eValueError\u003c/code\u003e when called with an invalid \u003ccode\u003etimeout\u003c/code\u003e argument on a pool created with \u003ccode\u003eblock=True\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5059\"\u003e#5059\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed port-zero handling to preserve explicit \u003ccode\u003e:0\u003c/code\u003e values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, \u003ccode\u003econnection_from_url()\u003c/code\u003e, and HTTP/2 request authority. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5071\"\u003e#5071\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5101\"\u003e#5101\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed a bug where \u003ccode\u003ePoolManager\u003c/code\u003e passed the \u003ccode\u003eassert_hostname\u003c/code\u003e and \u003ccode\u003eassert_fingerprint\u003c/code\u003e parameters to HTTP connection pools. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5077\"\u003e#5077\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPConnectionPool.urlopen()\u003c/code\u003e and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5079\"\u003e#5079\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5091\"\u003e#5091\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eHTTPSConnection.connect()\u003c/code\u003e overriding \u003ccode\u003eProxyConfig.ssl_context\u003c/code\u003e's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eHTTPSConnection\u003c/code\u003e no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its \u003ccode\u003essl_context\u003c/code\u003e as a fallback when an HTTPS proxy forwards an HTTP target. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5093\"\u003e#5093\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5095\"\u003e#5095\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst\"\u003eurllib3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.8.0 (2026-09-15)\u003c/h1\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eFixed the following security issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe TLS configuration for HTTPS proxies could be ignored or overridden.\n(High severity, \u003ccode\u003eGHSA-8988-9cw3-xx77 \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eread_chunked()\u003c/code\u003e could buffer a chunk-size\nline of unbounded length in memory. (High severity,\n\u003ccode\u003eGHSA-vxq7-64xx-v4gw \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eChunked Deflate streaming could enter an infinite loop. (Medium severity,\n\u003ccode\u003eGHSA-gh4c-6fx4-qh6g \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e.. caution::\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eurllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or\noverridden by destination settings. Configurations relying on that\nbehavior may require changes.\n\u003cp\u003eConfigure proxy CA certificates and client certificates in\n\u003ccode\u003eproxy_ssl_context\u003c/code\u003e, and proxy identity checks with\n\u003ccode\u003eproxy_assert_hostname\u003c/code\u003e or \u003ccode\u003eproxy_assert_fingerprint\u003c/code\u003e.\nDestination client certificates and identity overrides no longer\napply to HTTPS forwarding proxy connections.\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch2\u003eDeprecations \u0026amp; Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecated using an empty collection as the \u003ccode\u003eRetry\u003c/code\u003e option\n\u003ccode\u003eallowed_methods\u003c/code\u003e to retry any verb.\n(\u003ccode\u003e[#5044](https://github.com/urllib3/urllib3/issues/5044) \u0026lt;https://github.com/urllib3/urllib3/issues/5044\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eUrl.auth_decoded\u003c/code\u003e and \u003ccode\u003eUrl.auth_decoded_joined\u003c/code\u003e convenience\nproperties to the result of \u003ccode\u003eparse_url()\u003c/code\u003e.\n(\u003ccode\u003e[#4945](https://github.com/urllib3/urllib3/issues/4945) \u0026lt;https://github.com/urllib3/urllib3/issues/4945\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003ebasic_auth_encoding\u003c/code\u003e and \u003ccode\u003eproxy_basic_auth_encoding\u003c/code\u003e parameters to\n\u003ccode\u003eurllib3.util.make_headers()\u003c/code\u003e.\n(\u003ccode\u003e[#5092](https://github.com/urllib3/urllib3/issues/5092) \u0026lt;https://github.com/urllib3/urllib3/issues/5092\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a\"\u003e\u003ccode\u003eb1d30ab\u003c/code\u003e\u003c/a\u003e Release 2.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e\"\u003e\u003ccode\u003e9016d7e\u003c/code\u003e\u003c/a\u003e Skip \u003ccode\u003etest_read_chunked_with_trailing_data_does_not_hang\u003c/code\u003e for brotlicffi (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5258\"\u003e#5258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533\"\u003e\u003ccode\u003e9101f58\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003enox -s docs\u003c/code\u003e warning (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5256\"\u003e#5256\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed\"\u003e\u003ccode\u003ecd770b0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f\"\u003e\u003ccode\u003eea2ad7b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8\"\u003e\u003ccode\u003e0716e31\u003c/code\u003e\u003c/a\u003e Fix loading unencrypted client keys with a password in pyOpenSSL (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5255\"\u003e#5255\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d\"\u003e\u003ccode\u003e43c68c8\u003c/code\u003e\u003c/a\u003e Test pickling of \u003ccode\u003eInvalidChunkLength\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5247\"\u003e#5247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817\"\u003e\u003ccode\u003e308b279\u003c/code\u003e\u003c/a\u003e Share security policy between GitHub and Read the Docs (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5253\"\u003e#5253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706\"\u003e\u003ccode\u003e53fa073\u003c/code\u003e\u003c/a\u003e Add policy on duplicate pull requests (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5252\"\u003e#5252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267\"\u003e\u003ccode\u003e5f2a6a8\u003c/code\u003e\u003c/a\u003e Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/5232\"\u003e#5232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/langchain-ai/langchain-ibm/pull/344","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/langchain-ai%2Flangchain-ibm/issues/344","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/344/packages"}},{"old_version":"5.5.0","new_version":"5.17.0","update_type":"minor","path":"the python-minor group","pr_created_at":"2026-09-21T19:03:16.000Z","version_change":"5.5.0 → 5.17.0","issue":{"uuid":"5531249555","node_id":"PR_kwDOQTfEL88AAAABEeOTKQ","number":225,"state":"closed","title":"chore(deps): bump transformers from 5.5.0 to 5.17.0 in the python-minor group","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-21T19:07:31.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-21T19:03:16.000Z","updated_at":"2026-09-21T19:07:40.000Z","time_to_close":255,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"transformers","old_version":"5.5.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":"the python-minor group","ecosystem":"pip"},"body":"Bumps the python-minor group with 1 update: [transformers](https://github.com/huggingface/transformers).\n\nUpdates `transformers` from 5.5.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=transformers\u0026package-manager=pip\u0026previous-version=5.5.0\u0026new-version=5.17.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/AmaniQuery/amaniquery-prototype/pull/225","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/AmaniQuery%2Famaniquery-prototype/issues/225","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/225/packages"}},{"old_version":"5.14.1","new_version":"5.17.0","update_type":"minor","path":"/services/ai-orchestrator-service","pr_created_at":"2026-09-19T19:44:57.000Z","version_change":"5.14.1 → 5.17.0","issue":{"uuid":"5513101412","node_id":"PR_kwDOT_waCs8AAAABEP-mQw","number":89,"state":"open","title":"build(deps): bump the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T19:44:57.000Z","updated_at":"2026-09-19T19:44:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip-minor-patch","update_count":70,"packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"annotated-doc","old_version":"0.0.4","new_version":"0.0.5","repository_url":"https://github.com/fastapi/annotated-doc"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"build","old_version":"1.5.0","new_version":"1.6.1","repository_url":"https://github.com/pypa/build"},{"name":"certifi","old_version":"2026.6.17","new_version":"2026.7.22","repository_url":"https://github.com/certifi/python-certifi"},{"name":"cffi","old_version":"2.1.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.9","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cloudpathlib","old_version":"0.24.0","new_version":"0.25.0","repository_url":"https://github.com/drivendataorg/cloudpathlib"},{"name":"contourpy","old_version":"1.3.3","new_version":"1.4.0","repository_url":"https://github.com/contourpy/contourpy"},{"name":"durationpy","old_version":"0.10","new_version":"0.11","repository_url":"https://github.com/icholy/durationpy"},{"name":"fastapi","old_version":"0.139.2","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"filelock","old_version":"3.30.2","new_version":"3.32.7","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"fsspec","old_version":"2026.6.0","new_version":"2026.7.0","repository_url":"https://github.com/fsspec/filesystem_spec"},{"name":"google-auth","old_version":"2.55.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-genai","old_version":"2.12.0","new_version":"2.23.0","repository_url":"https://github.com/googleapis/python-genai"},{"name":"googleapis-common-protos","old_version":"1.75.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"grpcio","old_version":"1.82.1","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"hf-xet","old_version":"1.5.2","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"huggingface-hub","old_version":"1.23.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"idna","old_version":"3.18","new_version":"3.19","repository_url":"https://github.com/kjd/idna"},{"name":"jiter","old_version":"0.16.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"kiwisolver","old_version":"1.5.0","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"langchain","old_version":"1.3.14","new_version":"1.4.1","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-core","old_version":"1.4.9","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-google-genai","old_version":"4.2.7","new_version":"4.4.0","repository_url":"https://github.com/langchain-ai/langchain-google"},{"name":"langchain-protocol","old_version":"0.0.18","new_version":"0.0.19","repository_url":"https://github.com/langchain-ai/agent-protocol"},{"name":"langgraph","old_version":"1.2.9","new_version":"1.2.11","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-checkpoint","old_version":"4.1.1","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-sdk","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langsmith","old_version":"0.10.5","new_version":"0.12.6","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"mmh3","old_version":"5.2.1","new_version":"5.3.0","repository_url":"https://github.com/hajimes/mmh3"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"multidict","old_version":"6.7.1","new_version":"6.8.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.24.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"numpy","old_version":"2.5.1","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"onnxruntime","old_version":"1.27.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"orjson","old_version":"3.11.9","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"packaging","old_version":"26.2","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"pandas","old_version":"3.0.3","new_version":"3.0.5","repository_url":"https://github.com/pandas-dev/pandas"},{"name":"propcache","old_version":"0.5.2","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"protobuf","old_version":"7.35.1","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pydantic-core","old_version":"2.46.4","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pygments","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyproject-hooks","old_version":"1.2.0","new_version":"1.3.3","repository_url":"https://github.com/pypa/pyproject-hooks"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"regex","old_version":"2026.7.10","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"scikit-learn","old_version":"1.9.0","new_version":"1.9.1","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.18.0","new_version":"1.18.1","repository_url":"https://github.com/scipy/scipy"},{"name":"smart-open","old_version":"8.0.0","new_version":"8.0.1","repository_url":"https://github.com/piskvorky/smart_open"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"threadpoolctl","old_version":"3.6.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"tqdm","old_version":"4.68.4","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"typing-inspection","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/pydantic/typing-inspection"},{"name":"tzdata","old_version":"2026.3","new_version":"2026.4","repository_url":"https://github.com/python/tzdata"},{"name":"urllib3","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.51.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"wrapt","old_version":"2.2.2","new_version":"2.4.1","repository_url":"https://github.com/GrahamDumpleton/wrapt"},{"name":"yarl","old_version":"1.24.2","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"}],"path":"/services/ai-orchestrator-service","ecosystem":"pip"},"body":"Bumps the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [build](https://github.com/pypa/build) | `1.5.0` | `1.6.1` |\n| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cloudpathlib](https://github.com/drivendataorg/cloudpathlib) | `0.24.0` | `0.25.0` |\n| [contourpy](https://github.com/contourpy/contourpy) | `1.3.3` | `1.4.0` |\n| [durationpy](https://github.com/icholy/durationpy) | `0.10` | `0.11` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.2` | `0.141.1` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.30.2` | `3.32.7` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| [fsspec](https://github.com/fsspec/filesystem_spec) | `2026.6.0` | `2026.7.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.55.2` | `2.58.0` |\n| [google-genai](https://github.com/googleapis/python-genai) | `2.12.0` | `2.23.0` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.0` | `1.75.3` |\n| [grpcio](https://github.com/grpc/grpc) | `1.82.1` | `1.84.0` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.2` | `1.6.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.23.0` | `1.31.0` |\n| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |\n| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.5.0` | `1.5.1` |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.3.14` | `1.4.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.4.9` | `1.6.3` |\n| [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.2.7` | `4.4.0` |\n| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) | `0.0.18` | `0.0.19` |\n| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.9` | `1.2.11` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.1.1` | `4.2.0` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.2` | `0.4.4` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.5` | `0.12.6` |\n| [mmh3](https://github.com/hajimes/mmh3) | `5.2.1` | `5.3.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.8.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.24.0` | `2.26.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.1` | `2.5.3` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.27.0` | `1.30.0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |\n| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |\n| [pandas](https://github.com/pandas-dev/pandas) | `3.0.3` | `3.0.5` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.5.2` | `0.5.4` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.1` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.4` | `2.49.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |\n| [pyproject-hooks](https://github.com/pypa/pyproject-hooks) | `1.2.0` | `1.3.3` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.7.10` | `2026.9.10` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` |\n| [scipy](https://github.com/scipy/scipy) | `1.18.0` | `1.18.1` |\n| [smart-open](https://github.com/piskvorky/smart_open) | `8.0.0` | `8.0.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.6.0` | `3.7.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.68.4` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |\n| [tzdata](https://github.com/python/tzdata) | `2026.3` | `2026.4` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.51.0` | `0.53.0` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.2.2` | `2.4.1` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.2` | `1.25.1` |\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `annotated-doc` from 0.0.4 to 0.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/releases\"\u003eannotated-doc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.27 to 0.0.33. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/52\"\u003e#52\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/blob/main/release-notes.md\"\u003eannotated-doc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5 (2026-07-28)\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef48d6ad51d226f772fd9c5284f55199afe4007c\"\u003e\u003ccode\u003eef48d6a\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.0.5 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/93\"\u003e#93\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/c628000835a26f6bc8c776f90bcbcf95211f233b\"\u003e\u003ccode\u003ec628000\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/e0b4579d2ad8d62a304c9f30a1c2c084f0d372e5\"\u003e\u003ccode\u003ee0b4579\u003c/code\u003e\u003c/a\u003e ➖ Drop support for Python 3.8 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/36\"\u003e#36\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef956b4e9f2c0e2bead1cba7a6888e1ed8c2c237\"\u003e\u003ccode\u003eef956b4\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/84bf1e5402c5e0cfd1462c5d3c8bae22fb717bd8\"\u003e\u003ccode\u003e84bf1e5\u003c/code\u003e\u003c/a\u003e ⬆️ Upgrade latest-changes to 0.7.1 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cf773e138b1dc5608ce0f0d11e1939c410ef6228\"\u003e\u003ccode\u003ecf773e1\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/1375d6eb8147cb2352d080ef09f356dfc18e0d29\"\u003e\u003ccode\u003e1375d6e\u003c/code\u003e\u003c/a\u003e ⬆ Bump the github-actions group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/91\"\u003e#91\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cd373656cbf40e5fd4cc28680ca5e05bf12709cb\"\u003e\u003ccode\u003ecd37365\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/f9f3b695cbacc4ffc37d9cebff6e05bd1751f68a\"\u003e\u003ccode\u003ef9f3b69\u003c/code\u003e\u003c/a\u003e ⬆ Bump the python-packages group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/842084457f0a7739fb91d2a4ea602b2bc4e15767\"\u003e\u003ccode\u003e8420844\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/annotated-doc/compare/0.0.4...0.0.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `annotated-types` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/annotated-types/annotated-types/releases\"\u003eannotated-types's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRename DocInfo to Doc by \u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.13 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix docstring of \u003ccode\u003eTimezone\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/84\"\u003eannotated-types/annotated-types#84\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) by \u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: typo in README.md by \u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd CI for PyPy3.11 and fix test (issue 71) by \u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix string predicate names in doc by \u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd SPDX license expression by \u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Python 3.14 to the test matrix by \u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.14 and drop EOL 3.8-3.9 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/97\"\u003eannotated-types/annotated-types#97\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix typo in \u003ccode\u003eLen\u003c/code\u003e docstring by \u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare for 0.8.0 release by \u003ca href=\"https://github.com/adriangb\"\u003e\u003ccode\u003e@​adriangb\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/103\"\u003eannotated-types/annotated-types#103\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ehttps://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/9eb96680138269811a39d838d720abc3dce33954\"\u003e\u003ccode\u003e9eb9668\u003c/code\u003e\u003c/a\u003e Prepare for 0.8.0 release (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/103\"\u003e#103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/10b77644f88b385357653730a1ab23748ca3ae2e\"\u003e\u003ccode\u003e10b7764\u003c/code\u003e\u003c/a\u003e Fix typo in \u003ccode\u003eLen\u003c/code\u003e docstring (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/100\"\u003e#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/955f7576d616feb6e9407c74498517787c38afd4\"\u003e\u003ccode\u003e955f757\u003c/code\u003e\u003c/a\u003e Add support for Python 3.14 and drop EOL 3.8-3.9 (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/97\"\u003e#97\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/bd280fea7983550d266f993d868b8dd7ff822bf1\"\u003e\u003ccode\u003ebd280fe\u003c/code\u003e\u003c/a\u003e Added Python 3.14 to the test matrix (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/96\"\u003e#96\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/a471bb757663452459893e6f593118ec21eb1b9e\"\u003e\u003ccode\u003ea471bb7\u003c/code\u003e\u003c/a\u003e Add SPDX license expression (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/eab91d9a8c0d3f73661fc4b0794a1fe76c94fa84\"\u003e\u003ccode\u003eeab91d9\u003c/code\u003e\u003c/a\u003e Fix string predicate names in doc (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/03ad9c3c7b4d4dfe9e33c09075a3a2766c0820e1\"\u003e\u003ccode\u003e03ad9c3\u003c/code\u003e\u003c/a\u003e add CI for PyPy3.11 and fix test (issue 71) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/88\"\u003e#88\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/5ae60437f0ab493cedd27311bc6ce6d2188e8d8b\"\u003e\u003ccode\u003e5ae6043\u003c/code\u003e\u003c/a\u003e fix: typo in README.md (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/87\"\u003e#87\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/b60ad7bff90019c7de3547df1c8e3586eb328423\"\u003e\u003ccode\u003eb60ad7b\u003c/code\u003e\u003c/a\u003e Update license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/86\"\u003e#86\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/3fbeb6d129760ae48d7a0372fb9301764acc95ae\"\u003e\u003ccode\u003e3fbeb6d\u003c/code\u003e\u003c/a\u003e Fix docstring of \u003ccode\u003eTimezone\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/84\"\u003e#84\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anyio` from 4.14.2 to 4.15.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.15.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplemented a compatibility fix for supporting direct access of \u003ccode\u003eanyio.*\u003c/code\u003e submodules from the main package even when those submodules were not directly imported first (\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311\"\u003e#1311\u003c/a\u003e \u0026lt;\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E\"\u003eagronholm/anyio#1311\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.15.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for the newer keyword-only arguments on \u003ccode\u003eanyio.Path\u003c/code\u003e methods to match the standard library \u003ccode\u003epathlib.Path\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eexists()\u003c/code\u003e (Python 3.12+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_dir()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_file()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eowner()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003egroup()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enewline\u003c/code\u003e on \u003ccode\u003eread_text()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1286\"\u003e#1286\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1293\"\u003e#1293\u003c/a\u003e; PR by \u003ca href=\"https://github.com/jaideeppyne\"\u003e\u003ccode\u003e@​jaideeppyne\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eamap\u003c/code\u003e, \u003ccode\u003egather\u003c/code\u003e, and \u003ccode\u003eas_completed\u003c/code\u003e utility functions to simplify common patterns (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1173\"\u003e#1173\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003e--anyio-mode\u003c/code\u003e command-line option as an alternative to the \u003ccode\u003eanyio_mode\u003c/code\u003e ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: \u003ccode\u003epytest_asyncio\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1242\"\u003e#1242\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003eanyio.Future\u003c/code\u003e synchronization primitive which behaves similar to \u003ccode\u003easyncio.Future\u003c/code\u003e, allowing tasks to wait for a value (or exception) from another task (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1146\"\u003e#1146\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Vizonex\"\u003e\u003ccode\u003e@​Vizonex\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded guidance for managing multiple memory object stream producers and consumers with cloned streams (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/330\"\u003e#330\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nightcityblade\"\u003e\u003ccode\u003e@​nightcityblade\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eStapledObjectStream.send_nowait()\u003c/code\u003e that delegates to the underlying \u003ccode\u003eObjectSendStream\u003c/code\u003e, if it implements it (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1241\"\u003e#1241\u003c/a\u003e; PR by \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003emove_on_at()\u003c/code\u003e and \u003ccode\u003efail_at()\u003c/code\u003e functions to complement \u003ccode\u003emove_on_after()\u003c/code\u003e and \u003ccode\u003efail_after()\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the default name for a task spawned with \u003ccode\u003eTaskGroup.create_task(func())\u003c/code\u003e to match the default task name for the analogous task spawned with \u003ccode\u003eTaskGroup.start_soon(func)\u003c/code\u003e or \u003ccode\u003eTaskGroup.start(func)\u003c/code\u003e in more situations. Previously, the default name of a \u003ccode\u003eTaskGroup.create_task\u003c/code\u003e task never included the module name. (The default name for a task spawned with \u003ccode\u003eTaskGroup.start_soon\u003c/code\u003e or \u003ccode\u003eTaskGroup.start\u003c/code\u003e typically includes the module name.) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1234\"\u003e#1234\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the \u003ccode\u003eanyio\u003c/code\u003e and \u003ccode\u003eanyio.abc\u003c/code\u003e modules to lazily (much like \u003ccode\u003e810\u003c/code\u003e) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the \u003ccode\u003eif TYPE_CHECKING:\u003c/code\u003e block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1169\"\u003e#1169\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to \u003ccode\u003estart_blocking_portal()\u003c/code\u003e and \u003ccode\u003eanyio.to_thread.run_sync()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1224\"\u003e#1224\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eSpooledTemporaryFile.readinto()\u003c/code\u003e and \u003ccode\u003ereadinto1()\u003c/code\u003e reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1215\"\u003e#1215\u003c/a\u003e; PR by \u003ca href=\"https://github.com/c-tonneslan\"\u003e\u003ccode\u003e@​c-tonneslan\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded a \u003ccode\u003ereason\u003c/code\u003e parameter to \u003ccode\u003efail_after\u003c/code\u003e (and the new \u003ccode\u003efail_at\u003c/code\u003e) allowing for added exception context when raising \u003ccode\u003eTimeoutError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1227\"\u003e#1227\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the default \u003ccode\u003eTaskHandle.name\u003c/code\u003e missing part of the task name for tasks started with \u003ccode\u003eTaskGroup.start\u003c/code\u003e on Trio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1231\"\u003e#1231\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.run\u003c/code\u003e leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a \u003ccode\u003eRunVar\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1203\"\u003e#1203\u003c/a\u003e; PR by \u003ca href=\"https://github.com/tapetersen\"\u003e\u003ccode\u003e@​tapetersen\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.Path.with_stem()\u003c/code\u003e silently producing a wrong path (e.g. \u003ccode\u003ePath(\u0026quot;.txt\u0026quot;)\u003c/code\u003e) instead of raising \u003ccode\u003eValueError\u003c/code\u003e when given an empty stem on a path with a non-empty suffix, unlike \u003ccode\u003epathlib.PurePath.with_stem\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1200\"\u003e#1200\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Sanjays2402\"\u003e\u003ccode\u003e@​Sanjays2402\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eUNIXSocketStream.aclose()\u003c/code\u003e raising \u003ccode\u003easyncio.InvalidStateError\u003c/code\u003e when a concurrent receive or send operation had just been cancelled on the asyncio backend (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1267\"\u003e#1267\u003c/a\u003e; PR by \u003ca href=\"https://github.com/alloutflo\"\u003e\u003ccode\u003e@​alloutflo\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the pytest plugin importing the deprecated \u003ccode\u003e_pytest.python.CallSpec2\u003c/code\u003e alias, which triggers \u003ccode\u003ePytestRemovedIn10Warning\u003c/code\u003e on \u003ccode\u003epytest\u0026gt;=9.2\u003c/code\u003e and crashes pytest at startup when \u003ccode\u003efilterwarnings = error\u003c/code\u003e is configured (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1271\"\u003e#1271\u003c/a\u003e; PR by \u003ca href=\"https://github.com/matthewfeickert\"\u003e\u003ccode\u003e@​matthewfeickert\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed an asyncio worker thread race that could raise \u003ccode\u003eRuntimeError\u003c/code\u003e when the event loop closed between checking its state and scheduling the worker result (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1265\"\u003e#1265\u003c/a\u003e; PR by \u003ca href=\"https://github.com/hansu650\"\u003e\u003ccode\u003e@​hansu650\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens when \u003ccode\u003etotal_tokens\u003c/code\u003e was raised while the limiter was over-subscribed (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1223\"\u003e#1223\u003c/a\u003e; PR by \u003ca href=\"https://github.com/zelinewang\"\u003e\u003ccode\u003e@​zelinewang\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703\"\u003e\u003ccode\u003effcd154\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f\"\u003e\u003ccode\u003e0ecf5ed\u003c/code\u003e\u003c/a\u003e Added a workaround for third party code accessing unimported submodules (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f\"\u003e\u003ccode\u003e9283662\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d\"\u003e\u003ccode\u003ed137692\u003c/code\u003e\u003c/a\u003e Improved the instructions for AI agents\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265\"\u003e\u003ccode\u003e033fc52\u003c/code\u003e\u003c/a\u003e Shield TemporaryDirectory cleanup from cancellation (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc\"\u003e\u003ccode\u003e942e9a6\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1305\"\u003e#1305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704\"\u003e\u003ccode\u003eb825c3b\u003c/code\u003e\u003c/a\u003e Fixed pyproject.toml changes not triggering the test suite\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af\"\u003e\u003ccode\u003e9727dc5\u003c/code\u003e\u003c/a\u003e Fixed start inconsistencies between trio and asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1198\"\u003e#1198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8\"\u003e\u003ccode\u003eb05fe6d\u003c/code\u003e\u003c/a\u003e Fixed wrong type in move_on_after (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153\"\u003e\u003ccode\u003e44d0c93\u003c/code\u003e\u003c/a\u003e Fixed asyncio task group coroutine cleanup (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1275\"\u003e#1275\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.14.2...4.15.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `build` from 1.5.0 to 1.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/releases\"\u003ebuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.6.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore[v1]: prepare for v1.6.1 by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1181\"\u003epypa/build#1181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.6.0...1.6.1\"\u003ehttps://github.com/pypa/build/compare/1.6.0...1.6.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReplace prettier with mdformat and yamlfmt by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1133\"\u003epypa/build#1133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLet yamlfmt format the workflows by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1134\"\u003epypa/build#1134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(release): semver auto bump, changelog reflow, and roll back 1.5.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1132\"\u003epypa/build#1132\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: hash verification in --dependency-constraints-txt could be silently skipped by \u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): bump build-and-inspect-python-package to v3.0.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1147\"\u003epypa/build#1147\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): pin coverage core to ctrace so test contexts record by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1148\"\u003epypa/build#1148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: run mypy on more parts of the code by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1151\"\u003epypa/build#1151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: turn up strictness on mypy by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1153\"\u003epypa/build#1153\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: faster mypy, fix merge error by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1156\"\u003epypa/build#1156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): rerun integration tests on transient network errors by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1150\"\u003epypa/build#1150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: clean up unused casts in tests by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1154\"\u003epypa/build#1154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(typing): apply review feedback from \u003ca href=\"https://redirect.github.com/pypa/build/issues/1093\"\u003e#1093\u003c/a\u003e by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1155\"\u003epypa/build#1155\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Generator is more accurate than Iterator by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1152\"\u003epypa/build#1152\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: mark test_main_sdist_input_end_to_end with pytest.mark.network by \u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;⚠️ feat(util): deprecate project_wheel_metadata\u0026quot; by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1158\"\u003epypa/build#1158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: download integration sources once per run by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1157\"\u003epypa/build#1157\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse stdlib \u003ccode\u003eimportlib.metadata\u003c/code\u003e for typing by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1162\"\u003epypa/build#1162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop redundant \u003ccode\u003eexc_info\u003c/code\u003e parameter from backend exception wrapper by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1161\"\u003epypa/build#1161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop a few PyPy-specific test skips by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1164\"\u003epypa/build#1164\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1165\"\u003epypa/build#1165\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e👷 ci: use app token for releases by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1169\"\u003epypa/build#1169\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.5.1...1.6.0\"\u003ehttps://github.com/pypa/build/compare/1.5.1...1.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.5.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e✨ feat(cli): accept sdist tarball as srcdir argument by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1057\"\u003epypa/build#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: drop 3.9 branches for version_info checks by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1059\"\u003epypa/build#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: skip test_uv_install_strips_pythonpath with missing uv by \u003ca href=\"https://github.com/mtelka\"\u003e\u003ccode\u003e@​mtelka\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1063\"\u003epypa/build#1063\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove myself from codeowners by \u003ca href=\"https://github.com/FFY00\"\u003e\u003ccode\u003e@​FFY00\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1066\"\u003epypa/build#1066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: safe_extractall to use pathlib.Path by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1060\"\u003epypa/build#1060\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/blob/main/CHANGELOG.rst\"\u003ebuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e####################\n1.6.1 (2026-09-10)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:\u003ccode\u003ehenryiii\u003c/code\u003e (:issue:\u003ccode\u003e1175\u003c/code\u003e) (:issue:\u003ccode\u003e1175\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eDocumentation\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eFix doubled backslashes in the Windows pip config path (\u003ccode\u003e%APPDATA%\\pip\\pip.ini\u003c/code\u003e) in the docs - by :user:\u003ccode\u003earoh3006\u003c/code\u003e\n(:issue:\u003ccode\u003e1149\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eMiscellaneous\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e:issue:\u003ccode\u003e1168\u003c/code\u003e, :issue:\u003ccode\u003e1170\u003c/code\u003e, :issue:\u003ccode\u003e1178\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e####################\n1.6.0 (2026-08-27)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eFeatures\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003e--report=PATH\u003c/code\u003e to write a machine-readable JSON report of built artifacts; \u003ccode\u003e--metadata\u003c/code\u003e now also accepts\n\u003ccode\u003e.whl\u003c/code\u003e files - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e198\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esrcdir\u003c/code\u003e argument now accepts \u003ccode\u003e.tar.gz\u003c/code\u003e source distributions, extracting and building from them - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e311\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u0026quot;Unmet dependencies\u0026quot; error from \u003ccode\u003e--no-isolation\u003c/code\u003e builds now shows the wanted version, found version, and\ninterpreter - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e504\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e to extract the intermediate sdist into a persistent directory, enabling compiler cache\nreuse across rebuilds - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e614\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--env-dir\u003c/code\u003e to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds\n\u003cul\u003e\n\u003cli\u003eby :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e655\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePrint a summary of resolved dependency versions (\u003ccode\u003ename==version\u003c/code\u003e) after installing them in isolated builds - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e959\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eOn build failure, print a tip pointing to \u003ccode\u003e--env-dir\u003c/code\u003e and \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e for debugging and link to the\n\u0026quot;Debug a failed build\u0026quot; how-to - reported by :user:\u003ccode\u003edimpase\u003c/code\u003e, implemented by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e966\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/89cccef40df9011f03bec18cf52c53d1096ed6ee\"\u003e\u003ccode\u003e89cccef\u003c/code\u003e\u003c/a\u003e chore: prepare for 1.6.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/a6f707a75fc8548d7707645e97c7903197387849\"\u003e\u003ccode\u003ea6f707a\u003c/code\u003e\u003c/a\u003e ci: support releases from v* branches (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1178\"\u003e#1178\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/77851610de5d3894fa8a88e06e0232901cf93758\"\u003e\u003ccode\u003e7785161\u003c/code\u003e\u003c/a\u003e docs: fix doubled backslashes in Windows pip config path (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1149\"\u003e#1149\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/244b250c3219070eebb29764f7709262d48afd41\"\u003e\u003ccode\u003e244b250\u003c/code\u003e\u003c/a\u003e fix: always use copies for the isolated venv on Windows (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1176\"\u003e#1176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/c93ca6f6d252e4d8df7fda4a61f8f9ed8a55a411\"\u003e\u003ccode\u003ec93ca6f\u003c/code\u003e\u003c/a\u003e build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/e02ffd32241aec2e306d90869417c1e900c0adb4\"\u003e\u003ccode\u003ee02ffd3\u003c/code\u003e\u003c/a\u003e pre-commit: bump repositories (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1173\"\u003e#1173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/aad39a800e3d81bf907018ebe2fab135717da59b\"\u003e\u003ccode\u003eaad39a8\u003c/code\u003e\u003c/a\u003e docs: fix changelog page heading levels and sidebar (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1171\"\u003e#1171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/5c3fd46b5c38c7caea5dd95ce365971104a734aa\"\u003e\u003ccode\u003e5c3fd46\u003c/code\u003e\u003c/a\u003e docs: use PyPI ref directly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/1c5bd6c21cbd33c1816978d45219d48fb4c2b269\"\u003e\u003ccode\u003e1c5bd6c\u003c/code\u003e\u003c/a\u003e 🐛 fix(release): format generated changelog (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1170\"\u003e#1170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/7f0cc7ed19969558c7daeaa3652ce2ffc81599c1\"\u003e\u003ccode\u003e7f0cc7e\u003c/code\u003e\u003c/a\u003e 🔧 build(type): replace mypy with pyrefly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1168\"\u003e#1168\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/build/compare/1.5.0...1.6.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `certifi` from 2026.6.17 to 2026.7.22\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/f4bc676bc101fe2235846e37044e8c693d6cbaf4\"\u003e\u003ccode\u003ef4bc676\u003c/code\u003e\u003c/a\u003e 2026.07.22 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/428\"\u003e#428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/4c91f9c5f9b4676d40d2930025ba04d80dd536f6\"\u003e\u003ccode\u003e4c91f9c\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.3.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/427\"\u003e#427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/01a66c5cf32eadb8f03a0504c24cb44f6d581248\"\u003e\u003ccode\u003e01a66c5\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/426\"\u003e#426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/eb355f41cb71f71012ecf1a4d27a57d0ee2b1337\"\u003e\u003ccode\u003eeb355f4\u003c/code\u003e\u003c/a\u003e Bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/425\"\u003e#425\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/474e6fc996d55b91632248da0bade702504e62dc\"\u003e\u003ccode\u003e474e6fc\u003c/code\u003e\u003c/a\u003e Include tests in the source distribution (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/a31ef39bb5906af7dc9729890f7e4e04e75afdae\"\u003e\u003ccode\u003ea31ef39\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.2.0 to 6.3.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/420\"\u003e#420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/98eb2c76a9c7a8519912023dca00f762bbcd59af\"\u003e\u003ccode\u003e98eb2c7\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6.0.3 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/419\"\u003e#419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/certifi/python-certifi/compare/2026.06.17...2026.07.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cffi` from 2.1.0 to 2.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-cffi/cffi/releases\"\u003ecffi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMinimize internal Python API usage for interpreter and thread state sampling where possible. Avoids breaking ABI change in Python \u0026gt;= 3.15.0b4 (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/pull/269\"\u003epython-cffi/cffi#269\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/fd33e7700f0ebafe6f30bd5053f13327221b77a2\"\u003e\u003ccode\u003efd33e77\u003c/code\u003e\u003c/a\u003e New release 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/56a7876b8cd3b2d8148233a90e0121d74cd83852\"\u003e\u003ccode\u003e56a7876\u003c/code\u003e\u003c/a\u003e Use PyGILState_Ensure to avoid accessing CPython internals (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/269\"\u003e#269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/270\"\u003e#270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `charset-normalizer` from 3.4.9 to 3.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/releases\"\u003echarset-normalizer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.5.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.5.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md\"\u003echarset-normalizer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/e239bdc5cc1eb1f0db08d4046ad531f805dbea71\"\u003e\u003ccode\u003ee239bdc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/795\"\u003e#795\u003c/a\u003e from jawah/release-3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/648ad776db64a00aa7efd70a94656ac43784abb3\"\u003e\u003ccode\u003e648ad77\u003c/code\u003e\u003c/a\u003e docs: update faq\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/fab27492c39baa61aca12826022e266781108570\"\u003e\u003ccode\u003efab2749\u003c/code\u003e\u003c/a\u003e docs: write changelog for 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/7d32774e75d16cccd3d22c758a77fca135952787\"\u003e\u003ccode\u003e7d32774\u003c/code\u003e\u003c/a\u003e chore: bump version to 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/9a69f609f254ba4bfe9d0cbf375728e43360cdf2\"\u003e\u003ccode\u003e9a69f60\u003c/code\u003e\u003c/a\u003e docs: update data/info\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/5dcc6dd81a8a0a4bd525f8d6f508da8285caf402\"\u003e\u003ccode\u003e5dcc6dd\u003c/code\u003e\u003c/a\u003e perf: charinfo cache access optimization in cython\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/ea3b4479270762be1228562c590e5a212727f208\"\u003e\u003ccode\u003eea3b447\u003c/code\u003e\u003c/a\u003e fix: do not validate-decode large payload when md says it's noise\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/char...\n\n_Description has been truncated_","html_url":"https://github.com/RanugaVW/Clario-multiAgent-triage-micro-services/pull/89","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RanugaVW%2FClario-multiAgent-triage-micro-services/issues/89","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/89/packages"}},{"old_version":"5.16.1","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-19T00:34:21.000Z","version_change":"5.16.1 → 5.17.0","issue":{"uuid":"5506479377","node_id":"PR_kwDOUPlOCM8AAAABEKvAXA","number":119,"state":"open","title":"Bump the patch-and-minor group with 5 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T00:34:21.000Z","updated_at":"2026-09-19T00:34:22.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"patch-and-minor","update_count":5,"packages":[{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"transformers","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.30.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"ruff","old_version":"0.16.6","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"},{"name":"onnxruntime","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"}],"path":null,"ecosystem":"pip"},"body":"Bumps the patch-and-minor group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.16.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.30.0` | `1.31.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.29.0` | `1.30.0` |\n\nUpdates `uvicorn` from 0.52.4 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.16.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.30.0 to 1.31.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.31.0] Custom labels for Sandboxes, More resilient downloads and more\u003c/h2\u003e\n\u003ch2\u003e🏷️ Custom labels for Sandboxes\u003c/h2\u003e\n\u003cp\u003eDedicated sandboxes now accept custom labels, attached to the underlying Job. This is useful for cost attribution, bookkeeping, or finding and reconnecting to the sandboxes created by a given controller run. Labels use the same \u003ccode\u003e-l\u003c/code\u003e / \u003ccode\u003e--label KEY=VALUE\u003c/code\u003e syntax as \u003ccode\u003ehf jobs run\u003c/code\u003e. They are merged with the labels the SDK uses internally, and invalid or reserved labels are rejected before a billable Job is started. Pool-based sandboxes are unchanged: custom labels are only accepted for dedicated sandboxes.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e\u0026gt;\u0026gt;\u0026gt; from huggingface_hub import Sandbox\r\n\u0026gt;\u0026gt;\u0026gt; sandbox = Sandbox.create(image=\u0026quot;python:3.12\u0026quot;, labels={\u0026quot;controller-run\u0026quot;: \u0026quot;run-42\u0026quot;})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003ehf sandbox create --label controller-run=run-42 --label team=data-infra\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e[Sandbox] Support custom Job labels by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4824\"\u003e#4824\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📥 More resilient downloads\u003c/h2\u003e\n\u003cp\u003eA batch of fixes makes downloads more robust to unusual server responses, network hiccups and concurrent usage:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eA timeout while waiting for the response headers of a streamed download is now retried and resumed like a body read failure, instead of escaping \u003ccode\u003ehttp_get()\u003c/code\u003e while retries remain.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRegular HTTP downloads no longer fail when the HEAD response has no \u003ccode\u003eContent-Length\u003c/code\u003e. The file size is validated against the GET response when available.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003esnapshot_download\u003c/code\u003e now writes the \u003ccode\u003erefs/\u003c/code\u003e cache file atomically, reusing the logic already used by \u003ccode\u003ehf_hub_download\u003c/code\u003e. This fixes a long-standing race when many concurrent \u003ccode\u003esnapshot_download\u003c/code\u003e calls target the same repo (seen in vLLM / \u003ccode\u003ellm-compressor\u003c/code\u003e).\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003ehf download --dry-run --local-dir ...\u003c/code\u003e no longer copies files from the Hub cache into the destination. On large files and slow disks this looked like a hang and could leave an incomplete file behind.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Share retry handling for stream entry and body failures by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4826\"\u003e#4826\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Tolerate missing HEAD Content-Length by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4805\"\u003e#4805\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Write cache ref file atomically in \u003ccode\u003esnapshot_download\u003c/code\u003e by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4829\"\u003e#4829\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e[Download] Prevent cached file copies during local-dir dry runs by \u003ca href=\"https://github.com/wakamex\"\u003e\u003ccode\u003e@​wakamex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4817\"\u003e#4817\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔌 \u003ccode\u003ehttpx\u003c/code\u003e re-exported for library integrators\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003ehuggingface_hub\u003c/code\u003e now re-exports the HTTP library it uses as \u003ccode\u003ehuggingface_hub.utils.httpx\u003c/code\u003e. Libraries built on top of \u003ccode\u003ehuggingface_hub\u003c/code\u003e that need \u003ccode\u003ehttpx\u003c/code\u003e types or exceptions (typically to catch errors) should import it from there rather than importing \u003ccode\u003ehttpx\u003c/code\u003e directly. v1.x is built on \u003ccode\u003ehttpx\u003c/code\u003e, and v2.x will move to its successor \u003ccode\u003ehttpx2\u003c/code\u003e, so importing through \u003ccode\u003ehuggingface_hub.utils\u003c/code\u003e keeps your code compatible with both. This is only for types and exceptions: to make requests to the Hub, keep using \u003ccode\u003eget_session()\u003c/code\u003e.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom huggingface_hub.utils import httpx\r\n\u003cp\u003etry:\n...\nexcept httpx.HTTPError:\n...\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/package_reference/utilities\"\u003eUtilities — The \u003ccode\u003ehttpx\u003c/code\u003e module\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[httpx migration] Expose \u003ccode\u003ehttpx\u003c/code\u003e as a \u003ccode\u003ehuggingface_hub\u003c/code\u003e submodule by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4803\"\u003e#4803\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eHfFileSystem.get()\u003c/code\u003e now validates remote filenames before writing anything locally. A server-side filename such as \u003ccode\u003efolder/..\\..\\outside.txt\u003c/code\u003e could previously escape the destination directory on Windows during a recursive download. The same check already protected \u003ccode\u003ehf_hub_download\u003c/code\u003e, \u003ccode\u003esnapshot_download\u003c/code\u003e and bucket sync. Unsafe filenames now raise \u003ccode\u003eValueError\u003c/code\u003e on all platforms, including when downloading to an explicitly named file or a file object.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/495b17c8529614759ae0f1ccf1ebe9a61c148b7c\"\u003e\u003ccode\u003e495b17c\u003c/code\u003e\u003c/a\u003e Release: v1.31.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/0f50db0d43f4e961337caefa64268fed47e31b78\"\u003e\u003ccode\u003e0f50db0\u003c/code\u003e\u003c/a\u003e Release: v1.31.0.rc1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d592df877089d8183489ea606885d777d7cb97f7\"\u003e\u003ccode\u003ed592df8\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;[Jobs] Add network groups to hf jobs run (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4833\"\u003e#4833\u003c/a\u003e)\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/3c08b69fe40b40e155f1fa00760b2b964b62f269\"\u003e\u003ccode\u003e3c08b69\u003c/code\u003e\u003c/a\u003e Release: v1.31.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f14866648507aa58afc9554c712a4e1f70dd5c3e\"\u003e\u003ccode\u003ef148666\u003c/code\u003e\u003c/a\u003e [CLI] Fix truncated command descriptions in the CLI reference (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4849\"\u003e#4849\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/c4f076ccd0b45fc24965a483285f8bbec40e7294\"\u003e\u003ccode\u003ec4f076c\u003c/code\u003e\u003c/a\u003e (LFS)Fix SliceFileObj.\u003cstrong\u003eiter\u003c/strong\u003e yielding only the first 4MB chunk (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4844\"\u003e#4844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/22fe960210ef1805ba88a381b7043123fa9f9714\"\u003e\u003ccode\u003e22fe960\u003c/code\u003e\u003c/a\u003e Fix dotenv parser truncating unquoted values containing '#' (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4842\"\u003e#4842\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6cae778caef0b61dc219d42461fcb20913cb27b9\"\u003e\u003ccode\u003e6cae778\u003c/code\u003e\u003c/a\u003e [Jobs] Add network groups to hf jobs run (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4833\"\u003e#4833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/063b37b1b6090d83660113fa28a58b56fa55444b\"\u003e\u003ccode\u003e063b37b\u003c/code\u003e\u003c/a\u003e [CLI] Raise explicit error for shell-script extensions on Windows (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4846\"\u003e#4846\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b9c14d9a51765d24832dfc2cda5fb826370be61b\"\u003e\u003ccode\u003eb9c14d9\u003c/code\u003e\u003c/a\u003e [Download] Write cache ref file atomically in \u003ccode\u003esnapshot_download\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4829\"\u003e#4829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.30.0...v1.31.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ruff` from 0.16.6 to 0.16.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/releases\"\u003eruff's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md\"\u003eruff's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nightt5879\"\u003e\u003ccode\u003e@​nightt5879\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13\"\u003e\u003ccode\u003eb5dba86\u003c/code\u003e\u003c/a\u003e Bump version to 0.16.7 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28496\"\u003e#28496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24\"\u003e\u003ccode\u003e5992d05\u003c/code\u003e\u003c/a\u003e Install rustfmt before linting releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28495\"\u003e#28495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8\"\u003e\u003ccode\u003e1713a1f\u003c/code\u003e\u003c/a\u003e ensure prepare release changes pass prek (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28488\"\u003e#28488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334\"\u003e\u003ccode\u003e18cdbb4\u003c/code\u003e\u003c/a\u003e use scoped token for release workflow (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28484\"\u003e#28484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd\"\u003e\u003ccode\u003ec3813a5\u003c/code\u003e\u003c/a\u003e add a workflow for preparing releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28486\"\u003e#28486\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38\"\u003e\u003ccode\u003e00948c0\u003c/code\u003e\u003c/a\u003e Remove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427\"\u003e\u003ccode\u003e86a2eba\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (`UP...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/609e184aa35f0034b7ef63e3e04327081c484af6\"\u003e\u003ccode\u003e609e184\u003c/code\u003e\u003c/a\u003e Stop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/859ff2f01670c43ffff1ea597c8a2e375ada0fbe\"\u003e\u003ccode\u003e859ff2f\u003c/code\u003e\u003c/a\u003e [ty] Track symlinked directory status in listings (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28482\"\u003e#28482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/77f653825800ddaf3bc221ae6db49a500e1002d5\"\u003e\u003ccode\u003e77f6538\u003c/code\u003e\u003c/a\u003e Use paid GitHub-hosted runners for Linux (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28478\"\u003e#28478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `onnxruntime` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxruntime/releases\"\u003eonnxruntime's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eONNX Runtime v1.30.0\u003c/h2\u003e\n\u003cp\u003eONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32168\"\u003e#32168\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32340\"\u003e#32340\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32515\"\u003e#32515\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31727\"\u003e#31727\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32277\"\u003e#32277\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32284\"\u003e#32284\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32420\"\u003e#32420\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31674\"\u003e#31674\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31973\"\u003e#31973\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32178\"\u003e#32178\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32356\"\u003e#32356\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements \u0026amp; Compatibility\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with \u003ccode\u003e-Donnxruntime_USE_FP4_QMOE=OFF\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32096\"\u003e#32096\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32163\"\u003e#32163\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and \u003ccode\u003eblock_size=32\u003c/code\u003e. Set \u003ccode\u003e-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON\u003c/code\u003e when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32324\"\u003e#32324\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCPU FP16 \u003ccode\u003eGemm\u003c/code\u003e and \u003ccode\u003eMatMul\u003c/code\u003e execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32301\"\u003e#32301\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32197\"\u003e#32197\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eWebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32287\"\u003e#32287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31960\"\u003e#31960\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31970\"\u003e#31970\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSecurity \u0026amp; Reliability\u003c/h2\u003e\n\u003ch3\u003eModel Loading, Memory, and Input Validation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimited nested model-graph depth and canonicalized external-data locations to harden model loading (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32344\"\u003e#32344\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32135\"\u003e#32135\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32010\"\u003e#32010\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32040\"\u003e#32040\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eStrengthened shape, rank, and parameter validation for \u003ccode\u003eSplit\u003c/code\u003e, \u003ccode\u003eScan\u003c/code\u003e, \u003ccode\u003eGatherND\u003c/code\u003e, \u003ccode\u003eScatterND\u003c/code\u003e, \u003ccode\u003eSpaceToDepth\u003c/code\u003e/\u003ccode\u003eDepthToSpace\u003c/code\u003e, \u003ccode\u003eCrop\u003c/code\u003e, \u003ccode\u003eConv\u003c/code\u003e, \u003ccode\u003eNormalizer\u003c/code\u003e, and pooling (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29461\"\u003e#29461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31668\"\u003e#31668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32034\"\u003e#32034\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32039\"\u003e#32039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32076\"\u003e#32076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32157\"\u003e#32157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32160\"\u003e#32160\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32161\"\u003e#32161\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32345\"\u003e#32345\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32349\"\u003e#32349\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eHardened generation and attention input handling, including attention-attribute narrowing, \u003ccode\u003eBifurcationDetector\u003c/code\u003e inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31648\"\u003e#31648\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31701\"\u003e#31701\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32009\"\u003e#32009\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32078\"\u003e#32078\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32144\"\u003e#32144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eValidated \u003ccode\u003eTreeEnsemble\u003c/code\u003e node references and bounded subtree comparison, rejected non-finite CPU \u003ccode\u003eRoiAlign\u003c/code\u003e coordinates, and required \u003ccode\u003eImageScaler\u003c/code\u003e bias to match the channel count (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32031\"\u003e#32031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32043\"\u003e#32043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32011\"\u003e#32011\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32002\"\u003e#32002\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded an allowlist of safe LoRA adapter parameter data types, validated \u003ccode\u003eMatMulFpQ4\u003c/code\u003e shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31682\"\u003e#31682\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32032\"\u003e#32032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32007\"\u003e#32007\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eGPU Bounds and Resource Lifetimes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHardened CUDA indexing and buffer-size arithmetic in \u003ccode\u003eMatMulNBits\u003c/code\u003e, \u003ccode\u003eRemovePadding\u003c/code\u003e, \u003ccode\u003eRotaryEmbedding\u003c/code\u003e, \u003ccode\u003eSparseAttention\u003c/code\u003e, Whisper beam search, NMS, QDQ, and \u003ccode\u003eGatherElements\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31643\"\u003e#31643\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31994\"\u003e#31994\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31995\"\u003e#31995\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31996\"\u003e#31996\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31998\"\u003e#31998\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32014\"\u003e#32014\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32029\"\u003e#32029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32030\"\u003e#32030\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32137\"\u003e#32137\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32330\"\u003e#32330\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31997\"\u003e#31997\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept \u003ccode\u003eCudaAsyncBuffer\u003c/code\u003e staging storage alive across CUDA graph replay (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31968\"\u003e#31968\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32121\"\u003e#32121\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32364\"\u003e#32364\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32063\"\u003e#32063\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32317\"\u003e#32317\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies and Tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29906\"\u003e#29906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32190\"\u003e#32190\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32424\"\u003e#32424\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUpdated JavaScript dependencies including \u003ccode\u003ejs-yaml\u003c/code\u003e, \u003ccode\u003ejoi\u003c/code\u003e, \u003ccode\u003efast-uri\u003c/code\u003e, and the Next.js end-to-end fixture (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32397\"\u003e#32397\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32486\"\u003e#32486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32488\"\u003e#32488\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32505\"\u003e#32505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32508\"\u003e#32508\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32176\"\u003e#32176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32005\"\u003e#32005\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32440\"\u003e#32440\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003ch3\u003eCore APIs \u0026amp; Runtime\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExtended memory importing with host-pointer support and added access to preallocated outputs through \u003ccode\u003eKernelContext::GetPreallocatedOutput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29726\"\u003e#29726\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32089\"\u003e#32089\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32283\"\u003e#32283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32321\"\u003e#32321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32312\"\u003e#32312\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded DeepSeek Engram contrib operators, \u003ccode\u003eEngramGate\u003c/code\u003e and \u003ccode\u003eNGramHashMapping\u003c/code\u003e, and expanded kernel coverage for Qwen-3.5 operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32106\"\u003e#32106\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/f2c39fe2f838cf35ce7da92824f5a5e3ee6e88a7\"\u003e\u003ccode\u003ef2c39fe\u003c/code\u003e\u003c/a\u003e [CUDA] Add INT4 paged KV cache with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32515\"\u003e#32515\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/5894ba8a53526b3aeb702bd86e6b117c9df8fa4f\"\u003e\u003ccode\u003e5894ba8\u003c/code\u003e\u003c/a\u003e Add portable random-access file reads to Env (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/a2ee3eb43052de307003e6256fc9258ce19d9c34\"\u003e\u003ccode\u003ea2ee3eb\u003c/code\u003e\u003c/a\u003e Fix CUDA plugin device discovery on WSL (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32517\"\u003e#32517\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/b652e595b04d202b7f71af1d9105a183fac2b100\"\u003e\u003ccode\u003eb652e59\u003c/code\u003e\u003c/a\u003e [WebGPU] Prepack Conv weights for the im2col-matmul path (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32420\"\u003e#32420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/0f0f29f5015f16926912ae47061e6a3eedcfbe04\"\u003e\u003ccode\u003e0f0f29f\u003c/code\u003e\u003c/a\u003e Get rid of spurious warning about not being able to find spectre mitigation (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/23dd6510fd395b4556f474c1c0079be2a8b7a8c8\"\u003e\u003ccode\u003e23dd651\u003c/code\u003e\u003c/a\u003e Register ONNX schemas only when static registration is disabled (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32353\"\u003e#32353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/33af5d32801b2e631ebece4f382f4ba775f17d8c\"\u003e\u003ccode\u003e33af5d3\u003c/code\u003e\u003c/a\u003e Release external data loaders after graph initialization (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32502\"\u003e#32502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/2e3c24d5963d62d0bd7c9d306433b19b7304d5d2\"\u003e\u003ccode\u003e2e3c24d\u003c/code\u003e\u003c/a\u003e Clarify external initializer and EP context path interaction (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32442\"\u003e#32442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/e76036b8e49515ee7dd2dd0ac39c9d8b7533d38a\"\u003e\u003ccode\u003ee76036b\u003c/code\u003e\u003c/a\u003e [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32433\"\u003e#32433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/82583c5b6398a9c37815f91e9cd1d7c165a132a7\"\u003e\u003ccode\u003e82583c5\u003c/code\u003e\u003c/a\u003e Add session option for a BNHS GroupQueryAttention Value cache layout (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32139\"\u003e#32139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxruntime/compare/v1.29.0...v1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/sachncs/redax/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/sachncs%2Fredax/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"}},{"old_version":"5.15.0","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-19T00:16:35.000Z","version_change":"5.15.0 → 5.17.0","issue":{"uuid":"5506344708","node_id":"PR_kwDOUAvcQ88AAAABEKnzpw","number":7,"state":"open","title":"build(deps): bump the minor-and-patch group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T00:16:35.000Z","updated_at":"2026-09-19T00:20:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"minor-and-patch","update_count":11,"packages":[{"name":"uvicorn","old_version":"0.52.1","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"tiktoken","old_version":"0.13.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"grpcio","old_version":"1.83.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"nvidia-riva-client","old_version":"2.26.0","new_version":"2.27.0","repository_url":"https://github.com/nvidia-riva/python-clients"},{"name":"torch","old_version":"2.13.0+cu130","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"accelerate","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"ty","old_version":"0.0.70","new_version":"0.0.81","repository_url":"https://github.com/astral-sh/ty"},{"name":"ruff","old_version":"0.16.2","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-and-patch group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.1` | `0.53.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |\n| [grpcio](https://github.com/grpc/grpc) | `1.83.0` | `1.84.0` |\n| [nvidia-riva-client](https://github.com/nvidia-riva/python-clients) | `2.26.0` | `2.27.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0+cu130` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.14.0` | `1.15.0` |\n| [ty](https://github.com/astral-sh/ty) | `0.0.70` | `0.0.81` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.16.2` | `0.16.7` |\n\n\nUpdates `uvicorn` from 0.52.1 to 0.53.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.53.0\u003c/h2\u003e\n\u003ch2\u003e🌐 Opt-in HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003euvicorn\u003c/code\u003e 0.53.0 adds experimental HTTP/2 through \u003ccode\u003ezttp\u003c/code\u003e, alongside a new \u003ccode\u003ezuvloop\u003c/code\u003e integration and connection-handling improvements.\u003c/p\u003e\n\u003cpre lang=\"console\"\u003e\u003ccode\u003euv add uvicorn==0.53.0\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServe HTTP/1.1 and HTTP/2 with \u003ccode\u003ezttp\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e). Install \u003ccode\u003ezttp\u003c/code\u003e, then enable HTTP/2 with \u003ccode\u003e--http zttp --http2\u003c/code\u003e. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP/2 remains experimental.\u003c/strong\u003e Upgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚙️ More event loop choice\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRun Uvicorn with \u003ccode\u003ezuvloop\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e). Install \u003ccode\u003ezuvloop\u003c/code\u003e separately and select it explicitly with \u003ccode\u003e--loop zuvloop\u003c/code\u003e on CPython 3.14 or newer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ More reliable connections and proxies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHonor \u003ccode\u003eConnection: close\u003c/code\u003e token lists\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eTrust IPv6 loopback proxies by default\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e). The default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value now includes \u003ccode\u003e::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eKeep upgraded WebSockets alive\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0\"\u003e0.52.4...0.53.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.4\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.3\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.2\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.53.0 (September 14, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e. Enable it with \u003ccode\u003e--http zttp --http2\u003c/code\u003e.\nUpgrade-based h2c and WebSockets over HTTP/2 are not supported.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd experimental HTTP/2 support through \u003ccode\u003ezttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/2982\"\u003e#2982\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003ezuvloop\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3104\"\u003e#3104\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHandle comma-separated, case-insensitive \u003ccode\u003eConnection: close\u003c/code\u003e tokens across HTTP implementations (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3103\"\u003e#3103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTrust IPv6 loopback in the default \u003ccode\u003eFORWARDED_ALLOW_IPS\u003c/code\u003e value (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCancel the HTTP keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.4 (August 18, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.3 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.2 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee\"\u003e\u003ccode\u003e421708f\u003c/code\u003e\u003c/a\u003e Version 0.53.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3136\"\u003e#3136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23\"\u003e\u003ccode\u003ef1a1bff\u003c/code\u003e\u003c/a\u003e Unset the keep-alive timer when upgrading to WebSocket (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3107\"\u003e#3107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc\"\u003e\u003ccode\u003e63971ed\u003c/code\u003e\u003c/a\u003e Document HTTP/2 support (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3130\"\u003e#3130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a\"\u003e\u003ccode\u003e7d1a005\u003c/code\u003e\u003c/a\u003e Remove race from multiprocess health check test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3128\"\u003e#3128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9\"\u003e\u003ccode\u003e5ac6265\u003c/code\u003e\u003c/a\u003e Add ::1 to FORWARDED_ALLOW_IPS (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3119\"\u003e#3119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6\"\u003e\u003ccode\u003e098b206\u003c/code\u003e\u003c/a\u003e Remove timing race from SIGHUP supervisor test (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3127\"\u003e#3127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d\"\u003e\u003ccode\u003e968f15e\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3113\"\u003e#3113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b\"\u003e\u003ccode\u003e7d4c08c\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9\"\u003e\u003ccode\u003efe528a4\u003c/code\u003e\u003c/a\u003e Require explicit opt-in for zttp HTTP/2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3101\"\u003e#3101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf\"\u003e\u003ccode\u003efa324a4\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3121\"\u003e#3121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.1...0.53.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.13.4 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tiktoken` from 0.13.0 to 0.14.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/tiktoken/blob/main/CHANGELOG.md\"\u003etiktoken's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v0.14.0]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBuild wheels for Python 3.15\u003c/li\u003e\n\u003cli\u003eSupport looking up more GPT-5 series models\u003c/li\u003e\n\u003cli\u003eUpgrade dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4e71bbe0c078468e00fefbf94b39849389f346e5\"\u003e\u003ccode\u003e4e71bbe\u003c/code\u003e\u003c/a\u003e Release 0.14.0 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/212b893ba940cba53476851103d2e5c1d0020c6e\"\u003e\u003ccode\u003e212b893\u003c/code\u003e\u003c/a\u003e Fail open for GPT-5 model tokenisers (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/596\"\u003e#596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4187ba33e48b7c554de02c17149ff0c5e50ddf38\"\u003e\u003ccode\u003e4187ba3\u003c/code\u003e\u003c/a\u003e Upgrade dependencies (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/595\"\u003e#595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/92a82552fc5d046839f83e3505a6d9b002208ac2\"\u003e\u003ccode\u003e92a8255\u003c/code\u003e\u003c/a\u003e Remove test-skip comment for macOS arm64 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/562\"\u003e#562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/674f5e65caad92c2b17f944fbdc4256fea32890e\"\u003e\u003ccode\u003e674f5e6\u003c/code\u003e\u003c/a\u003e Build Python 3.15 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/594\"\u003e#594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/dbea866194b3c7d496a029c8faf9ad238064a992\"\u003e\u003ccode\u003edbea866\u003c/code\u003e\u003c/a\u003e Remove deprecated freethreading build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/f6782242d03134d18b9a551845fd7d69fd23106e\"\u003e\u003ccode\u003ef678224\u003c/code\u003e\u003c/a\u003e Update cibuildwheel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/08a5f3b2c987ada4fc5aa1f16c643c203fa8acaa\"\u003e\u003ccode\u003e08a5f3b\u003c/code\u003e\u003c/a\u003e ci: use static artifact name for sdist build job (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/535\"\u003e#535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/openai/tiktoken/compare/0.13.0...0.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `grpcio` from 1.83.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003egrpcio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease v1.84.0\u003c/h2\u003e\n\u003cp\u003eThis is release 1.84.0 (\u003ca href=\"https://github.com/grpc/grpc/blob/master/doc/g_stands_for.md\"\u003egimbal\u003c/a\u003e) of gRPC Core.\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release contains refinements, improvements, and bug fixes, with highlights listed below.\u003c/p\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[promise_based_filter] enable v2_non_owning_waker_implementation experiment. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43253\"\u003e#43253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[xDS] allow server listener address to match wildcard port. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43247\"\u003e#43247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[WRR] remove env var guard for custom backend metrics. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43198\"\u003e#43198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[subchannel] enable connection scaling service config fields. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43116\"\u003e#43116\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[subchannel] add metrics as per A94. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43140\"\u003e#43140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix incorrect hostname suffix matching in no_proxy handling (prevents proxy bypass). (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/41915\"\u003e#41915\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eC#\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[C# Grpc.Tools] Add native macOS ARM64 support via universal binaries. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/41222\"\u003e#41222\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePython\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Python] Fix -Werror=unused-result error triggered by Cythonized code. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43313\"\u003e#43313\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Release Python 3.15 wheels publicly. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43259\"\u003e#43259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python][AsyncIO] Fixed reference cycles. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43121\"\u003e#43121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] fix: remove ghost key in grpc.aio.Metadata.\u003cstrong\u003edelitem\u003c/strong\u003e when last value is deleted. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42974\"\u003e#42974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Fix the StatusCode Enums to be int. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43167\"\u003e#43167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Fixed the parenthesis placement. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43111\"\u003e#43111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Removed \u003ccode\u003eUsageError\u003c/code\u003e exception from registered method. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43086\"\u003e#43086\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Added registered methods support in AsyncIO stack . (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/41796\"\u003e#41796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] AIO Part 4 - Typehints fixes and add Pyright for aio/_channel.py. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42736\"\u003e#42736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43000\"\u003e#43000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Observability plugin fixes. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42785\"\u003e#42785\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRuby\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Ruby] Fix: Addressed Array of strings passed as metadata. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42827\"\u003e#42827\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRelease v1.84.0-pre2\u003c/h2\u003e\n\u003cp\u003eThis is a prerelease of gRPC Core 1.84.0 (gimbal).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis is a Python-only pre-release that introduces pre-built wheels for Python 3.15.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/3252a89f10d8e92997862167ca7d095ecda85973\"\u003e\u003ccode\u003e3252a89\u003c/code\u003e\u003c/a\u003e Bump release version to 1.84.0 on v1.84.x branch (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43405\"\u003e#43405\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/c633e391bb20236fa7bd07b3fcce600d66a3ca69\"\u003e\u003ccode\u003ec633e39\u003c/code\u003e\u003c/a\u003e [Release] Bump version to 1.84.0-pre2 (on v1.84.x branch) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43401\"\u003e#43401\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/12cafeedefae1bcb27f7ae69d8bccf26f8270145\"\u003e\u003ccode\u003e12cafee\u003c/code\u003e\u003c/a\u003e [Backport][v1.84.x] Revert \u0026quot;[Python] Revert Python 3.15 changes due to sanity...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/56e86cb3b88de5b01cc5112e9c3c33be24c47aa5\"\u003e\u003ccode\u003e56e86cb\u003c/code\u003e\u003c/a\u003e Bump release version to 1.84.0-pre1 on v1.84.x branch (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43327\"\u003e#43327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/7ef6a9efc3a1518d838dfb250cffe520a59185ac\"\u003e\u003ccode\u003e7ef6a9e\u003c/code\u003e\u003c/a\u003e [build] Source reflection and channelz v1 schemas from BCR (\u003ca href=\"https://github.com/grpc\"\u003e\u003ccode\u003e@​grpc\u003c/code\u003e\u003c/a\u003e_proto) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43\"\u003e#43\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/c337c3e372ae1fcd0d94b9c461618f953c55478a\"\u003e\u003ccode\u003ec337c3e\u003c/code\u003e\u003c/a\u003e [core][filters] Unit test framework for v3 filter (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/42969\"\u003e#42969\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/ce22bb46d6befd39539d931bdb4b1c05de14df83\"\u003e\u003ccode\u003ece22bb4\u003c/code\u003e\u003c/a\u003e [PH2][CHTTP2] Retire stream flow control delta early to avoid data race\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/25c16f90b8103107dab0b5ff4c474aa9c50b04c7\"\u003e\u003ccode\u003e25c16f9\u003c/code\u003e\u003c/a\u003e [PH2][Test] Add destructor tests for the Seq promise combinator.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/a7fabec4d888e3500c87d455e66ae503ec5c8b4c\"\u003e\u003ccode\u003ea7fabec\u003c/code\u003e\u003c/a\u003e [Python] Fix -Werror=unused-result error triggered by Cythonized code (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43313\"\u003e#43313\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/d92ee432237eb7fec6ae74646a6bbe1d99027a79\"\u003e\u003ccode\u003ed92ee43\u003c/code\u003e\u003c/a\u003e [util] remove LoadFile() option to append null byte (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/41478\"\u003e#41478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc/compare/v1.83.0...v1.84.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nvidia-riva-client` from 2.26.0 to 2.27.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nvidia-riva/python-clients/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.13.0+cu130 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.14.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#security\"\u003eSecurity\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003ch2\u003etorch.nn\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003etorch.nn.LinearCrossEntropyOptions\u003c/code\u003e no longer accepts \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e; use \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e instead (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188283\"\u003e#188283\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003e\u0026quot;balanced\u0026quot;\u003c/code\u003e policy was removed because \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e provides the same weight-gradient accumulation precision with lower memory use on CUDA, already uses the equivalent scratch layout for mixed-precision inputs on other devices, and was never selected by \u003ccode\u003e\u0026quot;auto\u0026quot;\u003c/code\u003e. Constructing the options with \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e now raises \u003ccode\u003eValueError: invalid acc_policy: 'balanced'; expected one of 'auto', 'accurate', 'compact'\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBefore:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;balanced\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n    input, linear_weight, target, options=options\r\n)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eAfter:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;compact\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pytorch/pytorch/commits/v2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.14.0 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/6afc1e5ee217051fde702b23de2813344dc0fd33\"\u003e\u003ccode\u003e6afc1e5\u003c/code\u003e\u003c/a\u003e Release: v1.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/636a9343b4265db1212b04c778b8910b5cbfa713\"\u003e\u003ccode\u003e636a934\u003c/code\u003e\u003c/a\u003e Fix nightly CI: tensor parallel size detection and DeepSpeed warmup steps (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/385d9fb40bdb92b0cb34775ad0ef493c171e559f\"\u003e\u003ccode\u003e385d9fb\u003c/code\u003e\u003c/a\u003e docs: fix three dead links left by the docs restructure (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4230\"\u003e#4230\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/c424d0b82d4ed61672bf30f1a81ce80370fd945a\"\u003e\u003ccode\u003ec424d0b\u003c/code\u003e\u003c/a\u003e docs: fix garbled sentence in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4231\"\u003e#4231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/0f7e35fe7902cc6ba8dc01b146d6447900464b88\"\u003e\u003ccode\u003e0f7e35f\u003c/code\u003e\u003c/a\u003e Clip grad norm support for dtensors (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/b2ac5095f04585043e21d295afe3aaaacdcc8357\"\u003e\u003ccode\u003eb2ac509\u003c/code\u003e\u003c/a\u003e Fix FSDP2/ PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/33e8bc499254e7f3886db3f8a277d05a4ad2667e\"\u003e\u003ccode\u003e33e8bc4\u003c/code\u003e\u003c/a\u003e Fix load_accelerator_state only restoring one RNG backend (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4217\"\u003e#4217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/50de3ad45f4da279819529e443ba746eb5b3b187\"\u003e\u003ccode\u003e50de3ad\u003c/code\u003e\u003c/a\u003e Treat MPS out-of-memory errors as OOM in find_executable_batch_size (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4227\"\u003e#4227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/ab5fe8e507366f814fee59138eb96b9879cb05d6\"\u003e\u003ccode\u003eab5fe8e\u003c/code\u003e\u003c/a\u003e feat: add the neuron device branch in state (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4218\"\u003e#4218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/9baf95be958c3fd8b2449d1463e6a89e14f61e7d\"\u003e\u003ccode\u003e9baf95b\u003c/code\u003e\u003c/a\u003e Fix MLFLOW_NESTED_RUN never being able to turn nesting off (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4223\"\u003e#4223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/accelerate/compare/v1.14.0...v1.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ty` from 0.0.70 to 0.0.81\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/releases\"\u003ety's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.81\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-14.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEscape glob characters in anchored directory paths (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28518\"\u003e#28518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIgnore divergent markers when detecting descriptors (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28514\"\u003e#28514\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAnchor default exclude patterns at the project root (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28463\"\u003e#28463\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid rebinding extracted method calls (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28469\"\u003e#28469\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDefault-specialize class objects in meta-protocol checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28265\"\u003e#28265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix MRO ordering for generic bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28172\"\u003e#28172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix assignability of bounded typevars to intersection types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28479\"\u003e#28479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix variadic partial signature reduction (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28586\"\u003e#28586\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle gradual metaclass ancestry and conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28474\"\u003e#28474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve recursive metadata in union transformations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28497\"\u003e#28497\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve runtime comparison semantics when narrowing tagged unions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28053\"\u003e#28053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve wrapped signatures in nominal descriptor checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28466\"\u003e#28466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject reassignment of enum members (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28462\"\u003e#28462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReport override conflicts introduced by new bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28530\"\u003e#28530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eResolve dependencies within correlated inference alternatives (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28252\"\u003e#28252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect instance dictionary storage for slotted classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27749\"\u003e#27749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate explicitly overridden constructor signatures (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28115\"\u003e#28115\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid redundant superclass member inference (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28587\"\u003e#28587\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReuse rendered union elements when displaying types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28494\"\u003e#28494\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMemory usage improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReduce retained AST memory by shrinking expressions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28335\"\u003e#28335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare strings in dependency metadata (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28141\"\u003e#28141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp\"\u003e\u003ccode\u003e@​sharkdp\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ibraheemdev\"\u003e\u003ccode\u003e@​ibraheemdev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mtshiba\"\u003e\u003ccode\u003e@​mtshiba\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/blob/main/CHANGELOG.md\"\u003ety's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.81\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-14.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEscape glob characters in anchored directory paths (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28518\"\u003e#28518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIgnore divergent markers when detecting descriptors (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28514\"\u003e#28514\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCLI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAnchor default exclude patterns at the project root (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28463\"\u003e#28463\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid rebinding extracted method calls (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28469\"\u003e#28469\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDefault-specialize class objects in meta-protocol checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28265\"\u003e#28265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix MRO ordering for generic bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28172\"\u003e#28172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix assignability of bounded typevars to intersection types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28479\"\u003e#28479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix variadic partial signature reduction (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28586\"\u003e#28586\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle gradual metaclass ancestry and conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28474\"\u003e#28474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve recursive metadata in union transformations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28497\"\u003e#28497\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve runtime comparison semantics when narrowing tagged unions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28053\"\u003e#28053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve wrapped signatures in nominal descriptor checks (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28466\"\u003e#28466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject reassignment of enum members (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28462\"\u003e#28462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReport override conflicts introduced by new bases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28530\"\u003e#28530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eResolve dependencies within correlated inference alternatives (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28252\"\u003e#28252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect instance dictionary storage for slotted classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27749\"\u003e#27749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate explicitly overridden constructor signatures (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28115\"\u003e#28115\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid redundant superclass member inference (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28587\"\u003e#28587\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReuse rendered union elements when displaying types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28494\"\u003e#28494\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMemory usage improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReduce retained AST memory by shrinking expressions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28335\"\u003e#28335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare strings in dependency metadata (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28141\"\u003e#28141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp\"\u003e\u003ccode\u003e@​sharkdp\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ibraheemdev\"\u003e\u003ccode\u003e@​ibraheemdev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mtshiba\"\u003e\u003ccode\u003e@​mtshiba\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/carljm\"\u003e\u003ccode\u003e@​carljm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/4edd7724afd129fff0a09241d3fc9b4e7607c038\"\u003e\u003ccode\u003e4edd772\u003c/code\u003e\u003c/a\u003e Bump version to 0.0.81 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4528\"\u003e#4528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/8cfdd79e9ded89997d612f816a8d0f4b0cfb2ca0\"\u003e\u003ccode\u003e8cfdd79\u003c/code\u003e\u003c/a\u003e Use paid GitHub-hosted runners for Linux (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4502\"\u003e#4502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/7fd8e15694f869200f7778082564c5968c50ce30\"\u003e\u003ccode\u003e7fd8e15\u003c/code\u003e\u003c/a\u003e Bump version to 0.0.80 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4501\"\u003e#4501\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/c163f21ed4be7a5608ae5791720b43040b08cf5c\"\u003e\u003ccode\u003ec163f21\u003c/code\u003e\u003c/a\u003e Update dependency prek to v0.4.12 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4494\"\u003e#4494\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/8ce0450332e815c0f734fb84d03d63be3eb96829\"\u003e\u003ccode\u003e8ce0450\u003c/code\u003e\u003c/a\u003e Update prek dependencies (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4495\"\u003e#4495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/5d0aa7a142189fc1955759c2987029b8ff8ef4a7\"\u003e\u003ccode\u003e5d0aa7a\u003c/code\u003e\u003c/a\u003e Update actions/attest-build-provenance action to v4.2.2 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/e22b86b3e6d461af46b549e5ebef5474b6256783\"\u003e\u003ccode\u003ee22b86b\u003c/code\u003e\u003c/a\u003e Update Swatinem/rust-cache action to v2.9.2 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4496\"\u003e#4496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/5cde40f5cb83f1cb164b91282e6a72f3dfe4580c\"\u003e\u003ccode\u003e5cde40f\u003c/code\u003e\u003c/a\u003e Document uv integration and workspace trust settings (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4339\"\u003e#4339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/b4cd79275b7ce22c4cf4208f8b005adb53e92523\"\u003e\u003ccode\u003eb4cd792\u003c/code\u003e\u003c/a\u003e Bump version to 0.0.79 (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ty/commit/52f2d5b12ff4a86f1100f3b9c3e2d61b086d8a89\"\u003e\u003ccode\u003e52f2d5b\u003c/code\u003e\u003c/a\u003e Add a GitHub repository threat model for ty (\u003ca href=\"https://redirect.github.com/astral-sh/ty/issues/4481\"\u003e#4481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/astral-sh/ty/compare/0.0.70...0.0.81\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ruff` from 0.16.2 to 0.16.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/releases\"\u003eruff's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md\"\u003eruff's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.16.7\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-10.\u003c/p\u003e\n\u003ch3\u003ePreview features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Add rule for default values on method receivers (\u003ccode\u003eRUF077\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26700\"\u003e#26700\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eruff\u003c/code\u003e] Recognize \u003ccode\u003ere.prefixmatch\u003c/code\u003e (\u003ccode\u003eRUF039\u003c/code\u003e, \u003ccode\u003eRUF055\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28311\"\u003e#28311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlternate nested quotes inside format spec interpolations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28259\"\u003e#28259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-implicit-str-concat\u003c/code\u003e] Mark fix unsafe when it creates a docstring (\u003ccode\u003eISC003\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/27981\"\u003e#27981\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003eflake8-tidy-imports\u003c/code\u003e] Skip fixes for multi-member imports (\u003ccode\u003eTID254\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/26584\"\u003e#26584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epylint\u003c/code\u003e] Gate \u003ccode\u003eImportCycleError\u003c/code\u003e on Python 3.15 (\u003ccode\u003ePLW0133\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28310\"\u003e#28310\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRule changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect \u003ccode\u003eD211\u003c/code\u003e and \u003ccode\u003eD203\u003c/code\u003e rule conflict diagnostic (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28444\"\u003e#28444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRecognize \u003ccode\u003eslice\u003c/code\u003e and \u003ccode\u003efrozendict\u003c/code\u003e generics (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28477\"\u003e#28477\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop defining \u003ccode\u003e__cached__\u003c/code\u003e for Python 3.15 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28476\"\u003e#28476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (\u003ccode\u003eUP035\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28475\"\u003e#28475\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReuse parser name lookups when interning (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28399\"\u003e#28399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSpeed up inherited configuration resolution (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28299\"\u003e#28299\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eline-length\u003c/code\u003e path in \u003ccode\u003e--config\u003c/code\u003e example (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28392\"\u003e#28392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEmbed archive checksums in the shell installer (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28281\"\u003e#28281\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/The-Compiler\"\u003e\u003ccode\u003e@​The-Compiler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdiniz97\"\u003e\u003ccode\u003e@​mdiniz97\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gorewilliams\"\u003e\u003ccode\u003e@​gorewilliams\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RafaelJohn9\"\u003e\u003ccode\u003e@​RafaelJohn9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qatcod\"\u003e\u003ccode\u003e@​qatcod\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MichaReiser\"\u003e\u003ccode\u003e@​MichaReiser\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntBre\"\u003e\u003ccode\u003e@​ntBre\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nightt5879\"\u003e\u003ccode\u003e@​nightt5879\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13\"\u003e\u003ccode\u003eb5dba86\u003c/code\u003e\u003c/a\u003e Bump version to 0.16.7 (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28496\"\u003e#28496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24\"\u003e\u003ccode\u003e5992d05\u003c/code\u003e\u003c/a\u003e Install rustfmt before linting releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28495\"\u003e#28495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8\"\u003e\u003ccode\u003e1713a1f\u003c/code\u003e\u003c/a\u003e ensure prepare release changes pass prek (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28488\"\u003e#28488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334\"\u003e\u003ccode\u003e18cdbb4\u003c/code\u003e\u003c/a\u003e use scoped token for release workflow (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28484\"\u003e#28484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd\"\u003e\u003ccode\u003ec3813a5\u003c/code\u003e\u003c/a\u003e add a workflow for preparing releases (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28486\"\u003e#28486\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38\"\u003e\u003ccode\u003e00948c0\u003c/code\u003e\u003c/a\u003e Remove the \u0026quot;Who’s Using Ruff?\u0026quot; list (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/issues/28455\"\u003e#28455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427\"\u003e\u003ccode\u003e86a2eba\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003epyupgrade\u003c/code\u003e] Stop recommending removed \u003ccode\u003etyping.no_type_check_decorator\u003c/code\u003e (`UP...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https:/...\n\n_Description has been truncated_","html_url":"https://github.com/Legendary-Gamer970/aim-trainer/pull/7","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Legendary-Gamer970%2Faim-trainer/issues/7","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7/packages"}},{"old_version":"5.15.1","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-19T00:00:03.000Z","version_change":"5.15.1 → 5.17.0","issue":{"uuid":"5506212254","node_id":"PR_kwDOUE4m3s8AAAABEKg5kg","number":14,"state":"closed","title":"chore(deps): bump the python-runtime group across 1 directory with 16 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-25T23:58:36.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-19T00:00:03.000Z","updated_at":"2026-09-25T23:58:38.000Z","time_to_close":604713,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"python-runtime","update_count":16,"packages":[{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"},{"name":"numpy","old_version":"2.5.2","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"onnxruntime","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"openai","old_version":"3.3.1","new_version":"3.14.1","repository_url":"https://github.com/openai/openai-python"},{"name":"piper-tts","old_version":"1.4.2","new_version":"1.8.0","repository_url":"https://github.com/OHF-voice/piper1-gpl"},{"name":"playwright","old_version":"1.55.0","new_version":"1.63.0","repository_url":"https://github.com/microsoft/playwright-python"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"scipy","old_version":"1.18.0","new_version":"1.18.1","repository_url":"https://github.com/scipy/scipy"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"uvicorn","old_version":"0.52.4","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vllm","old_version":"0.27.1","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/vllm"},{"name":"huggingface-hub","old_version":"1.28.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"ninja","old_version":"1.13.0","new_version":"1.13.2","repository_url":"https://github.com/ninja-build/ninja"},{"name":"accelerate","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.15.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-runtime group with 16 updates in the /requirements directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.1` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.29.0` | `1.30.0` |\n| [openai](https://github.com/openai/openai-python) | `3.3.1` | `3.14.1` |\n| [piper-tts](https://github.com/OHF-voice/piper1-gpl) | `1.4.2` | `1.8.0` |\n| [playwright](https://github.com/microsoft/playwright-python) | `1.55.0` | `1.63.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [scipy](https://github.com/scipy/scipy) | `1.18.0` | `1.18.1` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |\n| [vllm](https://github.com/vllm-project/vllm) | `0.27.1` | `0.29.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.28.0` | `1.31.0` |\n| [ninja](https://github.com/ninja-build/ninja) | `1.13.0` | `1.13.2` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.14.0` | `1.15.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.1` | `5.17.0` |\n\n\nUpdates `cryptography` from 46.0.5 to 50.0.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.1 - 2026-08-25\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.\n\u003cp\u003e.. _v50-0-0:\u003c/p\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSECURITY ISSUE\u003c/strong\u003e:\n:func:\u003ccode\u003e~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der\u003c/code\u003e\nand its PEM and S/MIME variants no longer expose distinguishable errors or\ntiming when unwrapping a \u003ccode\u003eRecipientInfo\u003c/code\u003e's \u003ccode\u003eencryptedKey\u003c/code\u003e, which could\nact as a Bleichenbacher oracle for callers that decrypt untrusted messages.\nA random key is now substituted on failure, as described in :rfc:\u003ccode\u003e3218\u003c/code\u003e.\nCredit to \u003cstrong\u003e\u003ca href=\"https://github.com/X1AOxiang\"\u003e\u003ccode\u003e@​X1AOxiang\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e for reporting the issue. \u003cstrong\u003eCVE-2026-69247\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eDeprecated Diffie-Hellman key exchange over finite fields (FFDH).\nEverything FFDH is deprecated, including the types in\n\u003ccode\u003ecryptography.hazmat.primitives.asymmetric.dh\u003c/code\u003e and loading FFDH keys or\nparameters with the key loading APIs. Users should migrate to a more\nmodern key exchange algorithm.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003exof()\u003c/code\u003e class methods to\n:class:\u003ccode\u003e~cryptography.hazmat.primitives.hashes.SHAKE128\u003c/code\u003e and\n:class:\u003ccode\u003e~cryptography.hazmat.primitives.hashes.SHAKE256\u003c/code\u003e for constructing\nalgorithm instances configured for use with\n:class:\u003ccode\u003e~cryptography.hazmat.primitives.hashes.XOFHash\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe :mod:\u003ccode\u003eX.509 verification \u0026lt;cryptography.x509.verification\u0026gt;\u003c/code\u003e APIs are now\nconsidered stable and are subject to our API stability policy.\u003c/li\u003e\n\u003cli\u003eAdded the :doc:\u003ccode\u003e/cobblestone\u003c/code\u003e recipe, an implementation of the\nCobblestone-128 and Cobblestone-256 instantiations of the \u003ccode\u003eC2SP chunked-encryption specification \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;\u003c/code\u003e_ for streaming authenticated\nencryption of large messages.\u003c/li\u003e\n\u003cli\u003eParsing a Signed Certificate Timestamp list now rejects encodings that\ncarry trailing bytes after the list or after an individual SCT, instead of\nsilently ignoring them.\u003c/li\u003e\n\u003cli\u003eAdded support for using :class:\u003ccode\u003e~cryptography.x509.Name\u003c/code\u003e as a field type in\nthe :doc:\u003ccode\u003e/hazmat/asn1/index\u003c/code\u003e module.\u003c/li\u003e\n\u003cli\u003eLoading a public key or an EC private key now rejects DER where the\n\u003ccode\u003esubjectPublicKey\u003c/code\u003e (or EC \u003ccode\u003epublicKey\u003c/code\u003e) \u003ccode\u003eBIT STRING\u003c/code\u003e declares a non-zero\nnumber of unused bits, instead of silently ignoring it.\u003c/li\u003e\n\u003cli\u003eParsing a CRL entry's \u003ccode\u003eInvalidityDate\u003c/code\u003e extension now rejects a\n\u003ccode\u003eGeneralizedTime\u003c/code\u003e that carries fractional seconds or another non-DER form,\nmatching the strict encoding already required for every other X.509 time\nfield.\u003c/li\u003e\n\u003cli\u003e:func:\u003ccode\u003e~cryptography.x509.ocsp.load_der_ocsp_request\u003c/code\u003e and\n:func:\u003ccode\u003e~cryptography.x509.ocsp.load_der_ocsp_response\u003c/code\u003e now reject a request\nor response whose \u003ccode\u003eversion\u003c/code\u003e field is not \u003ccode\u003ev1\u003c/code\u003e, the only version defined\nby RFC 6960, matching the version validation already performed when loading\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/ffde75a2b594822c740a2e4748b56c00548302bf\"\u003e\u003ccode\u003effde75a\u003c/code\u003e\u003c/a\u003e bump for 50.0.1 + changelog (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15520\"\u003e#15520\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/46.0.5...50.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.5.2 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.5.2...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `onnxruntime` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxruntime/releases\"\u003eonnxruntime's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eONNX Runtime v1.30.0\u003c/h2\u003e\n\u003cp\u003eONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32168\"\u003e#32168\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32340\"\u003e#32340\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32515\"\u003e#32515\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31727\"\u003e#31727\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32277\"\u003e#32277\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32284\"\u003e#32284\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32420\"\u003e#32420\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31674\"\u003e#31674\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31973\"\u003e#31973\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32178\"\u003e#32178\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32356\"\u003e#32356\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements \u0026amp; Compatibility\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with \u003ccode\u003e-Donnxruntime_USE_FP4_QMOE=OFF\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32096\"\u003e#32096\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32163\"\u003e#32163\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and \u003ccode\u003eblock_size=32\u003c/code\u003e. Set \u003ccode\u003e-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON\u003c/code\u003e when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32324\"\u003e#32324\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCPU FP16 \u003ccode\u003eGemm\u003c/code\u003e and \u003ccode\u003eMatMul\u003c/code\u003e execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32301\"\u003e#32301\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32197\"\u003e#32197\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eWebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32287\"\u003e#32287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31960\"\u003e#31960\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31970\"\u003e#31970\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSecurity \u0026amp; Reliability\u003c/h2\u003e\n\u003ch3\u003eModel Loading, Memory, and Input Validation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimited nested model-graph depth and canonicalized external-data locations to harden model loading (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32344\"\u003e#32344\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32135\"\u003e#32135\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32010\"\u003e#32010\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32040\"\u003e#32040\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eStrengthened shape, rank, and parameter validation for \u003ccode\u003eSplit\u003c/code\u003e, \u003ccode\u003eScan\u003c/code\u003e, \u003ccode\u003eGatherND\u003c/code\u003e, \u003ccode\u003eScatterND\u003c/code\u003e, \u003ccode\u003eSpaceToDepth\u003c/code\u003e/\u003ccode\u003eDepthToSpace\u003c/code\u003e, \u003ccode\u003eCrop\u003c/code\u003e, \u003ccode\u003eConv\u003c/code\u003e, \u003ccode\u003eNormalizer\u003c/code\u003e, and pooling (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29461\"\u003e#29461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31668\"\u003e#31668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32034\"\u003e#32034\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32039\"\u003e#32039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32076\"\u003e#32076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32157\"\u003e#32157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32160\"\u003e#32160\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32161\"\u003e#32161\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32345\"\u003e#32345\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32349\"\u003e#32349\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eHardened generation and attention input handling, including attention-attribute narrowing, \u003ccode\u003eBifurcationDetector\u003c/code\u003e inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31648\"\u003e#31648\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31701\"\u003e#31701\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32009\"\u003e#32009\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32078\"\u003e#32078\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32144\"\u003e#32144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eValidated \u003ccode\u003eTreeEnsemble\u003c/code\u003e node references and bounded subtree comparison, rejected non-finite CPU \u003ccode\u003eRoiAlign\u003c/code\u003e coordinates, and required \u003ccode\u003eImageScaler\u003c/code\u003e bias to match the channel count (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32031\"\u003e#32031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32043\"\u003e#32043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32011\"\u003e#32011\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32002\"\u003e#32002\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded an allowlist of safe LoRA adapter parameter data types, validated \u003ccode\u003eMatMulFpQ4\u003c/code\u003e shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31682\"\u003e#31682\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32032\"\u003e#32032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32007\"\u003e#32007\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eGPU Bounds and Resource Lifetimes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHardened CUDA indexing and buffer-size arithmetic in \u003ccode\u003eMatMulNBits\u003c/code\u003e, \u003ccode\u003eRemovePadding\u003c/code\u003e, \u003ccode\u003eRotaryEmbedding\u003c/code\u003e, \u003ccode\u003eSparseAttention\u003c/code\u003e, Whisper beam search, NMS, QDQ, and \u003ccode\u003eGatherElements\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31643\"\u003e#31643\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31994\"\u003e#31994\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31995\"\u003e#31995\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31996\"\u003e#31996\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31998\"\u003e#31998\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32014\"\u003e#32014\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32029\"\u003e#32029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32030\"\u003e#32030\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32137\"\u003e#32137\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32330\"\u003e#32330\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31997\"\u003e#31997\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept \u003ccode\u003eCudaAsyncBuffer\u003c/code\u003e staging storage alive across CUDA graph replay (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31968\"\u003e#31968\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32121\"\u003e#32121\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32364\"\u003e#32364\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32063\"\u003e#32063\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32317\"\u003e#32317\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies and Tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29906\"\u003e#29906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32190\"\u003e#32190\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32424\"\u003e#32424\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUpdated JavaScript dependencies including \u003ccode\u003ejs-yaml\u003c/code\u003e, \u003ccode\u003ejoi\u003c/code\u003e, \u003ccode\u003efast-uri\u003c/code\u003e, and the Next.js end-to-end fixture (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32397\"\u003e#32397\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32486\"\u003e#32486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32488\"\u003e#32488\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32505\"\u003e#32505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32508\"\u003e#32508\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32176\"\u003e#32176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32005\"\u003e#32005\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32440\"\u003e#32440\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003ch3\u003eCore APIs \u0026amp; Runtime\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExtended memory importing with host-pointer support and added access to preallocated outputs through \u003ccode\u003eKernelContext::GetPreallocatedOutput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29726\"\u003e#29726\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32089\"\u003e#32089\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32283\"\u003e#32283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32321\"\u003e#32321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32312\"\u003e#32312\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded DeepSeek Engram contrib operators, \u003ccode\u003eEngramGate\u003c/code\u003e and \u003ccode\u003eNGramHashMapping\u003c/code\u003e, and expanded kernel coverage for Qwen-3.5 operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32106\"\u003e#32106\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/f2c39fe2f838cf35ce7da92824f5a5e3ee6e88a7\"\u003e\u003ccode\u003ef2c39fe\u003c/code\u003e\u003c/a\u003e [CUDA] Add INT4 paged KV cache with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32515\"\u003e#32515\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/5894ba8a53526b3aeb702bd86e6b117c9df8fa4f\"\u003e\u003ccode\u003e5894ba8\u003c/code\u003e\u003c/a\u003e Add portable random-access file reads to Env (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/a2ee3eb43052de307003e6256fc9258ce19d9c34\"\u003e\u003ccode\u003ea2ee3eb\u003c/code\u003e\u003c/a\u003e Fix CUDA plugin device discovery on WSL (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32517\"\u003e#32517\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/b652e595b04d202b7f71af1d9105a183fac2b100\"\u003e\u003ccode\u003eb652e59\u003c/code\u003e\u003c/a\u003e [WebGPU] Prepack Conv weights for the im2col-matmul path (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32420\"\u003e#32420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/0f0f29f5015f16926912ae47061e6a3eedcfbe04\"\u003e\u003ccode\u003e0f0f29f\u003c/code\u003e\u003c/a\u003e Get rid of spurious warning about not being able to find spectre mitigation (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/23dd6510fd395b4556f474c1c0079be2a8b7a8c8\"\u003e\u003ccode\u003e23dd651\u003c/code\u003e\u003c/a\u003e Register ONNX schemas only when static registration is disabled (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32353\"\u003e#32353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/33af5d32801b2e631ebece4f382f4ba775f17d8c\"\u003e\u003ccode\u003e33af5d3\u003c/code\u003e\u003c/a\u003e Release external data loaders after graph initialization (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32502\"\u003e#32502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/2e3c24d5963d62d0bd7c9d306433b19b7304d5d2\"\u003e\u003ccode\u003e2e3c24d\u003c/code\u003e\u003c/a\u003e Clarify external initializer and EP context path interaction (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32442\"\u003e#32442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/e76036b8e49515ee7dd2dd0ac39c9d8b7533d38a\"\u003e\u003ccode\u003ee76036b\u003c/code\u003e\u003c/a\u003e [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32433\"\u003e#32433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/82583c5b6398a9c37815f91e9cd1d7c165a132a7\"\u003e\u003ccode\u003e82583c5\u003c/code\u003e\u003c/a\u003e Add session option for a BNHS GroupQueryAttention Value cache layout (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32139\"\u003e#32139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxruntime/compare/v1.29.0...v1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `openai` from 3.3.1 to 3.14.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/openai-python/releases\"\u003eopenai's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.14.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.14.0...v3.14.1\"\u003e3.14.1\u003c/a\u003e (2026-09-15)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e validate retry limits and preserve application errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3867\"\u003e#3867\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/f86c7214093038faa512bd4883558b093bdb8c9a\"\u003ef86c721\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ecorrect typo \u0026quot;th\u0026quot; to \u0026quot;the\u0026quot; in StreamAlreadyConsumed error message (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3022\"\u003e#3022\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/718620397c38a546d2cbbc964983c286db7abf97\"\u003e7186203\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e correct Azure endpoint hostname (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3298\"\u003e#3298\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/543516c4223372a7fb830d560f26d8e6ad081d02\"\u003e543516c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e refresh chat streaming examples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2974\"\u003e#2974\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/54f460ef8c212a7849d10cef69853dffb48c4491\"\u003e54f460e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e split push-to-talk shebang arguments (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3210\"\u003e#3210\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d241ed65c122a964679ca9d102924761956aa71f\"\u003ed241ed6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e use uv in remaining Python launchers (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3821\"\u003e#3821\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8c76c4f5e6ee65c6393e80494d2bbbdc8607e983\"\u003e8c76c4f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003elog only metadata for Live WebSocket diagnostics (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3865\"\u003e#3865\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ccc10f595ff606cf007459aecae6ddc90d02794a\"\u003eccc10f5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eresponses:\u003c/strong\u003e skip structured parsing for commentary (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3861\"\u003e#3861\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/6520df1220a0030c7b45b00a6fa4bf2e9c7396ac\"\u003e6520df1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e bump module_client.py to gpt-5.6 (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3211\"\u003e#3211\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/1493321affb1814fba7b669892e376a119d8d36f\"\u003e1493321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unused fine-tuning data validators (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3863\"\u003e#3863\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/9640f2903d65c43f0e5aee58d60f46880ff0bd15\"\u003e9640f29\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify async client cleanup (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2388\"\u003e#2388\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/a3d83b5af23e4057453aae83dcdb4e3cced1cdad\"\u003ea3d83b5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eclarify filenames for in-memory file uploads (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3729\"\u003e#3729\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/cb27380d95f5e6995ea56dc588914454629cce0f\"\u003ecb27380\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e correct retry jitter comment (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2252\"\u003e#2252\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/bdbbc16a3f289601cb7cbcec9e64c94e95753e94\"\u003ebdbbc16\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix Realtime docstring wording (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3535\"\u003e#3535\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8cb9dedabd03297816749fcadfa12ef3ebcd3ed8\"\u003e8cb9ded\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix reusing wording in Azure client docstrings (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3061\"\u003e#3061\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/dc625f9533cb43e74aea53529c86d4848eed82ec\"\u003edc625f9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix streaming comment typo (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3005\"\u003e#3005\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d421d7ab8c0a5e4e00147407ef9941c7f2bc9c09\"\u003ed421d7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix vector store polling helper paths (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3101\"\u003e#3101\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/2ef2de6bf1603b2df8cb28bcc604c79c6e7f773d\"\u003e2ef2de6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ereadme:\u003c/strong\u003e correct SSE terminology (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2837\"\u003e#2837\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/caaa9b45a24c7698244824cda2c2d9ae16359354\"\u003ecaaa9b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate Responses API reference link (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3279\"\u003e#3279\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/557bd06bce467e7f748b9c86bdde6427e85d28c7\"\u003e557bd06\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e correct query component RFC reference (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3300\"\u003e#3300\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/929a8a500a0e95df090ef53fe38890eba1e97660\"\u003e929a8a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.14.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.13.0...v3.14.0\"\u003e3.14.0\u003c/a\u003e (2026-09-14)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estreaming:\u003c/strong\u003e normalize errors raised while reading streams (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3827\"\u003e#3827\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d7c41efee1b0802b79f3f88a678ef2052b06e9ce\"\u003ed7c41ef\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebound vector store file polling (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3401\"\u003e#3401\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ae41bc46cdd53d17e948ac8a73e16bdbf34123a1\"\u003eae41bc4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexample:\u003c/strong\u003e refresh realtime push_to_talk_app session types (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2926\"\u003e#2926\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/0b7ad38292ef862f1dd07f71543b2f60eade8999\"\u003e0b7ad38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003efiles:\u003c/strong\u003e normalize PathLike upload tuples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3475\"\u003e#3475\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/90ac74ccfe7a966787d1f204755d4cd4cc4d406a\"\u003e90ac74c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003einclude completion in content filter errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3094\"\u003e#3094\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/e57a1b19fbcc32306a691e63334fd2dc4b1a804c\"\u003ee57a1b1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/openai-python/blob/main/CHANGELOG.md\"\u003eopenai's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.14.0...v3.14.1\"\u003e3.14.1\u003c/a\u003e (2026-09-15)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e validate retry limits and preserve application errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3867\"\u003e#3867\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/f86c7214093038faa512bd4883558b093bdb8c9a\"\u003ef86c721\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ecorrect typo \u0026quot;th\u0026quot; to \u0026quot;the\u0026quot; in StreamAlreadyConsumed error message (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3022\"\u003e#3022\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/718620397c38a546d2cbbc964983c286db7abf97\"\u003e7186203\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e correct Azure endpoint hostname (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3298\"\u003e#3298\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/543516c4223372a7fb830d560f26d8e6ad081d02\"\u003e543516c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e refresh chat streaming examples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2974\"\u003e#2974\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/54f460ef8c212a7849d10cef69853dffb48c4491\"\u003e54f460e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e split push-to-talk shebang arguments (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3210\"\u003e#3210\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d241ed65c122a964679ca9d102924761956aa71f\"\u003ed241ed6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e use uv in remaining Python launchers (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3821\"\u003e#3821\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8c76c4f5e6ee65c6393e80494d2bbbdc8607e983\"\u003e8c76c4f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003elog only metadata for Live WebSocket diagnostics (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3865\"\u003e#3865\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ccc10f595ff606cf007459aecae6ddc90d02794a\"\u003eccc10f5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eresponses:\u003c/strong\u003e skip structured parsing for commentary (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3861\"\u003e#3861\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/6520df1220a0030c7b45b00a6fa4bf2e9c7396ac\"\u003e6520df1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eexamples:\u003c/strong\u003e bump module_client.py to gpt-5.6 (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3211\"\u003e#3211\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/1493321affb1814fba7b669892e376a119d8d36f\"\u003e1493321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unused fine-tuning data validators (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3863\"\u003e#3863\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/9640f2903d65c43f0e5aee58d60f46880ff0bd15\"\u003e9640f29\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify async client cleanup (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2388\"\u003e#2388\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/a3d83b5af23e4057453aae83dcdb4e3cced1cdad\"\u003ea3d83b5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eclarify filenames for in-memory file uploads (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3729\"\u003e#3729\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/cb27380d95f5e6995ea56dc588914454629cce0f\"\u003ecb27380\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e correct retry jitter comment (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2252\"\u003e#2252\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/bdbbc16a3f289601cb7cbcec9e64c94e95753e94\"\u003ebdbbc16\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix Realtime docstring wording (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3535\"\u003e#3535\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/8cb9dedabd03297816749fcadfa12ef3ebcd3ed8\"\u003e8cb9ded\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix reusing wording in Azure client docstrings (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3061\"\u003e#3061\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/dc625f9533cb43e74aea53529c86d4848eed82ec\"\u003edc625f9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix streaming comment typo (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3005\"\u003e#3005\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d421d7ab8c0a5e4e00147407ef9941c7f2bc9c09\"\u003ed421d7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix vector store polling helper paths (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3101\"\u003e#3101\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/2ef2de6bf1603b2df8cb28bcc604c79c6e7f773d\"\u003e2ef2de6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ereadme:\u003c/strong\u003e correct SSE terminology (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2837\"\u003e#2837\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/caaa9b45a24c7698244824cda2c2d9ae16359354\"\u003ecaaa9b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate Responses API reference link (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3279\"\u003e#3279\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/557bd06bce467e7f748b9c86bdde6427e85d28c7\"\u003e557bd06\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e correct query component RFC reference (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3300\"\u003e#3300\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/929a8a500a0e95df090ef53fe38890eba1e97660\"\u003e929a8a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/openai/openai-python/compare/v3.13.0...v3.14.0\"\u003e3.14.0\u003c/a\u003e (2026-09-14)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estreaming:\u003c/strong\u003e normalize errors raised while reading streams (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3827\"\u003e#3827\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/d7c41efee1b0802b79f3f88a678ef2052b06e9ce\"\u003ed7c41ef\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebound vector store file polling (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3401\"\u003e#3401\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/ae41bc46cdd53d17e948ac8a73e16bdbf34123a1\"\u003eae41bc4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexample:\u003c/strong\u003e refresh realtime push_to_talk_app session types (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2926\"\u003e#2926\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/0b7ad38292ef862f1dd07f71543b2f60eade8999\"\u003e0b7ad38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003efiles:\u003c/strong\u003e normalize PathLike upload tuples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3475\"\u003e#3475\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/90ac74ccfe7a966787d1f204755d4cd4cc4d406a\"\u003e90ac74c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003einclude completion in content filter errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3094\"\u003e#3094\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/e57a1b19fbcc32306a691e63334fd2dc4b1a804c\"\u003ee57a1b1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003elogging:\u003c/strong\u003e support standard OPENAI_LOG levels (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3734\"\u003e#3734\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/44000e0fc5e11692663045d6183568ff3ec32736\"\u003e44000e0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize API error codes to strings (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3532\"\u003e#3532\u003c/a\u003e) (\u003ca href=\"https://github.com/openai/openai-python/commit/233d9557be3e7ee186b5ac3f1ab634a257134ac1\"\u003e233d955\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3531\"\u003e#3531\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/5bae14cb22724ef0a9db0d3a7fb7556d28b3fee3\"\u003e\u003ccode\u003e5bae14c\u003c/code\u003e\u003c/a\u003e release: 3.14.1 (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3856\"\u003e#3856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/f86c7214093038faa512bd4883558b093bdb8c9a\"\u003e\u003ccode\u003ef86c721\u003c/code\u003e\u003c/a\u003e fix(client): validate retry limits and preserve application errors (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3867\"\u003e#3867\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/6520df1220a0030c7b45b00a6fa4bf2e9c7396ac\"\u003e\u003ccode\u003e6520df1\u003c/code\u003e\u003c/a\u003e fix(responses): skip structured parsing for commentary (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3861\"\u003e#3861\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/b3c04f4e701e07726f320295a38928421946e530\"\u003e\u003ccode\u003eb3c04f4\u003c/code\u003e\u003c/a\u003e fix(azure): preserve deployment routing across copy/with_options (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3593\"\u003e#3593\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/ccc10f595ff606cf007459aecae6ddc90d02794a\"\u003e\u003ccode\u003eccc10f5\u003c/code\u003e\u003c/a\u003e fix: log only metadata for Live WebSocket diagnostics (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3865\"\u003e#3865\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/9640f2903d65c43f0e5aee58d60f46880ff0bd15\"\u003e\u003ccode\u003e9640f29\u003c/code\u003e\u003c/a\u003e chore: remove unused fine-tuning data validators (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3863\"\u003e#3863\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/8cb9dedabd03297816749fcadfa12ef3ebcd3ed8\"\u003e\u003ccode\u003e8cb9ded\u003c/code\u003e\u003c/a\u003e docs: fix Realtime docstring wording (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3535\"\u003e#3535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/a3d83b5af23e4057453aae83dcdb4e3cced1cdad\"\u003e\u003ccode\u003ea3d83b5\u003c/code\u003e\u003c/a\u003e docs: clarify async client cleanup (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2388\"\u003e#2388\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/54f460ef8c212a7849d10cef69853dffb48c4491\"\u003e\u003ccode\u003e54f460e\u003c/code\u003e\u003c/a\u003e fix(examples): refresh chat streaming examples (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/2974\"\u003e#2974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/openai-python/commit/d241ed65c122a964679ca9d102924761956aa71f\"\u003e\u003ccode\u003ed241ed6\u003c/code\u003e\u003c/a\u003e fix(examples): split push-to-talk shebang arguments (\u003ca href=\"https://redirect.github.com/openai/openai-python/issues/3210\"\u003e#3210\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/openai/openai-python/compare/v3.3.1...v3.14.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `piper-tts` from 1.4.2 to 1.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/OHF-voice/piper1-gpl/releases\"\u003epiper-tts's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.8.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Thai phonemizer using TLTK in the new \u003ccode\u003eth\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type thai\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;thai\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng's Thai voice is a placeholder: its \u003ccode\u003eth_dict\u003c/code\u003e holds no lexicon, so unspaced Thai is never segmented; the leading vowels เ แ โ ใ ไ are not reordered; and a tone mark deletes the syllable's vowel, collapsing ป่า/ป้า/ป๊า/ป๋า to the same phonemes\u003c/li\u003e\n\u003cli\u003eTLTK does dictionary-based word segmentation and emits a tone digit (1-5) per syllable, in the same style \u003ccode\u003ephonemize_chinese\u003c/code\u003e uses for Mandarin tones\u003c/li\u003e\n\u003cli\u003eThe whole inventory already has ids in the default IPA map, so Thai voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --th\u003c/code\u003e, and install the \u003ccode\u003eth\u003c/code\u003e extra in CI so the Thai tests run\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.7.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Japanese phonemizer using OpenJTalk (\u003ccode\u003epyopenjtalk-plus\u003c/code\u003e) in the new \u003ccode\u003eja\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type japanese\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;japanese\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng has no kanji coverage (it reads out Unicode character names) and no pitch accent\u003c/li\u003e\n\u003cli\u003eFull-context labels are parsed for pitch accent and mapped to IPA, so Japanese voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --ja\u003c/code\u003e, and install the \u003ccode\u003eja\u003c/code\u003e extra in CI so the Japanese tests run\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibpiper\u003c/code\u003e: add \u003ccode\u003epiper_create_options\u003c/code\u003e and \u003ccode\u003epiper_create_with_options()\u003c/code\u003e, with \u003ccode\u003epiper_create()\u003c/code\u003e kept as a wrapper for ABI compatibility\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.6.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRun the g2pW model through \u003ccode\u003epiper.g2pw_onnx\u003c/code\u003e instead of \u003ccode\u003eg2pw.api\u003c/code\u003e, dropping \u003ccode\u003etorch\u003c/code\u003e (~750 MB installed) and \u003ccode\u003erequests\u003c/code\u003e from the \u003ccode\u003ezh\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eg2pw.api\u003c/code\u003e imports torch only to build padded tensors and iterate batches; the model itself already ran under onnxruntime\u003c/li\u003e\n\u003cli\u003eAlso 1.5-2x faster, since it no longer forks DataLoader worker processes on every call\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eg2pW\u003c/code\u003e is still required, for its pinyin/bopomofo lookup tables\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Hebrew phonemizer using Nakdimon\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003elibpiper\u003c/code\u003e C++ CLI executable ported from the legacy Piper repository, plus a C++ test suite\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003elibpiper\u003c/code\u003e builds on Windows (MSVC, MSYS2-GCC) and Windows CI\u003c/li\u003e\n\u003cli\u003eBump embedded espeak-ng version\u003c/li\u003e\n\u003cli\u003eAdd default speaker id for multi-speaker voices\u003c/li\u003e\n\u003cli\u003eAdd vowel clustering support (\u003ccode\u003e--data.vowel_clusters\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd in-memory patching for alignments\u003c/li\u003e\n\u003cli\u003eTraining: add MRD (Multi-Resolution STFT) discriminator, loss/MOS tracking with UTMOS, silence-trim fixes, and dataloader performance improvements\u003c/li\u003e\n\u003cli\u003ePass custom phoneme id map when training\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/blob/main/CHANGELOG.md\"\u003epiper-tts's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.8.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Thai phonemizer using TLTK in the new \u003ccode\u003eth\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type thai\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;thai\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng's Thai voice is a placeholder: its \u003ccode\u003eth_dict\u003c/code\u003e holds no lexicon, so unspaced Thai is never segmented; the leading vowels เ แ โ ใ ไ are not reordered; and a tone mark deletes the syllable's vowel, collapsing ป่า/ป้า/ป๊า/ป๋า to the same phonemes\u003c/li\u003e\n\u003cli\u003eTLTK does dictionary-based word segmentation and emits a tone digit (1-5) per syllable, in the same style \u003ccode\u003ephonemize_chinese\u003c/code\u003e uses for Mandarin tones\u003c/li\u003e\n\u003cli\u003eThe whole inventory already has ids in the default IPA map, so Thai voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --th\u003c/code\u003e, and install the \u003ccode\u003eth\u003c/code\u003e extra in CI so the Thai tests run\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.7.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Japanese phonemizer using OpenJTalk (\u003ccode\u003epyopenjtalk-plus\u003c/code\u003e) in the new \u003ccode\u003eja\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--data.phoneme_type japanese\u003c/code\u003e for training; \u003ccode\u003e\u0026quot;phoneme_type\u0026quot;: \u0026quot;japanese\u0026quot;\u003c/code\u003e in a voice config for synthesis\u003c/li\u003e\n\u003cli\u003eespeak-ng has no kanji coverage (it reads out Unicode character names) and no pitch accent\u003c/li\u003e\n\u003cli\u003eFull-context labels are parsed for pitch accent and mapped to IPA, so Japanese voices stay compatible with the IPA-based (espeak) warmstart\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escript/setup --ja\u003c/code\u003e, and install the \u003ccode\u003eja\u003c/code\u003e extra in CI so the Japanese tests run\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elibpiper\u003c/code\u003e: add \u003ccode\u003epiper_create_options\u003c/code\u003e and \u003ccode\u003epiper_create_with_options()\u003c/code\u003e, with \u003ccode\u003epiper_create()\u003c/code\u003e kept as a wrapper for ABI compatibility\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.6.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRun the g2pW model through \u003ccode\u003epiper.g2pw_onnx\u003c/code\u003e instead of \u003ccode\u003eg2pw.api\u003c/code\u003e, dropping \u003ccode\u003etorch\u003c/code\u003e (~750 MB installed) and \u003ccode\u003erequests\u003c/code\u003e from the \u003ccode\u003ezh\u003c/code\u003e extra\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eg2pw.api\u003c/code\u003e imports torch only to build padded tensors and iterate batches; the model itself already ran under onnxruntime\u003c/li\u003e\n\u003cli\u003eAlso 1.5-2x faster, since it no longer forks DataLoader worker processes on every call\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eg2pW\u003c/code\u003e is still required, for its pinyin/bopomofo lookup tables\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.6.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Hebrew phonemizer using Nakdimon\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.5.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003elibpiper\u003c/code\u003e C++ CLI executable ported from the legacy Piper repository, plus a C++ test suite\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003elibpiper\u003c/code\u003e builds on Windows (MSVC, MSYS2-GCC) and Windows CI\u003c/li\u003e\n\u003cli\u003eBump embedded espeak-ng version\u003c/li\u003e\n\u003cli\u003eAdd default speaker id for multi-speaker voices\u003c/li\u003e\n\u003cli\u003eAdd vowel clustering support (\u003ccode\u003e--data.vowel_clusters\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd in-memory patching for alignments\u003c/li\u003e\n\u003cli\u003eTraining: add MRD (Multi-Resolution STFT) discriminator, loss/MOS tracking with UTMOS, silence-trim fixes, and dataloader performance improvements\u003c/li\u003e\n\u003cli\u003ePass custom phoneme id map when training\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/639388b6317fc4731e91d53da42aea68fd4166ff\"\u003e\u003ccode\u003e639388b\u003c/code\u003e\u003c/a\u003e Bump version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/46d794711decab265e7f04c8a9a2f03f5d40b244\"\u003e\u003ccode\u003e46d7947\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/OHF-voice/piper1-gpl/issues/293\"\u003e#293\u003c/a\u003e from OHF-Voice/claude/thai-piper-training-feasibility...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/9336d103bd2aa8f94d21c8b14c3e0d7727da292c\"\u003e\u003ccode\u003e9336d10\u003c/code\u003e\u003c/a\u003e Fix Thai test collection aborting CI on a broken optional dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/fb14e09b49725af3cd806d2aba6c9f33501546ce\"\u003e\u003ccode\u003efb14e09\u003c/code\u003e\u003c/a\u003e Add Thai phonemizer (TLTK segmentation + G2P -\u0026gt; IPA + tone digits)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/850c45a3d70b5981de4d908ba98caf39796e7201\"\u003e\u003ccode\u003e850c45a\u003c/code\u003e\u003c/a\u003e fix: Phase 1 relaxed poly fallback for mobile (\u003ca href=\"https://redirect.github.com/OHF-voice/piper1-gpl/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/b2758261878e4d832acb208e33915df8954ae2d4\"\u003e\u003ccode\u003eb275826\u003c/code\u003e\u003c/a\u003e Add Chinese pinyin support – Phase 1 (monophonic dict fallback, honest scopin...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/7b8e8f7197a480047677715f00d3d78903b55a2a\"\u003e\u003ccode\u003e7b8e8f7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/OHF-voice/piper1-gpl/issues/275\"\u003e#275\u003c/a\u003e from OHF-Voice/claude/version-1-7-0-release-2b37ec\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/222159fb3a25672b1a1a6c8f4d5f9351ed68ad3d\"\u003e\u003ccode\u003e222159f\u003c/code\u003e\u003c/a\u003e Silence pylint redefined-outer-name in the phonemizer tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/af4ff76238e6aee94f95555fbff87c001ecf94bc\"\u003e\u003ccode\u003eaf4ff76\u003c/code\u003e\u003c/a\u003e Make the mypy exclude for vendored VITS code actually work\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/OHF-Voice/piper1-gpl/commit/c0f3289b64e2eb704ac115af61cac90228e2f7d2\"\u003e\u003ccode\u003ec0f3289\u003c/code\u003e\u003c/a\u003e Release 1.7.0: add --ja setup flag and test Japanese in CI\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/OHF-voice/piper1-gpl/compare/v1.4.2...v1.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `playwright` from 1.55.0 to 1.63.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/playwright-python/releases\"\u003eplaywright's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.63.0\u003c/h2\u003e\n\u003ch2\u003e🪟 Locate across frames\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/python/docs/api/class-page#page-frame-locator\"\u003epage.frame_locator()\u003c/a\u003e and \u003ca href=\"https://playwright.dev/python/docs/api/class-frame#frame-frame-locator\"\u003eframe.frame_locator()\u003c/a\u003e called without a selector search in any frame of the\nsubtree, so you no longer need to locate the iframe first:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# Finds the button in any frame on the page.\r\npage.frame_locator().get_by_role(\u0026quot;button\u0026quot;).click()\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it\nmatches elements in several frames.\u003c/p\u003e\n\u003ch2\u003e👁️ Visible-only locators\u003c/h2\u003e\n\u003cp\u003eNew \u003ca href=\"https://playwright.dev/python/docs/api/class-locator#locator-visible\"\u003elocator.visible\u003c/a\u003e returns a locator that matches only visible elements. It is the recommended\nreplacement for the \u003ccode\u003e:visible\u003c/code\u003e CSS pseudo-class:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003epage.locator(\u0026quot;button\u0026quot;).visible.click()\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch2\u003e🖼️ Aria and screen snapshots in traces\u003c/h2\u003e\n\u003cp\u003eNew \u003ca href=\"https://playwright.dev/python/docs/api/class-tracing#tracing-start-option-aria-snapshots\"\u003e\u003ccode\u003earia_snapshots\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://playwright.dev/python/docs/api/class-tracing#tracing-start-option-screen-snapshots\"\u003e\u003ccode\u003escreen_snapshots\u003c/code\u003e\u003c/a\u003e options of\n\u003ca href=\"https://playwright.dev/python/docs/api/class-tracing#tracing-start\"\u003etracing.start()\u003c/a\u003e capture an aria snapshot and a screenshot of the page on every action:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003econtext.tracing.start(snapshots=True, aria_snapshots=True, screen_snapshots=True)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eWith aria and screen snapshots recorded, the new \u003cstrong\u003eDisplay Aria\u003c/strong\u003e mode in the trace viewer shows the action screenshot\nside by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.\u003c/p\u003e\n\u003ch2\u003eNew APIs\u003c/h2\u003e\n\u003ch3\u003eBrowser and Context\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://playwright.dev/python/docs/api/class-browser#browser-new-context-option-http-credentials\"\u003e\u003ccode\u003ehttp_credentials\u003c/code\u003e\u003c/a\u003e now also accepts an array of credentials. The first entry matching the request origin is used, and entries without an origin match any request.\u003c/li\u003e\n\u003cli\u003eNew option \u003ca href=\"https://playwright.dev/python/docs/api/class-browsercontext#browser-context-storage-state-option-opfs\"\u003e\u003ccode\u003eopfs\u003c/code\u003e\u003c/a\u003e includes the \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/API/File_System_API/Origin_private_file_system\"\u003eorigin private file system\u003c/a\u003e in the storage state, so it can be persisted and restored into later contexts.\u003c/li\u003e\n\u003cli\u003eNew events \u003ca href=\"https://playwright.dev/python/docs/api/class-page#page-event-dialog-closed\"\u003epage.on('dialogclosed')\u003c/a\u003e and \u003ca href=\"https://playwright.dev/python/docs/api/class-browsercontext#browser-context-event-dialog-closed\"\u003ebrowserContext.on('dialogclosed')\u003c/a\u003e are emitted when a JavaScript dialog is accepted, dismissed or closed by the user.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommand line\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eplaywright install --no-remove\u003c/code\u003e keeps the browsers of other Playwright installations instead of removing them.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eplaywright codegen --http-credentials\u003c/code\u003e records against pages behind HTTP authentication.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e⚠️ Ubuntu 20.04 is not supported anymore.\u003c/li\u003e\n\u003cli\u003e🐧 On Linux arm64, Playwright now downloads the \u003ca href=\"https://developer.chrome.com/blog/chrome-for-testing\"\u003eChrome for Testing\u003c/a\u003e build of Chromium, the same build used on all other platforms.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/8cb967b3e4199bef5ce38e1cf34df1bf79cb8a8d\"\u003e\u003ccode\u003e8cb967b\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3200\"\u003e#3200\u003c/a\u003e): devops(docker): move docker publishing to Azure Pipelines\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/ab18c77c56f64b47e871bf4d8b08fd0675559377\"\u003e\u003ccode\u003eab18c77\u003c/code\u003e\u003c/a\u003e chore: roll Playwright to 1.63.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3198\"\u003e#3198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/0e66a0927e5431b0f659ff41b6544de96b0486f5\"\u003e\u003ccode\u003e0e66a09\u003c/code\u003e\u003c/a\u003e devops(pipeline): resolve pip and npm packages from DevDiv_PublicPackages fee...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/010a9cc73f8a90bc2d7b9e34591c4e2c4a4ea566\"\u003e\u003ccode\u003e010a9cc\u003c/code\u003e\u003c/a\u003e Pin GitHub Actions to full-length commit SHAs (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3176\"\u003e#3176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/154f67ced51ada646b0fcf8574897d96c9712aa3\"\u003e\u003ccode\u003e154f67c\u003c/code\u003e\u003c/a\u003e fix(sync): wait for initialize before leaving \u003cstrong\u003eenter\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3168\"\u003e#3168\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/4af2fc65fb05eb04904b69b6206e9d07ca2b4cbc\"\u003e\u003ccode\u003e4af2fc6\u003c/code\u003e\u003c/a\u003e chore: roll Playwright to 1.62.1 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3169\"\u003e#3169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/4d2e058f43f05448ad29b19e82919be5b86e8349\"\u003e\u003ccode\u003e4d2e058\u003c/code\u003e\u003c/a\u003e fix(connection): register protocol callback only after successful send (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/eab2bca195df8709bd32fc11129c268cf8963cd2\"\u003e\u003ccode\u003eeab2bca\u003c/code\u003e\u003c/a\u003e chore(deps): remove unused development dependencies (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3164\"\u003e#3164\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/3b7c24c3e67dc84f7b0eddd0c5fd2ca685705021\"\u003e\u003ccode\u003e3b7c24c\u003c/code\u003e\u003c/a\u003e chore: roll Playwright to 1.62.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3161\"\u003e#3161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright-python/commit/1db079f769ff42c60b7bde3498fb98f638131534\"\u003e\u003ccode\u003e1db079f\u003c/code\u003e\u003c/a\u003e build(deps): bump typing-extensions from 4.15.0 to 4.16.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright-python/issues/3162\"\u003e#3162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/playwright-python/compare/v1.55.0...v1.63.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.13.4 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `scipy` from 1.18.0 to 1.18.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/scipy/scipy/releases\"\u003escipy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eSciPy 1.18.1 Release Notes\u003c/h1\u003e\n\u003cp\u003eSciPy \u003ccode\u003e1.18.1\u003c/code\u003e is a bug-fix release with no new features\ncompared to \u003ccode\u003e1.18.0\u003c/code\u003e. This release includes binaries on\nPyPI for Python \u003ccode\u003e3.15\u003c/code\u003e, and the minimum required version\nof the GCC toolchain has been increased to \u003ccode\u003e10.3...\n\n_Description has been truncated_","html_url":"https://github.com/debpalash/friday/pull/14","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/debpalash%2Ffriday/issues/14","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/14/packages"}},{"old_version":"5.16.1","new_version":"5.17.0","update_type":"minor","path":"/evaluation","pr_created_at":"2026-09-18T17:22:40.000Z","version_change":"5.16.1 → 5.17.0","issue":{"uuid":"5502511387","node_id":"PR_kwDORckIoM8AAAABEHcvOw","number":1587,"state":"open","title":"security(deps): Bump the inference-dependencies group in /evaluation with 4 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-18T17:22:40.000Z","updated_at":"2026-09-18T17:23:01.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"security(deps): Bump","group_name":"inference-dependencies","update_count":4,"packages":[{"name":"onnxscript","old_version":"0.7.1","new_version":"0.7.2","repository_url":"https://github.com/microsoft/onnxscript"},{"name":"onnxruntime-gpu","old_version":"1.29.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"transformers","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tensordict","old_version":"0.14.1","new_version":"0.14.2","repository_url":"https://github.com/pytorch/tensordict"}],"path":"/evaluation","ecosystem":"pip"},"body":"Bumps the inference-dependencies group in /evaluation with 4 updates: [onnxscript](https://github.com/microsoft/onnxscript), [onnxruntime-gpu](https://github.com/microsoft/onnxruntime), [transformers](https://github.com/huggingface/transformers) and [tensordict](https://github.com/pytorch/tensordict).\n\nUpdates `onnxscript` from 0.7.1 to 0.7.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxscript/releases\"\u003eonnxscript's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.7.2\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eOptimizer and rewriter\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix constant folding dropping subgraph initializers when inlining If branches by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2825\"\u003emicrosoft/onnxscript#2825\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove Reshape and Slice folding by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2807\"\u003emicrosoft/onnxscript#2807\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTorch Lib\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[torchlib] Add \u003ccode\u003eprims::remainder\u003c/code\u003e by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2953\"\u003emicrosoft/onnxscript#2953\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGenerate new opsets up to 27 by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2958\"\u003emicrosoft/onnxscript#2958\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix incorrect rank handling in aten_repeat_interleave_self_int ONNX export \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2932\"\u003e#2932\u003c/a\u003e by \u003ca href=\"https://github.com/PratikWayase\"\u003e\u003ccode\u003e@​PratikWayase\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2936\"\u003emicrosoft/onnxscript#2936\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExport aten::relu6 as a single Clip op by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2987\"\u003emicrosoft/onnxscript#2987\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FFT export truncation by preserving dft_length in rFFT lowering by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2991\"\u003emicrosoft/onnxscript#2991\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix invalid ONNX graph from None start/end in aten_slice_scatter by \u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3006\"\u003emicrosoft/onnxscript#3006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor the dtype argument of aten::mean when exporting without dim by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3009\"\u003emicrosoft/onnxscript#3009\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix dynamo export for scalar mul on converted real tensors by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3005\"\u003emicrosoft/onnxscript#3005\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMaterialize the DFT axis default when converting opset 19 to 20 by \u003ca href=\"https://github.com/MohammedAlkindi\"\u003e\u003ccode\u003e@​MohammedAlkindi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3023\"\u003emicrosoft/onnxscript#3023\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_isclose handling of infinities and equal_nan by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3026\"\u003emicrosoft/onnxscript#3026\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix float16 trunc division rounding by \u003ca href=\"https://github.com/Alphaxiaoteng\"\u003e\u003ccode\u003e@​Alphaxiaoteng\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3025\"\u003emicrosoft/onnxscript#3025\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd converter for \u003ccode\u003eaten::_grouped_mm.default\u003c/code\u003e by \u003ca href=\"https://github.com/Sid-V5\"\u003e\u003ccode\u003e@​Sid-V5\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2805\"\u003emicrosoft/onnxscript#2805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_roll for negative dims and shifts past the dimension length by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3024\"\u003emicrosoft/onnxscript#3024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[torchlib] Reimplement as_strided without an ONNX loop by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2928\"\u003emicrosoft/onnxscript#2928\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip GQA key/value repeat when query and key head counts are equal by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2957\"\u003emicrosoft/onnxscript#2957\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SplitToSequence with scalar uneven split producing incorrect equal-split output by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2858\"\u003emicrosoft/onnxscript#2858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ReshapeReshape initializer name collisions when resolving shared \u003ccode\u003e-1\u003c/code\u003e shapes by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2947\"\u003emicrosoft/onnxscript#2947\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[torchlib] add \u003ccode\u003eaten::bincount\u003c/code\u003e ONNX lowering and bool-mask \u003ccode\u003eaten::index_put\u003c/code\u003e fix with e2e coverage by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2921\"\u003emicrosoft/onnxscript#2921\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSet kernel_shape attribute on Conv/ConvTranspose in torchlib by \u003ca href=\"https://github.com/titaiwangms\"\u003e\u003ccode\u003e@​titaiwangms\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2972\"\u003emicrosoft/onnxscript#2972\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDisable Publish Docs workflow on forks by \u003ca href=\"https://github.com/take-cheeze\"\u003e\u003ccode\u003e@​take-cheeze\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2980\"\u003emicrosoft/onnxscript#2980\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_linear rank mismatch for 1D weight (missing squeeze) by \u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2984\"\u003emicrosoft/onnxscript#2984\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove integer aten_floor_divide export to drop Sign ops by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2960\"\u003emicrosoft/onnxscript#2960\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix full_like Dynamo export when memory_format is passed by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2994\"\u003emicrosoft/onnxscript#2994\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse the query dtype's lowest finite value for the causal attention mask by \u003ca href=\"https://github.com/SubhajitMitra-GH\"\u003e\u003ccode\u003e@​SubhajitMitra-GH\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2992\"\u003emicrosoft/onnxscript#2992\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAccept memory_format kwarg on rand/randn/randint _like ops by \u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3011\"\u003emicrosoft/onnxscript#3011\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEmit scalar Range bounds in aten_unfold by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3013\"\u003emicrosoft/onnxscript#3013\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs(_framework_apis): say check_model is a deliberate no-op by \u003ca href=\"https://github.com/MohammedAlkindi\"\u003e\u003ccode\u003e@​MohammedAlkindi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3012\"\u003emicrosoft/onnxscript#3012\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix arange and logit behavior for torch-nightly CI by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2974\"\u003emicrosoft/onnxscript#2974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFold Gemm beta into the fused BatchNorm bias by \u003ca href=\"https://github.com/MohammedAlkindi\"\u003e\u003ccode\u003e@​MohammedAlkindi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3027\"\u003emicrosoft/onnxscript#3027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix aten_pow_scalar type promotion when the exponent is not floating point by \u003ca href=\"https://github.com/Om-singhaI\"\u003e\u003ccode\u003e@​Om-singhaI\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/3036\"\u003emicrosoft/onnxscript#3036\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Codecov test-results upload to supported action path by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2970\"\u003emicrosoft/onnxscript#2970\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix protobuf serialization failure in ort_fusions ort_run for large models by \u003ca href=\"https://github.com/justinchuby\"\u003e\u003ccode\u003e@​justinchuby\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2955\"\u003emicrosoft/onnxscript#2955\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin GitHub Actions to full-length commit SHAs by \u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2995\"\u003emicrosoft/onnxscript#2995\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PratikWayase\"\u003e\u003ccode\u003e@​PratikWayase\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2936\"\u003emicrosoft/onnxscript#2936\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gabrielfruet\"\u003e\u003ccode\u003e@​gabrielfruet\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2984\"\u003emicrosoft/onnxscript#2984\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SubhajitMitra-GH\"\u003e\u003ccode\u003e@​SubhajitMitra-GH\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2992\"\u003emicrosoft/onnxscript#2992\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danfiedler-msft\"\u003e\u003ccode\u003e@​danfiedler-msft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/microsoft/onnxscript/pull/2995\"\u003emicrosoft/onnxscript#2995\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/082bfa28e959a4c0639d91b62663c6c59c4dfc42\"\u003e\u003ccode\u003e082bfa2\u003c/code\u003e\u003c/a\u003e Fix aten_pow_scalar type promotion when the exponent is not floating point (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/d1c005d158f40020597a0b35fd681c4f5286378f\"\u003e\u003ccode\u003ed1c005d\u003c/code\u003e\u003c/a\u003e [torchlib] Reimplement as_strided without an ONNX loop (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2928\"\u003e#2928\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/9b6d4cc7f19478bd9e7a61385e83a9016f291480\"\u003e\u003ccode\u003e9b6d4cc\u003c/code\u003e\u003c/a\u003e Fix aten_roll for negative dims and shifts past the dimension length (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3024\"\u003e#3024\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/9709f8a0777037c4c0a6320a64593f342aef7183\"\u003e\u003ccode\u003e9709f8a\u003c/code\u003e\u003c/a\u003e Add converter for \u003ccode\u003eaten::_grouped_mm.default\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2805\"\u003e#2805\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/b4c10fab5b65d7f15bbaadae89512ba4fba74745\"\u003e\u003ccode\u003eb4c10fa\u003c/code\u003e\u003c/a\u003e Fold Gemm beta into the fused BatchNorm bias (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3027\"\u003e#3027\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/fc4357c74d827639b72c8a7ea55d89920b1b1e2f\"\u003e\u003ccode\u003efc4357c\u003c/code\u003e\u003c/a\u003e Fix float16 trunc division rounding (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3025\"\u003e#3025\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/995ce9819494bbee2531e2d2b8cb0e7346676fed\"\u003e\u003ccode\u003e995ce98\u003c/code\u003e\u003c/a\u003e Fix aten_isclose handling of infinities and equal_nan (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3026\"\u003e#3026\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/c927620f320c37ea638e2abad20c994afa107953\"\u003e\u003ccode\u003ec927620\u003c/code\u003e\u003c/a\u003e Materialize the DFT axis default when converting opset 19 to 20 (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3023\"\u003e#3023\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/3ba2bf74970122d2a8b043765128f34cea69be8f\"\u003e\u003ccode\u003e3ba2bf7\u003c/code\u003e\u003c/a\u003e Fix arange and logit behavior for torch-nightly CI (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/2974\"\u003e#2974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxscript/commit/0e4df17d1f21f6216f06be0a430c09360cbd3c3e\"\u003e\u003ccode\u003e0e4df17\u003c/code\u003e\u003c/a\u003e docs(_framework_apis): say check_model is a deliberate no-op (\u003ca href=\"https://redirect.github.com/microsoft/onnxscript/issues/3012\"\u003e#3012\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxscript/compare/v0.7.1...v0.7.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `onnxruntime-gpu` from 1.29.0 to 1.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/onnxruntime/releases\"\u003eonnxruntime-gpu's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eONNX Runtime v1.30.0\u003c/h2\u003e\n\u003cp\u003eONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32168\"\u003e#32168\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32340\"\u003e#32340\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32515\"\u003e#32515\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31727\"\u003e#31727\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32277\"\u003e#32277\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32284\"\u003e#32284\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32420\"\u003e#32420\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31674\"\u003e#31674\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31973\"\u003e#31973\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32178\"\u003e#32178\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32356\"\u003e#32356\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eAnnouncements \u0026amp; Compatibility\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with \u003ccode\u003e-Donnxruntime_USE_FP4_QMOE=OFF\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32096\"\u003e#32096\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32163\"\u003e#32163\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and \u003ccode\u003eblock_size=32\u003c/code\u003e. Set \u003ccode\u003e-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON\u003c/code\u003e when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32324\"\u003e#32324\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCPU FP16 \u003ccode\u003eGemm\u003c/code\u003e and \u003ccode\u003eMatMul\u003c/code\u003e execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32301\"\u003e#32301\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32197\"\u003e#32197\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eWebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32287\"\u003e#32287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31960\"\u003e#31960\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31970\"\u003e#31970\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSecurity \u0026amp; Reliability\u003c/h2\u003e\n\u003ch3\u003eModel Loading, Memory, and Input Validation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimited nested model-graph depth and canonicalized external-data locations to harden model loading (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32344\"\u003e#32344\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32135\"\u003e#32135\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32010\"\u003e#32010\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32040\"\u003e#32040\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eStrengthened shape, rank, and parameter validation for \u003ccode\u003eSplit\u003c/code\u003e, \u003ccode\u003eScan\u003c/code\u003e, \u003ccode\u003eGatherND\u003c/code\u003e, \u003ccode\u003eScatterND\u003c/code\u003e, \u003ccode\u003eSpaceToDepth\u003c/code\u003e/\u003ccode\u003eDepthToSpace\u003c/code\u003e, \u003ccode\u003eCrop\u003c/code\u003e, \u003ccode\u003eConv\u003c/code\u003e, \u003ccode\u003eNormalizer\u003c/code\u003e, and pooling (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29461\"\u003e#29461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31668\"\u003e#31668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32034\"\u003e#32034\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32039\"\u003e#32039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32076\"\u003e#32076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32157\"\u003e#32157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32160\"\u003e#32160\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32161\"\u003e#32161\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32345\"\u003e#32345\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32349\"\u003e#32349\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eHardened generation and attention input handling, including attention-attribute narrowing, \u003ccode\u003eBifurcationDetector\u003c/code\u003e inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31648\"\u003e#31648\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31701\"\u003e#31701\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32009\"\u003e#32009\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32078\"\u003e#32078\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32144\"\u003e#32144\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eValidated \u003ccode\u003eTreeEnsemble\u003c/code\u003e node references and bounded subtree comparison, rejected non-finite CPU \u003ccode\u003eRoiAlign\u003c/code\u003e coordinates, and required \u003ccode\u003eImageScaler\u003c/code\u003e bias to match the channel count (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32031\"\u003e#32031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32043\"\u003e#32043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32011\"\u003e#32011\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32002\"\u003e#32002\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded an allowlist of safe LoRA adapter parameter data types, validated \u003ccode\u003eMatMulFpQ4\u003c/code\u003e shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31682\"\u003e#31682\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32032\"\u003e#32032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32007\"\u003e#32007\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eGPU Bounds and Resource Lifetimes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHardened CUDA indexing and buffer-size arithmetic in \u003ccode\u003eMatMulNBits\u003c/code\u003e, \u003ccode\u003eRemovePadding\u003c/code\u003e, \u003ccode\u003eRotaryEmbedding\u003c/code\u003e, \u003ccode\u003eSparseAttention\u003c/code\u003e, Whisper beam search, NMS, QDQ, and \u003ccode\u003eGatherElements\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31643\"\u003e#31643\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31994\"\u003e#31994\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31995\"\u003e#31995\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31996\"\u003e#31996\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31998\"\u003e#31998\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32014\"\u003e#32014\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32029\"\u003e#32029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32030\"\u003e#32030\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32137\"\u003e#32137\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32330\"\u003e#32330\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31997\"\u003e#31997\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept \u003ccode\u003eCudaAsyncBuffer\u003c/code\u003e staging storage alive across CUDA graph replay (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/31968\"\u003e#31968\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32121\"\u003e#32121\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32364\"\u003e#32364\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32063\"\u003e#32063\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32317\"\u003e#32317\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies and Tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29906\"\u003e#29906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32190\"\u003e#32190\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32424\"\u003e#32424\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUpdated JavaScript dependencies including \u003ccode\u003ejs-yaml\u003c/code\u003e, \u003ccode\u003ejoi\u003c/code\u003e, \u003ccode\u003efast-uri\u003c/code\u003e, and the Next.js end-to-end fixture (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32397\"\u003e#32397\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32486\"\u003e#32486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32488\"\u003e#32488\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32505\"\u003e#32505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32508\"\u003e#32508\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32176\"\u003e#32176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32005\"\u003e#32005\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32440\"\u003e#32440\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003ch3\u003eCore APIs \u0026amp; Runtime\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Go bindings for the ONNX Runtime C API (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29615\"\u003e#29615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExtended memory importing with host-pointer support and added access to preallocated outputs through \u003ccode\u003eKernelContext::GetPreallocatedOutput\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/29726\"\u003e#29726\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32089\"\u003e#32089\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32283\"\u003e#32283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32321\"\u003e#32321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32312\"\u003e#32312\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded DeepSeek Engram contrib operators, \u003ccode\u003eEngramGate\u003c/code\u003e and \u003ccode\u003eNGramHashMapping\u003c/code\u003e, and expanded kernel coverage for Qwen-3.5 operators (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32268\"\u003e#32268\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/pull/32106\"\u003e#32106\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/f2c39fe2f838cf35ce7da92824f5a5e3ee6e88a7\"\u003e\u003ccode\u003ef2c39fe\u003c/code\u003e\u003c/a\u003e [CUDA] Add INT4 paged KV cache with per-channel scales (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32515\"\u003e#32515\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/5894ba8a53526b3aeb702bd86e6b117c9df8fa4f\"\u003e\u003ccode\u003e5894ba8\u003c/code\u003e\u003c/a\u003e Add portable random-access file reads to Env (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/a2ee3eb43052de307003e6256fc9258ce19d9c34\"\u003e\u003ccode\u003ea2ee3eb\u003c/code\u003e\u003c/a\u003e Fix CUDA plugin device discovery on WSL (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32517\"\u003e#32517\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/b652e595b04d202b7f71af1d9105a183fac2b100\"\u003e\u003ccode\u003eb652e59\u003c/code\u003e\u003c/a\u003e [WebGPU] Prepack Conv weights for the im2col-matmul path (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32420\"\u003e#32420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/0f0f29f5015f16926912ae47061e6a3eedcfbe04\"\u003e\u003ccode\u003e0f0f29f\u003c/code\u003e\u003c/a\u003e Get rid of spurious warning about not being able to find spectre mitigation (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/23dd6510fd395b4556f474c1c0079be2a8b7a8c8\"\u003e\u003ccode\u003e23dd651\u003c/code\u003e\u003c/a\u003e Register ONNX schemas only when static registration is disabled (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32353\"\u003e#32353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/33af5d32801b2e631ebece4f382f4ba775f17d8c\"\u003e\u003ccode\u003e33af5d3\u003c/code\u003e\u003c/a\u003e Release external data loaders after graph initialization (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32502\"\u003e#32502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/2e3c24d5963d62d0bd7c9d306433b19b7304d5d2\"\u003e\u003ccode\u003e2e3c24d\u003c/code\u003e\u003c/a\u003e Clarify external initializer and EP context path interaction (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32442\"\u003e#32442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/e76036b8e49515ee7dd2dd0ac39c9d8b7533d38a\"\u003e\u003ccode\u003ee76036b\u003c/code\u003e\u003c/a\u003e [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32433\"\u003e#32433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/onnxruntime/commit/82583c5b6398a9c37815f91e9cd1d7c165a132a7\"\u003e\u003ccode\u003e82583c5\u003c/code\u003e\u003c/a\u003e Add session option for a BNHS GroupQueryAttention Value cache layout (\u003ca href=\"https://redirect.github.com/microsoft/onnxruntime/issues/32139\"\u003e#32139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/onnxruntime/compare/v1.29.0...v1.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.16.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tensordict` from 0.14.1 to 0.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/tensordict/releases\"\u003etensordict's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eTensorDict v0.14.2\u003c/h2\u003e\n\u003cp\u003eTensorDict 0.14.2 is a patch release correcting compiled shallow copies, non-tensor concatenation, and CUDA graph replay. No new public APIs, breaking changes, or deprecations are introduced.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve independent nested containers in compiled shallow copies while continuing to share tensor leaves (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/pull/1784\"\u003e#1784\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePreserve non-tensor values during concatenation, including mixed inputs and padded metadata, while retaining scalar metadata and weak-reference behavior (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/pull/1786\"\u003e#1786\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eEnsure CUDA graph replay uses updated inputs when a module writes outputs under its input keys (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/pull/1788\"\u003e#1788\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eInstall after publication: \u003ccode\u003epip install tensordict==0.14.2\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/vmoens\"\u003e\u003ccode\u003e@​vmoens\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pytorch/tensordict/compare/v0.14.1...v0.14.2\"\u003eFull changelog\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/f2b44ecd1ed86b34aad43a075a04e9f45e22c044\"\u003e\u003ccode\u003ef2b44ec\u003c/code\u003e\u003c/a\u003e [Versioning] Prepare TensorDict 0.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/72b56ac039deb19d58aa348e92132bf2d60bf8a3\"\u003e\u003ccode\u003e72b56ac\u003c/code\u003e\u003c/a\u003e [BugFix] Preserve uniform metadata during non-tensor concatenation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/1bb5136fd43119e0f8246f00a4a0f8d547853e63\"\u003e\u003ccode\u003e1bb5136\u003c/code\u003e\u003c/a\u003e [BugFix] Keep CudaGraphModule inputs bound when a module rewrites its input k...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/1f853a53e63fef528b93e8aa464058cf0be48ba7\"\u003e\u003ccode\u003e1f853a5\u003c/code\u003e\u003c/a\u003e [BugFix] Preserve non-tensor values during concatenation (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/issues/1786\"\u003e#1786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/tensordict/commit/03e16e08e271ad6d8494a80eefa8b05c6ee69225\"\u003e\u003ccode\u003e03e16e0\u003c/code\u003e\u003c/a\u003e [Compile] Preserve nested structure in shallow TensorDict copies (\u003ca href=\"https://redirect.github.com/pytorch/tensordict/issues/1784\"\u003e#1784\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pytorch/tensordict/compare/v0.14.1...v0.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/microsoft/physical-ai-toolchain/pull/1587","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/microsoft%2Fphysical-ai-toolchain/issues/1587","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1587/packages"}},{"old_version":"\u003e=4.35.0","new_version":"\u003e=5.17.0","update_type":null,"path":"/backend","pr_created_at":"2026-09-17T00:31:08.000Z","version_change":"\u003e=4.35.0 → \u003e=5.17.0","issue":{"uuid":"5481366270","node_id":"PR_kwDOS3kNmM8AAAABD2crDA","number":132,"state":"closed","title":"chore(deps)(deps): update transformers requirement from \u003e=4.35.0 to \u003e=5.17.0 in /backend","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-17T00:38:04.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-17T00:31:08.000Z","updated_at":"2026-09-17T00:38:13.000Z","time_to_close":416,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): update","packages":[{"name":"transformers","old_version":"\u003e=4.35.0","new_version":"\u003e=5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":"/backend","ecosystem":"pip"},"body":"Updates the requirements on [transformers](https://github.com/huggingface/transformers) to permit the latest version.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.35.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/health-assistant-io/health-assistant/pull/132","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/health-assistant-io%2Fhealth-assistant/issues/132","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/132/packages"}},{"old_version":"5.13.0","new_version":"5.17.0","update_type":"minor","path":null,"pr_created_at":"2026-09-16T20:45:44.000Z","version_change":"5.13.0 → 5.17.0","issue":{"uuid":"5479729744","node_id":"PR_kwDOSigF3M8AAAABD1It1g","number":82,"state":"open","title":"Bump the python-minor-patch group across 1 directory with 9 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-16T20:45:44.000Z","updated_at":"2026-09-25T07:00:22.462Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"python-minor-patch","update_count":9,"packages":[{"name":"aiolimiter","old_version":"1.2.1","new_version":"1.3.0","repository_url":"https://github.com/mjpieters/aiolimiter"},{"name":"fastapi","old_version":"0.139.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"numpy","old_version":"2.5.1","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"pgvector","old_version":"0.4.2","new_version":"0.5.0","repository_url":"https://github.com/pgvector/pgvector-python"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"rapidfuzz","old_version":"3.14.5","new_version":"3.14.6","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"av","old_version":"18.0.0","new_version":"18.1.0","repository_url":"https://github.com/PyAV-Org/PyAV"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.13.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-minor-patch group with 9 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiolimiter](https://github.com/mjpieters/aiolimiter) | `1.2.1` | `1.3.0` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.0` | `0.141.1` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.1` | `2.5.3` |\n| [pgvector](https://github.com/pgvector/pgvector-python) | `0.4.2` | `0.5.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.14.5` | `3.14.6` |\n| [av](https://github.com/PyAV-Org/PyAV) | `18.0.0` | `18.1.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.13.0` | `5.17.0` |\n\n\nUpdates `aiolimiter` from 1.2.1 to 1.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mjpieters/aiolimiter/releases\"\u003eaiolimiter's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAiolimiter 1.3.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eTightened boundary checks for the \u003ccode\u003eamount\u003c/code\u003e argument to \u003ccode\u003eAsyncLimiter.acquire()\u003c/code\u003e, rejecting values outside the 0 to \u003ccode\u003emax_rate\u003c/code\u003e range. Negative values and \u003ccode\u003eNaN\u003c/code\u003e are no longer accepted. (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/760\"\u003e#760\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/313\"\u003e#313\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/655\"\u003e#655\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mjpieters/aiolimiter/blob/main/CHANGELOG.md\"\u003eaiolimiter's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eaiolimiter 1.3.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eTightened boundary checks for the \u003ccode\u003eamount\u003c/code\u003e argument to \u003ccode\u003eAsyncLimiter.acquire()\u003c/code\u003e, rejecting values outside the 0 to \u003ccode\u003emax_rate\u003c/code\u003e range. Negative values and \u003ccode\u003eNaN\u003c/code\u003e are no longer accepted. (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/760\"\u003e#760\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/313\"\u003e#313\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/655\"\u003e#655\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/f7df2d7ff4be2d2b64bb2cbf2340e5a8a28d988d\"\u003e\u003ccode\u003ef7df2d7\u003c/code\u003e\u003c/a\u003e ci: Address release process issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/be2530b0352d2382b71e6490b948356904543952\"\u003e\u003ccode\u003ebe2530b\u003c/code\u003e\u003c/a\u003e chore: fix sdist packaging\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/252b97ff8819e1ea3ffb79c676286feb0970c79e\"\u003e\u003ccode\u003e252b97f\u003c/code\u003e\u003c/a\u003e ci: unbreak prek step during releases\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/ee7f6efcd0ef8c15282e66bddda9871331585807\"\u003e\u003ccode\u003eee7f6ef\u003c/code\u003e\u003c/a\u003e Release v1.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/697643f8b768c63ade9777004b130d5203329297\"\u003e\u003ccode\u003e697643f\u003c/code\u003e\u003c/a\u003e feat: Reject negative and NaN acquisition amounts (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/760\"\u003e#760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/8438f6f458e2e00f9d3313f707af9c7abe2deb8f\"\u003e\u003ccode\u003e8438f6f\u003c/code\u003e\u003c/a\u003e chore(deps): lock file maintenance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/8ed24d146a52a961303db8b5c13691f0b4eaf212\"\u003e\u003ccode\u003e8ed24d1\u003c/code\u003e\u003c/a\u003e chore(deps): update pre-commit hook renovatebot/pre-commit-hooks to v44.65.5 ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/4c57d27f05d92f66ea4e961ff661d525db46e6b4\"\u003e\u003ccode\u003e4c57d27\u003c/code\u003e\u003c/a\u003e chore(deps): update pre-commit updates (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/759\"\u003e#759\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/6c2f96d316db42b20e0ccc7a9bf537e575cfee7e\"\u003e\u003ccode\u003e6c2f96d\u003c/code\u003e\u003c/a\u003e chore(deps): update dependency towncrier to v26\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mjpieters/aiolimiter/commit/279fdb7780226444c2dd0f71807d45ffcd86a82d\"\u003e\u003ccode\u003e279fdb7\u003c/code\u003e\u003c/a\u003e chore(deps): update pre-commit updates (\u003ca href=\"https://redirect.github.com/mjpieters/aiolimiter/issues/757\"\u003e#757\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mjpieters/aiolimiter/compare/v1.2.1...v1.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fastapi` from 0.139.0 to 0.141.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/fastapi/releases\"\u003efastapi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.141.1\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix support for background tasks and headers from dependencies in \u003ccode\u003eapp.frontend()\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16105\"\u003e#16105\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16104\"\u003e#16104\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.141.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more convenient with \u003ccode\u003efastapi dev\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16102\"\u003e#16102\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.13\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003estatus_code\u003c/code\u003e being ignored for SSE and JSONL streaming endpoints. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15937\"\u003e#15937\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Fix \u003ccode\u003eformat_sse_event\u003c/code\u003e docstring rendering of \u003ccode\u003e\\n\\n\u003c/code\u003e terminator. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15613\"\u003e#15613\u003c/a\u003e by \u003ca href=\"https://github.com/AshNicolus\"\u003e\u003ccode\u003e@​AshNicolus\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e📝 Add API reference page for fastapi.sse. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15930\"\u003e#15930\u003c/a\u003e by \u003ca href=\"https://github.com/SAURABHSALVE\"\u003e\u003ccode\u003e@​SAURABHSALVE\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.12\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix line splitting in \u003ccode\u003eformat_sse_event\u003c/code\u003e to comply with SSE spec. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15515\"\u003e#15515\u003c/a\u003e by \u003ca href=\"https://github.com/Zawwarsami16\"\u003e\u003ccode\u003e@​Zawwarsami16\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.11\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eresponse_model_*\u003c/code\u003e params ignored for non-generator endpoints with \u003ccode\u003eIterable[..]\u003c/code\u003e return type. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/15093\"\u003e#15093\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.10\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix handling sequences with nested Annotated types. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/14874\"\u003e#14874\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Accept any base test failure as regression. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16092\"\u003e#16092\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🐛 Preserve pytest exit code in regression check. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16091\"\u003e#16091\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e✅ Test PR regressions against base code. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16090\"\u003e#16090\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.140.9\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 Fix \u003ccode\u003eexclude_defaults\u003c/code\u003e not propagated to dict keys and values in \u003ccode\u003ejsonable_encoder\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/fastapi/pull/16043\"\u003e#16043\u003c/a\u003e by \u003ca href=\"https://github.com/MBGrao\"\u003e\u003ccode\u003e@​MBGrao\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/95f8322ee1dcda7ceace7b1c4f6c9915b36d748f\"\u003e\u003ccode\u003e95f8322\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.1 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16106\"\u003e#16106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/f137944c435cff4e4b30ea7d12855ea88ddb868c\"\u003e\u003ccode\u003ef137944\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/d62354434b2e508fe89024213b220ca8e67dea5e\"\u003e\u003ccode\u003ed623544\u003c/code\u003e\u003c/a\u003e 🐛 Fix support for background tasks and headers from dependencies in `app.fron...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/1d211b9c1009d577f39fa2b19b10d9a93a72a0ed\"\u003e\u003ccode\u003e1d211b9\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/8a1f8768411e62093e70ce142ea10863a485643c\"\u003e\u003ccode\u003e8a1f876\u003c/code\u003e\u003c/a\u003e 📝 Document \u003ccode\u003eFASTAPI_ENV\u003c/code\u003e in FastAPI CLI guide (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16104\"\u003e#16104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/c7e7b651d6946c07cc9f675f39c9501d08319e57\"\u003e\u003ccode\u003ec7e7b65\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.141.0 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16103\"\u003e#16103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/6bceb84053eb2405e9c000aad30ea13367b5ee32\"\u003e\u003ccode\u003e6bceb84\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/5429fed84e84e32672c25a953eca3429b841ce90\"\u003e\u003ccode\u003e5429fed\u003c/code\u003e\u003c/a\u003e ✨ Add \u003ccode\u003eapp.frontend(check_dir=\u0026quot;auto\u0026quot;)\u003c/code\u003e, to make local development more conven...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/628663f4f899c465da423bce681c7adf9a218948\"\u003e\u003ccode\u003e628663f\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.140.13 (\u003ca href=\"https://redirect.github.com/fastapi/fastapi/issues/16096\"\u003e#16096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/fastapi/commit/0b54fd00273019034dd30b120ac842e65d80690e\"\u003e\u003ccode\u003e0b54fd0\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/fastapi/compare/0.139.0...0.141.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.5.1 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.5.1...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pgvector` from 0.4.2 to 0.5.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pgvector/pgvector-python/blob/master/CHANGELOG.md\"\u003epgvector's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.5.0 (2026-07-06)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded experimental support for type hints\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003evector\u003c/code\u003e and \u003ccode\u003ehalfvec\u003c/code\u003e types to return list for Django, SQLAlchemy, SQLModel, and Peewee\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003evector\u003c/code\u003e type to return \u003ccode\u003eVector\u003c/code\u003e object for Psycopg 3, Psycopg 2, asyncpg, and pg8000\u003c/li\u003e\n\u003cli\u003eRemoved \u003ccode\u003eutils\u003c/code\u003e package (use top-level \u003ccode\u003epgvector\u003c/code\u003e package instead)\u003c/li\u003e\n\u003cli\u003eRemoved re-exported classes (use top-level \u003ccode\u003epgvector\u003c/code\u003e package instead)\u003c/li\u003e\n\u003cli\u003eRemoved dependency on NumPy\u003c/li\u003e\n\u003cli\u003eDropped support for Python \u0026lt; 3.10\u003c/li\u003e\n\u003cli\u003eDropped support for SQLAlchemy \u0026lt; 2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/60739dfd6cb9d674f32afa4184d43e6aff9dfbcf\"\u003e\u003ccode\u003e60739df\u003c/code\u003e\u003c/a\u003e Version bump to 0.5.0 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/a810f27ca93c185e81e98b05d87622d736e89568\"\u003e\u003ccode\u003ea810f27\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/45b054c53fb174ca12ecb08157f7875bd4795356\"\u003e\u003ccode\u003e45b054c\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/efa144252a96be79c695923d2717b0555bea8fcd\"\u003e\u003ccode\u003eefa1442\u003c/code\u003e\u003c/a\u003e Updated examples [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/780cc73f723fd2300cd16ae7362c9ab00453ecfc\"\u003e\u003ccode\u003e780cc73\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/9f0d6b97640486eacf858143430b40d11634a845\"\u003e\u003ccode\u003e9f0d6b9\u003c/code\u003e\u003c/a\u003e Updated examples [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/f6e113e1ad10968473e630d001bc473b6c9a62ed\"\u003e\u003ccode\u003ef6e113e\u003c/code\u003e\u003c/a\u003e Updated example [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/dc6877060099dcd2485e23c9facb04d3e6df3faf\"\u003e\u003ccode\u003edc68770\u003c/code\u003e\u003c/a\u003e Updated readme [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/0c18e0aa5de9d9a4ff1bd1ad58c8839bb5ce814c\"\u003e\u003ccode\u003e0c18e0a\u003c/code\u003e\u003c/a\u003e Addressed todo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pgvector/pgvector-python/commit/28191fc8b9a5702cd07b2854dbf89b1e0d263100\"\u003e\u003ccode\u003e28191fc\u003c/code\u003e\u003c/a\u003e Removed todo [skip ci]\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pgvector/pgvector-python/compare/v0.4.2...v0.5.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `rapidfuzz` from 3.14.5 to 3.14.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/releases\"\u003erapidfuzz's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 3.14.6\u003c/h2\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix some divergences in the pure Python fallback\u003c/li\u003e\n\u003cli\u003efix compatibility with new Cython versions\u003c/li\u003e\n\u003cli\u003efixed potential out of bound access inside Editops.remove_subsequence\u003c/li\u003e\n\u003cli\u003efixed handling python fallback implementation of Editops.remove_subsequence\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRemoved\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edropped support for Python 3.10\u003c/li\u003e\n\u003cli\u003edropped wheels for experimental Python 3.13 free threaded\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/blob/main/CHANGELOG.rst\"\u003erapidfuzz's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003cp\u003e[3.14.6] - 2026-08-30\n^^^^^^^^^^^^^^^^^^^^^\nFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* fix some divergences in the pure Python fallback\n* fix compatibility with new Cython versions\n* fixed potential out of bound access inside Editops.remove_subsequence\n* fixed handling python fallback implementation of Editops.remove_subsequence\n\u003cp\u003eRemoved\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edropped support for Python 3.10\u003c/li\u003e\n\u003cli\u003edropped wheels for experimental Python 3.13 free threaded\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e[3.14.5] - 2026-04-07\n^^^^^^^^^^^^^^^^^^^^^\nFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* fix release ci attempting to upload a pyodide wheel\n\u003cp\u003e[3.14.4] - 2026-04-06\n^^^^^^^^^^^^^^^^^^^^^\nAdded\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eadd risc64 wheels\u003c/li\u003e\n\u003cli\u003eadd support for taskflow 4.0.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eChanged\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* upgrade to ``Cython==3.2.4``.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e* fix type hints for extractOne when no score_cutoff is provided\n\n[3.14.3] - 2025-11-01\n^^^^^^^^^^^^^^^^^^^^^\nFixed\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eadd missing pypy and freethreaded linux wheels\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eRemoved\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edrop s390x and ppc64le wheels since they are virtually unused and require extremely long to build under emulation\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e[3.14.2] - 2025-10-30\n^^^^^^^^^^^^^^^^^^^^^\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/d1b4a183f9ee445134989f4ebbf1e4acfacd4ed7\"\u003e\u003ccode\u003ed1b4a18\u003c/code\u003e\u003c/a\u003e fix cython call\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/f7be71b006ebc7bfeb836a18b7e33fc7412f699b\"\u003e\u003ccode\u003ef7be71b\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/3199c87e7309ed6a2779e658dbddcfc0ba654963\"\u003e\u003ccode\u003e3199c87\u003c/code\u003e\u003c/a\u003e fix version tag\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/7b57e516d59948d4d7e349e88ffafd99668aa2d2\"\u003e\u003ccode\u003e7b57e51\u003c/code\u003e\u003c/a\u003e update date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/15e68d7b195bca227e9992efe928a01d40bd3553\"\u003e\u003ccode\u003e15e68d7\u003c/code\u003e\u003c/a\u003e update rapidfuzz-cpp\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/b637f9f689ef12749d97be87056704cfbc4c2d7c\"\u003e\u003ccode\u003eb637f9f\u003c/code\u003e\u003c/a\u003e don't hand out references to internal elements\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/868a451a6eb8b111fd97bbd3b3413fcf14ee88e4\"\u003e\u003ccode\u003e868a451\u003c/code\u003e\u003c/a\u003e fix Editops.remove_subsequence\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/83b8b8468f3a0bef8fbee0a118c6ad85df325ac8\"\u003e\u003ccode\u003e83b8b84\u003c/code\u003e\u003c/a\u003e fix compatibility with new Cython versions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/24f2ac526bf1ec91db90e7ff02e52816e6bcb603\"\u003e\u003ccode\u003e24f2ac5\u003c/code\u003e\u003c/a\u003e Bump pypa/cibuildwheel from 4.1.1 to 4.2.0 in the github-actions group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/commit/03a5137851aab675b430389235d73bb18873dafe\"\u003e\u003ccode\u003e03a5137\u003c/code\u003e\u003c/a\u003e Bump pypa/gh-action-pypi-publish in the github-actions group\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/rapidfuzz/RapidFuzz/compare/v3.14.5...v3.14.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `av` from 18.0.0 to 18.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/PyAV-Org/PyAV/releases\"\u003eav's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev18.1.0\u003c/h2\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInfer the specific stream and codec context types for all FFmpeg encoder names in type-checked code by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.supported_options\u003c/code\u003e to discover generic and codec-specific options by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2032\"\u003e#2032\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ePacket.rescale_ts()\u003c/code\u003e to rescale packet PTS, DTS, and duration to a new \u003ccode\u003eAVRational\u003c/code\u003e time base by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSupport reusing the thread's current CUDA context via a \u003ccode\u003ecurrent_ctx\u003c/code\u003e flag on \u003ccode\u003eCudaContext\u003c/code\u003e and \u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e, for interop with libraries like PyTorch that initialize CUDA first by \u003ca href=\"https://github.com/Yozer\"\u003e\u003ccode\u003e@​Yozer\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2339\"\u003e#2339\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e no longer requires restating \u003ccode\u003eprimary_ctx\u003c/code\u003e/\u003ccode\u003ecurrent_ctx\u003c/code\u003e when passing an explicit \u003ccode\u003ecuda_context\u003c/code\u003e; the flags are only validated when explicitly given by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSupport passing an explicit CUDA stream to FFmpeg CUDA operations, including NVENC input and output, via a \u003ccode\u003ecuda_stream\u003c/code\u003e parameter on \u003ccode\u003eCudaContext\u003c/code\u003e; currently limited to logical CUDA device 0 by \u003ca href=\"https://github.com/Yozer\"\u003e\u003ccode\u003e@​Yozer\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2360\"\u003e#2360\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eav.AVRational\u003c/code\u003e, an exact rational number stored as two int32s that mirrors FFmpeg's \u003ccode\u003eAVRational\u003c/code\u003e. \u003ccode\u003eCodec.frame_rates\u003c/code\u003e now holds these rather than \u003ccode\u003efractions.Fraction\u003c/code\u003e, and every setter that accepts a \u003ccode\u003eFraction\u003c/code\u003e also accepts an \u003ccode\u003eAVRational\u003c/code\u003e. Unset rational attributes are falsy, so test them with \u003ccode\u003eif not stream.time_base:\u003c/code\u003e rather than \u003ccode\u003eis None\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eFrame.metadata\u003c/code\u003e, the metadata FFmpeg attaches to a frame, by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.level\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eVideoCodecContext.field_order\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.save\u003c/code\u003e now forwards keyword arguments to the encoder, letting callers trade file size for speed (e.g. \u003ccode\u003epred=\u0026quot;none\u0026quot;\u003c/code\u003e or \u003ccode\u003ecompression_level=1\u003c/code\u003e for PNG, \u003ccode\u003eqscale=2\u003c/code\u003e for JPG) by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eInputContainer.start_time_realtime\u003c/code\u003e, the stream's start time in microseconds since the Unix epoch, which RTSP derives from RTCP sender reports, by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2365\"\u003e#2365\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eVideoFrame.save\u003c/code\u003e raising \u003ccode\u003eAttributeError\u003c/code\u003e when given a \u003ccode\u003ePath\u003c/code\u003e rather than a \u003ccode\u003estr\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix a frame rate assigned to a \u003ccode\u003eVideoStream\u003c/code\u003e after \u003ccode\u003eadd_stream\u003c/code\u003e being dropped from the output; the codec context's frame rate is now copied to the stream before the header is written by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2301\"\u003e#2301\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePrevent crashes and corrupted output when structural codec properties are changed after an output stream has been opened by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e, reported by \u003ca href=\"https://github.com/oakaigh\"\u003e\u003ccode\u003e@​oakaigh\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2232\"\u003e#2232\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix a crash when using a stream that has no \u003ccode\u003eCodecContext\u003c/code\u003e (a demuxed stream with no available decoder, such as one from a truncated file, or a stream created by \u003ccode\u003eadd_mux_stream\u003c/code\u003e); decoding now raises \u003ccode\u003eDecoderNotFoundError\u003c/code\u003e, encoding now raises \u003ccode\u003eEncoderNotFoundError\u003c/code\u003e, and \u003ccode\u003eBitStreamFilterContext\u003c/code\u003e accepts such a stream as \u003ccode\u003eout_stream\u003c/code\u003e by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e, reported by \u003ca href=\"https://github.com/justinrmiller\"\u003e\u003ccode\u003e@​justinrmiller\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2344\"\u003e#2344\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport building from source against FFmpeg 9.0 by \u003ca href=\"https://github.com/WyattBlue\"\u003e\u003ccode\u003e@​WyattBlue\u003c/code\u003e\u003c/a\u003e. The binary wheels still ship FFmpeg 8.1.2.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Yozer\"\u003e\u003ccode\u003e@​Yozer\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/pull/2339\"\u003ePyAV-Org/PyAV#2339\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/PyAV-Org/PyAV/compare/v18.0.0...v18.1.0\"\u003ehttps://github.com/PyAV-Org/PyAV/compare/v18.0.0...v18.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/PyAV-Org/PyAV/blob/v18.1.0/CHANGELOG.rst\"\u003eav's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev18.1.0\u003c/h2\u003e\n\u003cp\u003eFeatures:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInfer the specific stream and codec context types for all FFmpeg encoder names in type-checked code by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.supported_options\u003c/code\u003e to discover generic and codec-specific options by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e (:issue:\u003ccode\u003e2032\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ePacket.rescale_ts()\u003c/code\u003e to rescale packet PTS, DTS, and duration to a new \u003ccode\u003eAVRational\u003c/code\u003e time base by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSupport reusing the thread's current CUDA context via a \u003ccode\u003ecurrent_ctx\u003c/code\u003e flag on \u003ccode\u003eCudaContext\u003c/code\u003e and \u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e, for interop with libraries like PyTorch that initialize CUDA first by :gh-user:\u003ccode\u003eYozer\u003c/code\u003e (:pr:\u003ccode\u003e2339\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.from_dlpack\u003c/code\u003e no longer requires restating \u003ccode\u003eprimary_ctx\u003c/code\u003e/\u003ccode\u003ecurrent_ctx\u003c/code\u003e when passing an explicit \u003ccode\u003ecuda_context\u003c/code\u003e; the flags are only validated when explicitly given by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSupport passing an explicit CUDA stream to FFmpeg CUDA operations, including NVENC input and output, via a \u003ccode\u003ecuda_stream\u003c/code\u003e parameter on \u003ccode\u003eCudaContext\u003c/code\u003e; currently limited to logical CUDA device 0 by :gh-user:\u003ccode\u003eYozer\u003c/code\u003e (:pr:\u003ccode\u003e2360\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eav.AVRational\u003c/code\u003e, an exact rational number stored as two int32s that mirrors FFmpeg's \u003ccode\u003eAVRational\u003c/code\u003e. \u003ccode\u003eCodec.frame_rates\u003c/code\u003e now holds these rather than \u003ccode\u003efractions.Fraction\u003c/code\u003e, and every setter that accepts a \u003ccode\u003eFraction\u003c/code\u003e also accepts an \u003ccode\u003eAVRational\u003c/code\u003e. Unset rational attributes are falsy, so test them with \u003ccode\u003eif not stream.time_base:\u003c/code\u003e rather than \u003ccode\u003eis None\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eFrame.metadata\u003c/code\u003e, the metadata FFmpeg attaches to a frame, by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eCodecContext.level\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eVideoCodecContext.field_order\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eVideoFrame.save\u003c/code\u003e now forwards keyword arguments to the encoder, letting callers trade file size for speed (e.g. \u003ccode\u003epred=\u0026quot;none\u0026quot;\u003c/code\u003e or \u003ccode\u003ecompression_level=1\u003c/code\u003e for PNG, \u003ccode\u003eqscale=2\u003c/code\u003e for JPG) by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eInputContainer.start_time_realtime\u003c/code\u003e, the stream's start time in microseconds since the Unix epoch, which RTSP derives from RTCP sender reports, by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e (:issue:\u003ccode\u003e2365\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eVideoFrame.save\u003c/code\u003e raising \u003ccode\u003eAttributeError\u003c/code\u003e when given a \u003ccode\u003ePath\u003c/code\u003e rather than a \u003ccode\u003estr\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFix a frame rate assigned to a \u003ccode\u003eVideoStream\u003c/code\u003e after \u003ccode\u003eadd_stream\u003c/code\u003e being dropped from the output; the codec context's frame rate is now copied to the stream before the header is written by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e (:issue:\u003ccode\u003e2301\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eMisc.:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eSupport building from source against FFmpeg 9.0 by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e. The binary wheels still ship FFmpeg 8.1.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ePrevent crashes and corrupted output when structural codec properties are changed after an output stream has been opened by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e, reported by :gh-user:\u003ccode\u003eoakaigh\u003c/code\u003e (:issue:\u003ccode\u003e2232\u003c/code\u003e).\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a crash when using a stream that has no \u003ccode\u003eCodecContext\u003c/code\u003e (a demuxed stream with no available decoder, such as one from a truncated file, or a stream created by \u003ccode\u003eadd_mux_stream\u003c/code\u003e); decoding now raises \u003ccode\u003eDecoderNotFoundError\u003c/code\u003e, encoding now raises \u003ccode\u003eEncoderNotFoundError\u003c/code\u003e, and \u003ccode\u003eBitStreamFilterContext\u003c/code\u003e accepts such a stream as \u003ccode\u003eout_stream\u003c/code\u003e by :gh-user:\u003ccode\u003eWyattBlue\u003c/code\u003e, reported by :gh-user:\u003ccode\u003ejustinrmiller\u003c/code\u003e (:issue:\u003ccode\u003e2344\u003c/code\u003e).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/7e3d950a8b72062502c1a60d672f8ca565313af5\"\u003e\u003ccode\u003e7e3d950\u003c/code\u003e\u003c/a\u003e Release 18.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/842955f0cb6df927a42172ff14de186aec6e9a00\"\u003e\u003ccode\u003e842955f\u003c/code\u003e\u003c/a\u003e Changelog entries missed since 18.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/fdb4ce4e18181332b0704b78a5e655e8acc6e7e1\"\u003e\u003ccode\u003efdb4ce4\u003c/code\u003e\u003c/a\u003e Add InputContainer.start_time_realtime, closes \u003ca href=\"https://redirect.github.com/PyAV-Org/PyAV/issues/2365\"\u003e#2365\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/b9ef85f33cca825f7f47bfb04217f92f27c60b8e\"\u003e\u003ccode\u003eb9ef85f\u003c/code\u003e\u003c/a\u003e Forward encoder options from \u003ccode\u003eVideoFrame.save()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/f711ab6866f27608c8b6a1e60e4512e98a52cc75\"\u003e\u003ccode\u003ef711ab6\u003c/code\u003e\u003c/a\u003e Disable avx-512 in build-deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/883642e7e68497de5c31487deaf48a11b364135e\"\u003e\u003ccode\u003e883642e\u003c/code\u003e\u003c/a\u003e Test with ffmpeg 9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/b35726c2b80f54b572d8c95f9bbae71ffa7ec9c6\"\u003e\u003ccode\u003eb35726c\u003c/code\u003e\u003c/a\u003e FFmpeg 9.0 reorders AVCodecID\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/f6f0a5e3d975aab851e12ca881bdadfdd8f9ec74\"\u003e\u003ccode\u003ef6f0a5e\u003c/code\u003e\u003c/a\u003e Avoid probing primary context flags for no reason\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/387fca5ec3eadbdd9ba286cac2918b74a5385b42\"\u003e\u003ccode\u003e387fca5\u003c/code\u003e\u003c/a\u003e Support explicit CUDA streams\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PyAV-Org/PyAV/commit/32e9f7de15c3ecdddd78cc17b5ed4cdafdd15149\"\u003e\u003ccode\u003e32e9f7d\u003c/code\u003e\u003c/a\u003e Refresh installation documentation\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/PyAV-Org/PyAV/compare/v18.0.0...v18.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.13.0 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.14.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#security\"\u003eSecurity\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003ch2\u003etorch.nn\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003etorch.nn.LinearCrossEntropyOptions\u003c/code\u003e no longer accepts \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e; use \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e instead (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188283\"\u003e#188283\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003e\u0026quot;balanced\u0026quot;\u003c/code\u003e policy was removed because \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e provides the same weight-gradient accumulation precision with lower memory use on CUDA, already uses the equivalent scratch layout for mixed-precision inputs on other devices, and was never selected by \u003ccode\u003e\u0026quot;auto\u0026quot;\u003c/code\u003e. Constructing the options with \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e now raises \u003ccode\u003eValueError: invalid acc_policy: 'balanced'; expected one of 'auto', 'accurate', 'compact'\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBefore:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;balanced\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n    input, linear_weight, target, options=options\r\n)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eAfter:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;compact\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/2b3ec34829036a65cd9d1398ea72a0167dc37470\"\u003e\u003ccode\u003e2b3ec34\u003c/code\u003e\u003c/a\u003e [release/2.14] Import SDPAParams in test_transformers to fix lint (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194970\"\u003e#194970\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/08187d9e0fba026dc8217405802ab5381dc88d90\"\u003e\u003ccode\u003e08187d9\u003c/code\u003e\u003c/a\u003e [cuDNN] Add guards for cuDNN SDPA decode (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194963\"\u003e#194963\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/8ceea97051dec8f6bee23d24bd7704dcb6843ade\"\u003e\u003ccode\u003e8ceea97\u003c/code\u003e\u003c/a\u003e Pin cython \u0026lt; 3.3.0 for the Windows Triton wheel build (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194931\"\u003e#194931\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/99ecebc63014f3454331b5a0914871daa063b512\"\u003e\u003ccode\u003e99ecebc\u003c/code\u003e\u003c/a\u003e [Cherry-pick][release/2.14] [inductor] Fix loop-local load CSE lifetime (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194\"\u003e#194\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/ec283a75077fa3ee24a9cda2c58d2b24d95ca98c\"\u003e\u003ccode\u003eec283a7\u003c/code\u003e\u003c/a\u003e Bump the Python 3.15 numpy pin to 2.5.2 (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194821\"\u003e#194821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/65890f364dd059ca97b9a37ada974eba8d8be772\"\u003e\u003ccode\u003e65890f3\u003c/code\u003e\u003c/a\u003e Fix docker-release validate job to use the channel matching the pushed image ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/168238882db0ad985f8904489604ff4955449fd2\"\u003e\u003ccode\u003e1682388\u003c/code\u003e\u003c/a\u003e Fix macOS py3.15 wheel builds: pin Cython \u0026lt; 3.3.0 and bump the cp315 numpy pi...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/972441861b1aee44141b60c98c7875e7e4fe23ca\"\u003e\u003ccode\u003e9724418\u003c/code\u003e\u003c/a\u003e Fix Windows py3.15 builds: constrain Cython \u0026lt; 3.3.0 and bump the cp315 numpy ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/f1b755434c258b61307de00f680bb2dc9c50d592\"\u003e\u003ccode\u003ef1b7554\u003c/code\u003e\u003c/a\u003e [MPS] Fix pin_memory() recycling buffers still in use by the GPU (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194662\"\u003e#194662\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/commit/9f205f7b38c08544132b001948ce9109c577c6ed\"\u003e\u003ccode\u003e9f205f7\u003c/code\u003e\u003c/a\u003e [MPS] fail loudly on large reductions (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/194661\"\u003e#194661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pytorch/pytorch/compare/v2.13.0...v2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.13.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.13.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/erick-ti/doppel/pull/82","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/erick-ti%2Fdoppel/issues/82","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/82/packages"}},{"old_version":"==4.*","new_version":"==5.*","update_type":null,"path":null,"pr_created_at":"2026-09-15T23:47:57.000Z","version_change":"==4.* → ==5.*","issue":{"uuid":"5468540029","node_id":"PR_kwDOUcpWsM8AAAABDsIQAg","number":4,"state":"open","title":"Update transformers requirement from ==4.* to ==5.*","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T23:47:57.000Z","updated_at":"2026-09-15T23:47:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Update","packages":[{"name":"transformers","old_version":"==4.*","new_version":"==5.*","repository_url":"https://github.com/huggingface/transformers"}],"path":null,"ecosystem":"pip"},"body":"Updates the requirements on [transformers](https://github.com/huggingface/transformers) to permit the latest version.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v4.0.0-rc-1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Ram004/ai-governance-platform/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Ram004%2Fai-governance-platform/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"}},{"old_version":"5.2.0","new_version":"5.10.1","update_type":"minor","path":null,"pr_created_at":"2026-09-15T22:33:23.000Z","version_change":"5.2.0 → 5.10.1","issue":{"uuid":"5468049854","node_id":"PR_kwDOQs9zJM8AAAABDrvNuw","number":6543,"state":"open","title":"chore(deps): bump the pip group across 1 directory with 18 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":5,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T22:33:23.000Z","updated_at":"2026-09-16T01:04:22.344Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"pip","update_count":18,"packages":[{"name":"python-multipart","old_version":"0.0.22","new_version":"0.0.31","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"pillow","old_version":"12.1.1","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"python-dotenv","old_version":"1.2.1","new_version":"1.2.2","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"pydantic-settings","old_version":"2.13.0","new_version":"2.14.2","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"transformers","old_version":"5.2.0","new_version":"5.10.1","repository_url":"https://github.com/huggingface/transformers"},{"name":"gdown","old_version":"5.2.1","new_version":"5.2.2","repository_url":"https://github.com/wkentaro/gdown"},{"name":"accelerate","old_version":"1.12.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"urllib3","old_version":"2.6.3","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"pytest","old_version":"9.0.2","new_version":"9.0.3","repository_url":"https://github.com/pytest-dev/pytest"},{"name":"idna","old_version":"3.11","new_version":"3.15","repository_url":"https://github.com/kjd/idna"},{"name":"mako","old_version":"1.3.10","new_version":"1.3.12","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"pygments","old_version":"2.19.2","new_version":"2.20.0","repository_url":"https://github.com/pygments/pygments"},{"name":"requests","old_version":"2.32.5","new_version":"2.33.0","repository_url":"https://github.com/psf/requests"},{"name":"setuptools","old_version":"82.0.0","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"soupsieve","old_version":"2.8.3","new_version":"2.8.4","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"starlette","old_version":"0.52.1","new_version":"1.3.1","repository_url":"https://github.com/Kludex/starlette"},{"name":"torch","old_version":"2.10.0","new_version":"2.13.0","repository_url":"https://github.com/pytorch/pytorch"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 18 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.22` | `0.0.31` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.1.1` | `12.3.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.1` | `1.2.2` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.13.0` | `2.14.2` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.2.0` | `5.10.1` |\n| [gdown](https://github.com/wkentaro/gdown) | `5.2.1` | `5.2.2` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.12.0` | `1.15.0` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n| [pytest](https://github.com/pytest-dev/pytest) | `9.0.2` | `9.0.3` |\n| [idna](https://github.com/kjd/idna) | `3.11` | `3.15` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.3.12` |\n| [pygments](https://github.com/pygments/pygments) | `2.19.2` | `2.20.0` |\n| [requests](https://github.com/psf/requests) | `2.32.5` | `2.33.0` |\n| [setuptools](https://github.com/pypa/setuptools) | `82.0.0` | `83.0.0` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.3` | `2.8.4` |\n| [starlette](https://github.com/Kludex/starlette) | `0.52.1` | `1.3.1` |\n| [torch](https://github.com/pytorch/pytorch) | `2.10.0` | `2.13.0` |\n\n\nUpdates `python-multipart` from 0.0.22 to 0.0.31\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/releases\"\u003epython-multipart's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.0.31\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003eKludex/python-multipart#295\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003eKludex/python-multipart#296\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate Content-Length is non-negative in parse_form by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003eKludex/python-multipart#297\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.30\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTreat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003eKludex/python-multipart#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003eKludex/python-multipart#291\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.29\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/manunio\"\u003e\u003ccode\u003e@​manunio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003eKludex/python-multipart#270\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.28\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003eKludex/python-multipart#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003eKludex/python-multipart#282\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.27\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePass parse offsets via constructors by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003eKludex/python-multipart#268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd multipart header limits by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003eKludex/python-multipart#267\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.26\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before first multipart boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003eKludex/python-multipart#262\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003eKludex/python-multipart#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.25\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply Apache-2.0 properly by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003eKludex/python-multipart#247\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003eKludex/python-multipart#252\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md\"\u003epython-multipart's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.31 (2026-06-04)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003e#295\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003e#296\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eValidate \u003ccode\u003eContent-Length\u003c/code\u003e is non-negative in \u003ccode\u003eparse_form\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003e#297\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.30 (2026-05-31)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eParse \u003ccode\u003eapplication/x-www-form-urlencoded\u003c/code\u003e bodies per the WHATWG URL standard, treating only \u003ccode\u003e\u0026amp;\u003c/code\u003e as a field separator \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003e#290\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231/5987 extended parameters (\u003ccode\u003ename*\u003c/code\u003e, \u003ccode\u003efilename*\u003c/code\u003e) in \u003ccode\u003eparse_options_header\u003c/code\u003e, keeping the plain parameter authoritative per \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc7578#section-4.2\"\u003eRFC 7578 §4.2\u003c/a\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003e#291\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.29 (2026-05-17)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003e#270\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.28 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003e#281\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003e#282\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.27 (2026-04-27)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd multipart header limits \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003e#267\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePass parse offsets via constructors \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003e#268\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.26 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before the first multipart boundary more efficiently \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003e#262\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing multipart boundary \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003e#259\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.25 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd MIME content type info to \u003ccode\u003eFile\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/143\"\u003e#143\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle CTE values case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/258\"\u003e#258\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRemove custom \u003ccode\u003eFormParser\u003c/code\u003e classes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/257\"\u003e#257\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eUPLOAD_DELETE_TMP\u003c/code\u003e to \u003ccode\u003eFormParser\u003c/code\u003e config \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/254\"\u003e#254\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEmit \u003ccode\u003efield_end\u003c/code\u003e for trailing bare field names on finalize \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/230\"\u003e#230\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003e#252\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eApply Apache-2.0 properly \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003e#247\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.24 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate \u003ccode\u003echunk_size\u003c/code\u003e in \u003ccode\u003eparse_form()\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/244\"\u003e#244\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.23 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove unused \u003ccode\u003etrust_x_headers\u003c/code\u003e parameter and \u003ccode\u003eX-File-Name\u003c/code\u003e fallback \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/196\"\u003e#196\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReturn processed length from \u003ccode\u003eQuerystringParser._internal_write\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/229\"\u003e#229\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCleanup metadata dunders from \u003ccode\u003e__init__.py\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/227\"\u003e#227\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/4cffc68a165f7a6f6b7756ce006fabf07a05b7a4\"\u003e\u003ccode\u003e4cffc68\u003c/code\u003e\u003c/a\u003e Version 0.0.31 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf\"\u003e\u003ccode\u003ec814948\u003c/code\u003e\u003c/a\u003e Reject negative \u003ccode\u003eContent-Length\u003c/code\u003e in \u003ccode\u003eparse_form\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6b837d47bc68826ed5cbbcb50c6c6a6093444494\"\u003e\u003ccode\u003e6b837d4\u003c/code\u003e\u003c/a\u003e Bound header field name size before validating (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/e0c4f9df2e737d1663fbbdd6563f80613a2089f9\"\u003e\u003ccode\u003ee0c4f9d\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/294\"\u003e#294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/b8a01bb683e8e8675fdb5d831b206a478c8215aa\"\u003e\u003ccode\u003eb8a01bb\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/293\"\u003e#293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6732164f30c58e28589a1e22213d2f6b8c6bad9f\"\u003e\u003ccode\u003e6732164\u003c/code\u003e\u003c/a\u003e Speed up multipart header parsing and callback dispatch (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/295\"\u003e#295\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/9d3ead568a259f222cff6425262ff63e88d930d4\"\u003e\u003ccode\u003e9d3ead5\u003c/code\u003e\u003c/a\u003e Version 0.0.30 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/292\"\u003e#292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/3506c15ce99cb62faf2d5ceb3c4c1e5800cb843d\"\u003e\u003ccode\u003e3506c15\u003c/code\u003e\u003c/a\u003e Ignore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/291\"\u003e#291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8\"\u003e\u003ccode\u003ed69df35\u003c/code\u003e\u003c/a\u003e Treat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/290\"\u003e#290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/1e6ff9740b09fb439755f30e2b0e2ada1d297325\"\u003e\u003ccode\u003e1e6ff97\u003c/code\u003e\u003c/a\u003e Bump idna from 3.11 to 3.15 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.22...0.0.31\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 12.1.1 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/12.1.1...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.1 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (#)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/607\"\u003etheskumar/python-dotenv#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eSupport for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e#790c5\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by \u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip 000 permission tests for root user by \u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/593\"\u003etheskumar/python-dotenv#593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Windows testing to CI by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/604\"\u003etheskumar/python-dotenv#604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove workflow efficiency with best practices by \u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/609\"\u003etheskumar/python-dotenv#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the use of \u003ccode\u003esh\u003c/code\u003e in tests by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/612\"\u003etheskumar/python-dotenv#612\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cpackham-atlnz\"\u003e\u003ccode\u003e@​cpackham-atlnz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/597\"\u003etheskumar/python-dotenv#597\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\"\u003ehttps://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.2] - 2026-03-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/607\"\u003e#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eDropped Support for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in [790c5c0]\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by [\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/590\"\u003e#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/36004e0e34be7665ff2b11a8a4005144f76f176d\"\u003e\u003ccode\u003e36004e0\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.1 → 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/eb202520e5933c9daf42501e1e42fdb0144002c8\"\u003e\u003ccode\u003eeb20252\u003c/code\u003e\u003c/a\u003e docs: update changelog for v1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e\u003ccode\u003e790c5c0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/43340da220fb4ca4f95357bbe21a3c7f8f1278b1\"\u003e\u003ccode\u003e43340da\u003c/code\u003e\u003c/a\u003e Remove the use of \u003ccode\u003esh\u003c/code\u003e in tests (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/612\"\u003e#612\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/09d7cee32459e7abdcb5c9d8122a552589c06a9c\"\u003e\u003ccode\u003e09d7cee\u003c/code\u003e\u003c/a\u003e docs: clarify override behavior and document FIFO support (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/610\"\u003e#610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/c8de2887c00198c22842c5ae5e92d1747467363c\"\u003e\u003ccode\u003ec8de288\u003c/code\u003e\u003c/a\u003e ci: improve workflow efficiency with best practices (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/609\"\u003e#609\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/7bd9e3dbfedc0983ad7d56d5570013035242bdf4\"\u003e\u003ccode\u003e7bd9e3d\u003c/code\u003e\u003c/a\u003e Add Windows testing to CI (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/604\"\u003e#604\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/1baaf04f336072e0ee324d5df9563ec767f14f81\"\u003e\u003ccode\u003e1baaf04\u003c/code\u003e\u003c/a\u003e Drop Python 3.9 support and update to PyPy 3.11 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/608\"\u003e#608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/4a22cf8993804aeede0c20b75bb1a29d3a99e9dc\"\u003e\u003ccode\u003e4a22cf8\u003c/code\u003e\u003c/a\u003e ci: enable testing on Python 3.14t (free-threaded) (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/e2e8e776b42e382ae38b44d3982dd649e7507dd4\"\u003e\u003ccode\u003ee2e8e77\u003c/code\u003e\u003c/a\u003e Fix license specifier (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic-settings` from 2.13.0 to 2.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic-settings/releases\"\u003epydantic-settings's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.14.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eThis is a security patch release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePrevent \u003ccode\u003eNestedSecretsSettingsSource\u003c/code\u003e from following symlinks outside \u003ccode\u003esecrets_dir\u003c/code\u003e by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/889\"\u003epydantic/pydantic-settings#889\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare release 2.14.2 by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/890\"\u003epydantic/pydantic-settings#890\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cp\u003eFixes \u003ca href=\"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j\"\u003eGHSA-4xgf-cpjx-pc3j\u003c/a\u003e: \u003ccode\u003eNestedSecretsSettingsSource\u003c/code\u003e with \u003ccode\u003esecrets_nested_subdir=True\u003c/code\u003e could follow a symbolic link inside \u003ccode\u003esecrets_dir\u003c/code\u003e pointing outside it, reading out-of-tree files into settings values and bypassing the \u003ccode\u003esecrets_dir_max_size\u003c/code\u003e cap. Affected versions: \u003ccode\u003e\u0026gt;= 2.12.0, \u0026lt; 2.14.2\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.14.2\"\u003ehttps://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.14.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.14.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/850\"\u003epydantic/pydantic-settings#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 5 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/854\"\u003epydantic/pydantic-settings#854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the github-actions group with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/853\"\u003epydantic/pydantic-settings#853\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/856\"\u003epydantic/pydantic-settings#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix field named \u003ccode\u003ecls\u003c/code\u003e conflicting with classmethod parameter by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/858\"\u003epydantic/pydantic-settings#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare release 2.14.1 by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/859\"\u003epydantic/pydantic-settings#859\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.14.0...v2.14.1\"\u003ehttps://github.com/pydantic/pydantic-settings/compare/v2.14.0...v2.14.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.14.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing env vars into Optional Strict types by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/792\"\u003epydantic/pydantic-settings#792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix RecursionError with mutually recursive models in CLI by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/794\"\u003epydantic/pydantic-settings#794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix env_file from model_config ignored in CliApp.run() (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/795\"\u003e#795\u003c/a\u003e) by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/796\"\u003epydantic/pydantic-settings#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate dependencies by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/798\"\u003epydantic/pydantic-settings#798\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Dependabot configuration by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/801\"\u003epydantic/pydantic-settings#801\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump samuelcolvin/check-python-version from 4.1 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/802\"\u003epydantic/pydantic-settings#802\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/upload-artifact from 4 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/803\"\u003epydantic/pydantic-settings#803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 4 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/804\"\u003epydantic/pydantic-settings#804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump astral-sh/setup-uv from 5 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/805\"\u003epydantic/pydantic-settings#805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/setup-python from 5 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/806\"\u003epydantic/pydantic-settings#806\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore chardet and group GitHub Actions in Dependabot by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/808\"\u003epydantic/pydantic-settings#808\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/download-artifact from 4 to 8 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/809\"\u003epydantic/pydantic-settings#809\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/810\"\u003epydantic/pydantic-settings#810\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport reading .env files from FIFOs (e.g. 1Password Environments) by \u003ca href=\"https://github.com/JacobHayes\"\u003e\u003ccode\u003e@​JacobHayes\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/776\"\u003epydantic/pydantic-settings#776\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix AliasChoices ignored when changing provider priority by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/813\"\u003epydantic/pydantic-settings#813\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: resolve KeyError in run_subcommand for underscore field names by \u003ca href=\"https://github.com/bradykieffer\"\u003e\u003ccode\u003e@​bradykieffer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/799\"\u003epydantic/pydantic-settings#799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/814\"\u003epydantic/pydantic-settings#814\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eLiteral[numeric Enum]\u003c/code\u003e coercion for CLI and env vars by \u003ca href=\"https://github.com/m9810223\"\u003e\u003ccode\u003e@​m9810223\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/811\"\u003epydantic/pydantic-settings#811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix nested discriminated unions not discovered by env/CLI providers by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/816\"\u003epydantic/pydantic-settings#816\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 3 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/820\"\u003epydantic/pydantic-settings#820\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCLI ensure env nested max split internally. by \u003ca href=\"https://github.com/kschwab\"\u003e\u003ccode\u003e@​kschwab\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/821\"\u003epydantic/pydantic-settings#821\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/824\"\u003epydantic/pydantic-settings#824\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/d703bd717e5e07439fa89da2245eee6139413e9e\"\u003e\u003ccode\u003ed703bd7\u003c/code\u003e\u003c/a\u003e Prepare release 2.14.2 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/890\"\u003e#890\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/e95c30bec8cfaee88ee275138c064aea97a25bdf\"\u003e\u003ccode\u003ee95c30b\u003c/code\u003e\u003c/a\u003e Prepare release 2.14.1 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/859\"\u003e#859\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/0c8734581b6cf70a995afad603ac456631d00621\"\u003e\u003ccode\u003e0c87345\u003c/code\u003e\u003c/a\u003e Fix field named \u003ccode\u003ecls\u003c/code\u003e conflicting with classmethod parameter (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/7bd0072795a800065b42210b6dca90fc9b83daf7\"\u003e\u003ccode\u003e7bd0072\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 2 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/b03e573d017ed48e1c2774a5e0b715db9766c76b\"\u003e\u003ccode\u003eb03e573\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 3 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/853\"\u003e#853\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/eaa3b434938411ec8a3717ea646614561e713f51\"\u003e\u003ccode\u003eeaa3b43\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 5 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/854\"\u003e#854\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/9f95615c24c6813c1d7d203576581a79cb6d9e8e\"\u003e\u003ccode\u003e9f95615\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/850\"\u003e#850\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/8916beeecc6d0510e3d0532a0ed839937400ddc3\"\u003e\u003ccode\u003e8916bee\u003c/code\u003e\u003c/a\u003e Prepare release 2.14.0 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/848\"\u003e#848\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/39e551c0910c85505b608ff85a103b2c9f7396c5\"\u003e\u003ccode\u003e39e551c\u003c/code\u003e\u003c/a\u003e Fix CLI descriptions lost under \u003ccode\u003epython -OO\u003c/code\u003e by falling back to `json_schema_...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/9ed7f48ea2c90f436a03b01f721fe6656c869b14\"\u003e\u003ccode\u003e9ed7f48\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/847\"\u003e#847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.13.0...v2.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cryptography` from 46.0.5 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/46.0.5...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.2.0 to 5.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v5.10.1\u003c/h1\u003e\n\u003cp\u003ev5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!\u003c/p\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eGemma4 unified+ Gemma4 MTP\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eGemma 4 12B Unified is an \u003cstrong\u003eencoder-free\u003c/strong\u003e multimodal model with pretrained and instruction-tuned variants. Unlike \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gemma4\"\u003estandard Gemma 4\u003c/a\u003e, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.\u003c/p\u003e\n\u003cp\u003eKey differences from standard Gemma 4:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo Vision Tower\u003c/strong\u003e: Raw pixel patches are projected directly into LM space via a \u003ccode\u003eDense + LayerNorm\u003c/code\u003e pipeline with factorized 2D positional embeddings, replacing the vision encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNo Audio Tower\u003c/strong\u003e: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple \u003ccode\u003eRMSNorm → Linear\u003c/code\u003e pipeline, replacing the mel spectrogram + Conformer encoder.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eShared Multimodal Pipeline\u003c/strong\u003e: Both vision and audio use the same \u003ccode\u003eGemma4UnifiedMultimodalEmbedder\u003c/code\u003e (RMSNorm → Linear) for the final projection to text hidden space.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou can find the original Gemma 4 12B Unified checkpoints under the \u003ca href=\"https://huggingface.co/collections/google/gemma-4\"\u003eGemma 4\u003c/a\u003e release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewho needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e) by \u003ca href=\"https://github.com/douglas-reid\"\u003e\u003ccode\u003e@​douglas-reid\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/sgerrard\"\u003e\u003ccode\u003e@​sgerrard\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/vasqu\"\u003e\u003ccode\u003e@​vasqu\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/molbap\"\u003e\u003ccode\u003e@​molbap\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSapiens2\u003c/h3\u003e\n\u003cp\u003eSapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2\"\u003eDocumentation\u003c/a\u003e | \u003ca href=\"https://huggingface.co/papers/2604.21681\"\u003ePaper\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e) by \u003ca href=\"https://github.com/guarin\"\u003e\u003ccode\u003e@​guarin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45919\"\u003e#45919\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDeepSeek-OCR-2\u003c/h3\u003e\n\u003cp\u003eDeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Deepseek-OCR-2 model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45075\"\u003e#45075\u003c/a\u003e) by \u003ca href=\"https://github.com/thisisiron\"\u003e\u003ccode\u003e@​thisisiron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/45075\"\u003e#45075\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMellum\u003c/h3\u003e\n\u003cp\u003eMellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/mellum\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Add support for JetBrains' \u003ccode\u003eMellum\u003c/code\u003e v2 code generation model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46112\"\u003e#46112\u003c/a\u003e) by \u003ca href=\"https://github.com/shadeMe\"\u003e\u003ccode\u003e@​shadeMe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/46112\"\u003e#46112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBreaking changes\u003c/h2\u003e\n\u003cp\u003eThe Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 Fix float16 overflow in Gemma4 vision pooler (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46277\"\u003e#46277\u003c/a\u003e) by \u003ca href=\"https://github.com/Bluear7878\"\u003e\u003ccode\u003e@​Bluear7878\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAudio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e🚨 [ALM] Add base model without head (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45534\"\u003e#45534\u003c/a\u003e) by \u003ca href=\"https://github.com/eustlb\"\u003e\u003ccode\u003e@​eustlb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d\"\u003e\u003ccode\u003e90c3ae5\u003c/code\u003e\u003c/a\u003e Patch because we had to yank 5.10 because the release branch was not up to date\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968\"\u003e\u003ccode\u003e0bd94b3\u003c/code\u003e\u003c/a\u003e v5.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897\"\u003e\u003ccode\u003e1423d22\u003c/code\u003e\u003c/a\u003e who needs encoders? (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46385\"\u003e#46385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98\"\u003e\u003ccode\u003e50eb20a\u003c/code\u003e\u003c/a\u003e Fix dsv4 dequant + tp/ep (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46378\"\u003e#46378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299\"\u003e\u003ccode\u003e74464e8\u003c/code\u003e\u003c/a\u003e Fix wrong changes produced by style/repo. check bot (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46371\"\u003e#46371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc\"\u003e\u003ccode\u003e1b8ec34\u003c/code\u003e\u003c/a\u003e Fix path traversal when saving Bark voice preset embeddings (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46237\"\u003e#46237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872\"\u003e\u003ccode\u003ee820678\u003c/code\u003e\u003c/a\u003e Add Sapiens2 Model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45919\"\u003e#45919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43\"\u003e\u003ccode\u003e595721c\u003c/code\u003e\u003c/a\u003e Pass library_name/version to Hub calls via a shared HfApi (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46318\"\u003e#46318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a\"\u003e\u003ccode\u003e0f0036c\u003c/code\u003e\u003c/a\u003e docs: update ACL Anthology URL in CITATION.cff (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46352\"\u003e#46352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353\"\u003e\u003ccode\u003efa6c830\u003c/code\u003e\u003c/a\u003e DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/45634\"\u003e#45634\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.2.0...v5.10.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `gdown` from 5.2.1 to 5.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/wkentaro/gdown/releases\"\u003egdown's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.2.2\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix path traversal vulnerability in extractall() that allowed zip/tar archives with ../ entries to write files outside the target directory (GHSA-76hw-p97h-883f)\u003c/li\u003e\n\u003cli\u003eReject symlinks, hardlinks, and special files in tar archives\u003c/li\u003e\n\u003cli\u003eUse Python 3.12+ filter=\u0026quot;data\u0026quot; for safe tar extraction when available\u003c/li\u003e\n\u003cli\u003eSanitize filenames from HTTP responses and URLs to prevent path traversal via /, , .., and null bytes\u003c/li\u003e\n\u003cli\u003eSanitize root folder name in download_folder() before building directory paths\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wkentaro/gdown/commit/af569fc6ed300b7974dee66dc51e9f01b57b4dff\"\u003e\u003ccode\u003eaf569fc\u003c/code\u003e\u003c/a\u003e fix: prevent path traversal in archive extraction and filename handling\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/wkentaro/gdown/compare/v5.2.1...v5.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.12.0 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (tru...\n\n_Description has been truncated_","html_url":"https://github.com/mikesvoboda/nemotron-v3-home-security-intelligence/pull/6543","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/mikesvoboda%2Fnemotron-v3-home-security-intelligence/issues/6543","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6543/packages"}}]}