-
Notifications
You must be signed in to change notification settings - Fork 33
security(deps): bump the inference-dependencies group across 1 directory with 8 updates #539
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,25 +4,25 @@ version = "0.1.0" | |
| description = "Evaluation workflow runtime dependencies" | ||
| requires-python = ">=3.12" | ||
| dependencies = [ | ||
| "numpy==2.2.6", | ||
| "numpy==2.4.4", | ||
| "azure-core==1.39.0", | ||
| "azure-storage-blob==12.28.0", | ||
| "azure-identity==1.25.3", | ||
| "azure-ai-ml==1.32.0", | ||
| "marshmallow==3.26.2", | ||
| "marshmallow==4.3.0", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
No Python files in Validation: |
||
| "mlflow==3.11.1", | ||
| "packaging==25.0", | ||
| "packaging==26.1", | ||
| "psutil==7.2.2", | ||
| "pynvml==13.0.1", | ||
| "pyperclip==1.11.0", | ||
| "onnx==1.21.0", | ||
| "onnxscript==0.6.2", | ||
| "onnxscript==0.7.0", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. onnxscript 0.6.2 → 0.7.0 — pre-1.0 minor bump
Changelog: microsoft/onnxscript releases. Verify that any |
||
| "onnxruntime-gpu==1.24.4", | ||
| "toml==0.10.2", | ||
| "gymnasium==1.2.3", | ||
| "torch==2.10.0", | ||
| "tensordict==0.12.1", | ||
| "lerobot==0.5.0", | ||
| "torch==2.11.0", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. torch 2.10.0 → 2.11.0 — check onnxruntime-gpu ABI compatibility Minor version bump for PyTorch on the
No security advisories identified for this bump. |
||
| "tensordict==0.12.2", | ||
| "lerobot==0.5.1", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. lerobot 0.5.0 → 0.5.1 — pre-1.0 patch bump Patch release in a pre-1.0 package. Low risk, but confirm this version is compatible with the Source: huggingface/lerobot releases |
||
| ] | ||
|
|
||
| [build-system] | ||
|
|
@@ -37,10 +37,10 @@ dev = [ | |
| "pytest==9.0.3", | ||
| "pytest-mock==3.15.1", | ||
| "pytest-cov==7.1.0", | ||
| "hypothesis==6.151.13", | ||
| "hypothesis==6.152.1", | ||
| "matplotlib==3.10.8", | ||
| "numpy==2.2.6", | ||
| "torch==2.10.0", | ||
| "numpy==2.4.4", | ||
| "torch==2.11.0", | ||
| ] | ||
|
|
||
| [tool.pytest.ini_options] | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
numpy 2.2.6 → 2.4.4 — cross-minor jump on ABI-sensitive surface
This bump skips the entire
2.3.xseries and lands on2.4.4. NumPy 2.x introduced C-ABI breaking changes (NEP 47/50). The 2.4.x branch supports Python 3.11–3.14 and includes fixes for OpenBLAS threading on ARM (issue #30816) — no security advisories found.Risk:
onnxruntime-gpu==1.24.4is pinned alongside this and is CUDA/ABI-sensitive. Verifyonnxruntime-gpubuilt against numpy 2.x ABI is compatible with numpy 2.4. Runpytest evaluation/tests/on a GPU node before merging.Source: NumPy 2.4.4 release notes