Skip to content

Bump the pip group across 72 directories with 5 updates - #570

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-aitk/requirements/pip-7f63205e69
Open

Bump the pip group across 72 directories with 5 updates#570
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-aitk/requirements/pip-7f63205e69

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip group with 5 updates in the /.aitk/requirements directory:

Package From To
aiohttp 3.14.0 3.14.3
cryptography 49.0.0 50.0.0
onnx 1.17.0 1.22.0
gitpython 3.1.50 3.1.57
nltk 3.9.4 3.10.0

Bumps the pip group with 3 updates in the /.aitk/requirements/AMD directory: aiohttp, onnx and nltk.
Bumps the pip group with 3 updates in the /.aitk/requirements/General directory: aiohttp, onnx and gitpython.
Bumps the pip group with 2 updates in the /.aitk/requirements/Intel directory: aiohttp and onnx.
Bumps the pip group with 1 update in the /Flux.2-Klein-4B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen1.5-7B-Chat/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen1.5-7B-Chat/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2-1.5B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2-7B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2-7B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-0.5B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-0.5B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-1.5B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-1.5B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-3B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-3B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-7B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-7B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-Coder-0.5B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-Coder-0.5B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-Coder-1.5B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-Coder-1.5B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-Coder-7B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /Qwen-Qwen2.5-Coder-7B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /amd-AMD-OLMo-1B-SFT-DPO/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /codellama-CodeLlama-7b-Instruct-hf/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /deepseek-ai-DeepSeek-R1-Distill-Llama-8B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /deepseek-ai-DeepSeek-R1-Distill-Llama-8B/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /deepseek-ai-DeepSeek-R1-Distill-Qwen-1.5B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /deepseek-ai-DeepSeek-R1-Distill-Qwen-1.5B/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /deepseek-ai-DeepSeek-R1-Distill-Qwen-7B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /deepseek-ai-DeepSeek-R1-Distill-Qwen-7B/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /gpt-oss-20b/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /intel-bert-base-uncased-mrpc/oci/cpu directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-2-7b-chat-hf/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-2-7b-chat-hf/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-2-7b-hf/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-2-7b-hf/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.1-8B-Instruct/QNN directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.1-8B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.1-8B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.1-8B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.1-8B/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.2-1B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.2-1B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.2-1B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.2-3B-Instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.2-3B-Instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Llama-3.2-3B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Meta-Llama-3-8B/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /meta-llama-Meta-Llama-3-8B/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3-mini-128k-instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3-mini-128k-instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3-mini-4k-instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3-mini-4k-instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3.5-mini-instruct/QNN directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3.5-mini-instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-3.5-mini-instruct/VitisAI directory: onnx.
Bumps the pip group with 3 updates in the /microsoft-Phi-4-mini-instruct/QAIRT directory: aiohttp, cryptography and onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-4-mini-instruct/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-4-mini-instruct/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-4-mini-reasoning/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-4-mini-reasoning/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /microsoft-Phi-4-reasoning/QNN directory: onnx.
Bumps the pip group with 1 update in the /mistralai-Mistral-7B-Instruct-v0.1/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /mistralai-Mistral-7B-Instruct-v0.2/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /mistralai-Mistral-7B-Instruct-v0.2/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /mistralai-Mistral-7B-Instruct-v0.3/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /mistralai-Mistral-7B-Instruct-v0.3/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /mistralai-Mistral-7B-v0.3/RyzenAI directory: onnx.
Bumps the pip group with 1 update in the /sd-legacy-stable-diffusion-v1-5/VitisAI directory: onnx.
Bumps the pip group with 1 update in the /sd-legacy-stable-diffusion-v1-5/olive directory: aiohttp.

Updates aiohttp from 3.14.0 to 3.14.3
Updates cryptography from 49.0.0 to 50.0.0

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Updates onnx from 1.17.0 to 1.22.0

Release notes

Sourced from onnx's releases.

v1.22.0

ONNX v1.22.0 is now available with exciting new features! We would like to thank everyone who contributed to this release! Please visit onnx.ai to learn more about ONNX and associated projects.

What's Changed

Breaking Changes and Deprecations

Spec and Operator

Two new operators LinearAttention-27 and CausalConvWithState-27 were introduced.

Reference Implementation

Utilities and Tools

Build, CI and Tests

... (truncated)

Commits

Updates gitpython from 3.1.50 to 3.1.57

Release notes

Sourced from gitpython's releases.

3.1.57 - Security and Fixes

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.56...3.1.57

3.1.56 - SECURITY

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.55...3.1.56

3.1.55 - Security

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.54...3.1.55

3.1.54 - Security

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.53...3.1.54

3.1.53 - Security

What's Changed

New Contributors

... (truncated)

Commits
  • ccbd573 prepare for new release
  • d1a631d Merge pull request #2193 from gitpython-developers/more-unsafe-options
  • ab33e33 Merge pull request #2194 from gitpython-developers/fix-basedpyright
  • 52199b3 address review comments
  • 60dec71 Adopt basedpyright with a legacy baseline
  • 7a4f5dc Block unsafe archive additions and bundle URI
  • 3af0c25 Block unsafe checkout-index and tag file options
  • fb5d584 Merge pull request #2187 from pick7/codex/remote-progress-return-type
  • 951cc44 Merge pull request #2188 from pick7/codex/redact-http-extraheader
  • 2e5b13f Merge pull request #2189 from pick7/codex/output-stream-timeout
  • Additional commits viewable in compare view

Updates nltk from 3.9.4 to 3.10.0

Release notes

Sourced from nltk's releases.

v3.10.0-rc1

What's Changed

... (truncated)

Changelog

Sourced from nltk's changelog.

Version 3.10.1 2026-07-29

  • Expand ~ in env-var paths
  • Validate types after WordNet app pickle deserialization
  • Fix uncontrolled search path in HunposTagger
  • Use exact thirds in masi_distance
  • Avoid retaining bllip import exceptions
  • Fix word_tokenize: pad opening single quote before multi-letter words.
  • Implement Tree.pformat_latex_forest.
  • Prevent module hijacking in inline imports.
  • Fix ReDoS in TweetTokenizer URL and email regexes.

Thanks to the following contributors to 3.10.1: Abhinav, Litesh Ghute, Eric Kafe, Eryk Kaźmierczak, Selim C., Muhtasim Munif Fahim, Triniti K., and Tom Y. Mitich.

Version 3.10.0 2026-06-11

  • Enforce the stricter nltk.pathsec security policy by default
  • Document the new security model and migration guidance
  • Harden resource loading against path traversal and SSRF/DNS-rebinding
  • Harden downloader path handling and block XML entity expansion
  • Close remaining corpus-reader security edge cases
  • Replace unsafe exec() usage in the utility CLI
  • Warn on unpickling user-provided pickles
  • Add HuggingFace datasets integration (nltk.huggingface)
  • Align TnT with Brants (2000) specifications
  • Fix PorterStemmer irregular-form lowercasing in NLTK mode
  • Fix TransitionParser sparse index dtype for scikit-learn 1.9
  • Fix TextCat tie handling
  • Fix WordNet object comparisons for incompatible types
  • Cache WordNet max depth lazily for lch_similarity()
  • Fix CCG variable direction, substitution, and type-raising bugs
  • Fix Jaro similarity for single-character and empty-string cases
  • Improve CI and release-maintenance workflows

Thanks to the following contributors to 3.10.0: 13rac1, alvations, bowiechen, devesh-2002, ekaf, elias-ba, haosenwang1018, HyperPS, ihitamandal, jancallewaert, jhnwnstd, JuanIMartinezB, Lemm1, LinZiyuu, Mr-Neutr0n, PastelStorm, scruge1, Syzygy2048, ylwango613, yzhaoinuw

Version 3.9.4 2026-03-24

  • Support Python 3.14
  • Fix bug in Levenshtein distance when substitution_cost > 2
  • Fix bug in Treebank detokeniser re quote ordering
  • Fix bug in Jaro similarity for empty strings
  • Several security enhancements
  • Fix GHSA-rf74-v2fm-23pw: unbounded recursion in JSONTaggedDecoder

... (truncated)

Commits
  • bd49f90 allow escaped brackets in Tree.fromstring (#3694)
  • 27b8ad6 don't crash chomsky_normal_form on terminals with siblings (#3693)
  • 52227d2 Use os.name for Windows path handling (#3605)
  • 06c0e2c Avoid RIBES zero division on empty inputs (#3604)
  • a167389 Treat missing unzip output as stale (#3607)
  • c94c967 Fix EOF empty document bug in IEER corpus reader (#3648)
  • 94a259c Enforce restrictive primitive type checking in pathsec wrappers (#3692)
  • 5ac475d fix(security): isolate Stanford Java options and clean temp files (#3683)
  • 986f26e ci(deps): bump the github-actions group with 3 updates (#3691)
  • f26b375 fix(security): prevent pickle RCE in TransitionParser model loading (CWE-502)...
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.3
Updates onnx from 1.18.0 to 1.22.0

Release notes

Sourced from onnx's releases.

v1.22.0

ONNX v1.22.0 is now available with exciting new features! We would like to thank everyone who contributed to this release! Please visit onnx.ai to learn more about ONNX and associated projects.

What's Changed

Breaking Changes and Deprecations

Spec and Operator

Two new operators LinearAttention-27 and CausalConvWithState-27 were introduced.

Reference Implementation

Utilities and Tools

Build, CI and Tests

... (truncated)

Commits

Updates nltk from 3.9.4 to 3.10.0

Release notes

Sourced from nltk's releases.

v3.10.0-rc1

What's Changed

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: gitpython
  dependency-version: 3.1.57
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: nltk
  dependency-version: 3.10.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: nltk
  dependency-version: 3.10.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: gitpython
  dependency-version: 3.1.57
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: onnx
  dependency-version: 1.22.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 4, 2026
Copilot AI lite review requested due to automatic review settings August 4, 2026 16:48
@dependabot
dependabot Bot requested review from a team as code owners August 4, 2026 16:48
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 4, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

This PR updates pinned dependency versions across multiple model/recipe requirement files (QNN, VitisAI, RyzenAI, and AITK envs), primarily to align on newer onnx and to refresh a handful of other commonly used packages.

Changes:

  • Bump onnx pins broadly to 1.22.0 across many environments/recipes.
  • Bump aiohttp pins to 3.14.3 in multiple requirement sets.
  • Update a few additional pins (cryptography, gitpython, nltk) in select environments.

Reviewed changes

Copilot reviewed 82 out of 82 changed files in this pull request and generated no comments.

Show a summary per file
File Description
sd-legacy-stable-diffusion-v1-5/olive/requirements_qnn.txt Bumps aiohttp pin.
sd-legacy-stable-diffusion-v1-5/VitisAI/requirements_vitisai_sd.txt Bumps onnx pin.
mistralai-Mistral-7B-v0.3/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
mistralai-Mistral-7B-Instruct-v0.3/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
mistralai-Mistral-7B-Instruct-v0.3/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
mistralai-Mistral-7B-Instruct-v0.2/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
mistralai-Mistral-7B-Instruct-v0.2/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
mistralai-Mistral-7B-Instruct-v0.1/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
microsoft-Phi-4-reasoning/QNN/requirements.txt Bumps onnx pin.
microsoft-Phi-4-mini-reasoning/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
microsoft-Phi-4-mini-reasoning/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
microsoft-Phi-4-mini-instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
microsoft-Phi-4-mini-instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
microsoft-Phi-4-mini-instruct/QAIRT/requirements.txt Bumps aiohttp, cryptography, onnx pins.
microsoft-Phi-3.5-mini-instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
microsoft-Phi-3.5-mini-instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
microsoft-Phi-3.5-mini-instruct/QNN/requirements.txt Bumps onnx pin.
microsoft-Phi-3-mini-4k-instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
microsoft-Phi-3-mini-4k-instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
microsoft-Phi-3-mini-128k-instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
microsoft-Phi-3-mini-128k-instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Meta-Llama-3-8B/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Meta-Llama-3-8B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.2-3B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.2-3B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.2-3B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.2-1B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.2-1B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.2-1B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.1-8B/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.1-8B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.1-8B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.1-8B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-3.1-8B-Instruct/QNN/requirements.txt Bumps onnx pin.
meta-llama-Llama-2-7b-hf/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Llama-2-7b-hf/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
meta-llama-Llama-2-7b-chat-hf/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
meta-llama-Llama-2-7b-chat-hf/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
intel-bert-base-uncased-mrpc/oci/cpu/requirements.txt Bumps onnx pin.
gpt-oss-20b/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
deepseek-ai-DeepSeek-R1-Distill-Qwen-7B/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
deepseek-ai-DeepSeek-R1-Distill-Qwen-7B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
deepseek-ai-DeepSeek-R1-Distill-Qwen-1.5B/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
deepseek-ai-DeepSeek-R1-Distill-Qwen-1.5B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
deepseek-ai-DeepSeek-R1-Distill-Llama-8B/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
deepseek-ai-DeepSeek-R1-Distill-Llama-8B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
codellama-CodeLlama-7b-Instruct-hf/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
amd-AMD-OLMo-1B-SFT-DPO/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-Coder-7B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-Coder-7B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-Coder-1.5B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-Coder-1.5B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-Coder-0.5B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-Coder-0.5B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-7B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-7B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-3B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-3B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-1.5B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-1.5B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-0.5B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2.5-0.5B-Instruct/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2-7B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen2-7B-Instruct/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen2-1.5B/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Qwen-Qwen1.5-7B-Chat/VitisAI/requirements_vitisai_llm.txt Bumps onnx pin.
Qwen-Qwen1.5-7B-Chat/RyzenAI/requirements_ryzenai_llm.txt Bumps onnx pin.
Flux.2-Klein-4B/RyzenAI/requirements_ryzenai_sd.txt Bumps onnx pin.
.aitk/requirements/requirements-WinMLCLI.txt Bumps aiohttp, cryptography, onnx pins.
.aitk/requirements/requirements-WCR.txt Bumps aiohttp, onnx pins.
.aitk/requirements/requirements-WCR-QAI.txt Bumps gitpython pin.
.aitk/requirements/requirements-QNN.txt Bumps aiohttp, onnx pins.
.aitk/requirements/requirements-Profiling.txt Bumps onnx pin.
.aitk/requirements/requirements-NvidiaGPU.txt Bumps aiohttp, onnx pins.
.aitk/requirements/requirements-IntelNPU.txt Bumps aiohttp, onnx pins.
.aitk/requirements/requirements-IntelNPU-WP.txt Bumps onnx pin.
.aitk/requirements/Intel/Test_py3.12.9.txt Bumps aiohttp, onnx pins.
.aitk/requirements/General/CUDA_py3.12.9.txt Bumps aiohttp, onnx pins.
.aitk/requirements/General/CUDA_py3.12.9-NVModelOptQuantization.txt Bumps onnx pin.
.aitk/requirements/General/CPU_py3.12.9.txt Bumps aiohttp, onnx pins.
.aitk/requirements/General/CPU_py3.12.9-QAI.txt Bumps gitpython pin.
.aitk/requirements/AMD/Quark_py3.12.13.txt Bumps aiohttp, nltk, onnx pins.
Suppressed comments (1)

microsoft-Phi-4-mini-instruct/QAIRT/requirements.txt:1

  • cryptography==50.0.0 is not a version I can verify exists. If this is intended for a security refresh, consider pinning to a known released cryptography version (or a constrained range) to avoid breaking installs and to ensure OpenSSL compatibility on all target platforms.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant