-
Notifications
You must be signed in to change notification settings - Fork 28
security(deps): bump the inference-dependencies group across 1 directory with 10 updates #544
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,25 +4,25 @@ version = "0.1.0" | |
| description = "Evaluation workflow runtime dependencies" | ||
| requires-python = ">=3.12" | ||
| dependencies = [ | ||
| "numpy==2.2.6", | ||
| "numpy==2.4.4", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. ABI note — numpy 2.2.6 → 2.4.4 (within 2.x series). The jump crosses numpy 2.3 and 2.4 minor releases. Both are bug-fix/maintenance series with no known CUDA ABI break, and 2.4.4 specifically resolves an OpenBLAS threading issue on ARM (numpy#30816). Cross-surface divergence: Validation: |
||
| "azure-core==1.39.0", | ||
| "azure-storage-blob==12.28.0", | ||
| "azure-identity==1.25.3", | ||
| "azure-ai-ml==1.32.0", | ||
| "marshmallow==3.26.2", | ||
| "marshmallow==4.3.0", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Note: |
||
| "mlflow==3.11.1", | ||
| "packaging==25.0", | ||
| "packaging==26.1", | ||
| "psutil==7.2.2", | ||
| "pynvml==13.0.1", | ||
| "pyperclip==1.11.0", | ||
| "onnx==1.21.0", | ||
| "onnxscript==0.6.2", | ||
| "onnxruntime-gpu==1.24.4", | ||
| "onnxscript==0.7.0", | ||
| "onnxruntime-gpu==1.25.0", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Additionally, this release notes the fix for CVE-2026-27904 (via |
||
| "toml==0.10.2", | ||
| "gymnasium==1.2.3", | ||
| "torch==2.10.0", | ||
| "tensordict==0.12.1", | ||
| "lerobot==0.5.0", | ||
| "gymnasium==1.3.0", | ||
| "torch==2.11.0", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. torch 2.10.0 → 2.11.0 — minor version, but PyTorch minor releases routinely include backwards-incompatible changes. The PyTorch 2.11.0 release notes list a "Backwards Incompatible Changes" section (see release engineering and Security sub-sections). Verify
|
||
| "tensordict==0.12.2", | ||
| "lerobot==0.5.1", | ||
| ] | ||
|
|
||
| [build-system] | ||
|
|
@@ -37,10 +37,10 @@ dev = [ | |
| "pytest==9.0.3", | ||
| "pytest-mock==3.15.1", | ||
| "pytest-cov==7.1.0", | ||
| "hypothesis==6.151.13", | ||
| "hypothesis==6.152.1", | ||
| "matplotlib==3.10.8", | ||
| "numpy==2.2.6", | ||
| "torch==2.10.0", | ||
| "numpy==2.4.4", | ||
| "torch==2.11.0", | ||
| ] | ||
|
|
||
| [tool.pytest.ini_options] | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lock file not updated. This PR modifies
evaluation/pyproject.tomlbut the correspondingevaluation/uv.lockis not included in the diff. After merge, runninguv syncin theevaluation/directory will regenerate the lock file. CI that relies on the lock file for reproducible installs should regenerate and commit it, or the environment may still install the old pinned versions until the lock is refreshed.