Skip to content

chore(deps): bump the python-dependencies group with 5 updates - #41

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-bf9ce90cd7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-bf9ce90cd7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on torch, transformers, peft, fastapi and tomli to permit the latest version.
Updates torch to 2.14.1

Release notes

Sourced from torch's releases.

PyTorch 2.14.1 Release

This release is meant to fix the following regressions and silent correctness issues:

Silent correctness fixes

  • Fix incorrect torch.linalg.lstsq solutions on MPS for complex batched underdetermined systems (#196113), fixed by #196128
  • Fix non-orthogonal U and inaccurate small singular values from torch.linalg.svd on MPS for rank-deficient and ill-conditioned inputs (#196112), fixed by #196139 and #199063
  • Update the CUDA 13.2 Linux binaries to CUDA 13.2.2 (#196351). This NVIDIA update resolves two critical issues that could produce incorrect results (CUDA 13.2.2 release notes):
    • cuBLAS: cublasLtMatmul() could ignore tensor-wide scaling for NVFP4 matrix multiplications (introduced in CUDA 13.2 Update 1)
    • Compiler: failed thread reconvergence could leave stale or corrupted register values in kernels with nested thread divergence (present since CUDA 12.8)

Regression fixes

  • Fix torch.linalg.svd, torch.linalg.svdvals and torch.linalg.lstsq failing on MPS with a Metal pipeline-state error for inputs above 8192 elements (#195937), fixed by #195949 and #195950
  • Fix internal assert in torch.svd(out=) on MPS for complex inputs (#195822), fixed by #195872
Changelog

Sourced from torch's changelog.

Releasing PyTorch

Release Compatibility Matrix

Following is the Release Compatibility Matrix for PyTorch releases:

... (truncated)

Commits
  • 5c48869 [MPS] Fix Jacobi SVD convergence for small columns (#199086)
  • 35223a2 [release/2.14] Run the release runner-group reconcile in pytorch/pytorch (#19...
  • 41ffbc4 [release-only] Update version to 2.14.1 (#198661)
  • e8f0c01 [release/2.14] [CD] Update to CUDA 13.2.2 for Linux binaries (#198644)
  • 911665d [MPS] Cherry-pick native SVD fixes into release/2.14 (#198394)
  • 2b3ec34 [release/2.14] Import SDPAParams in test_transformers to fix lint (#194970)
  • 08187d9 [cuDNN] Add guards for cuDNN SDPA decode (#194963)
  • 8ceea97 Pin cython < 3.3.0 for the Windows Triton wheel build (#194931)
  • 99ecebc [Cherry-pick][release/2.14] [inductor] Fix loop-local load CSE lifetime (#194...
  • ec283a7 Bump the Python 3.15 numpy pin to 2.5.2 (#194821)
  • Additional commits viewable in compare view

Updates transformers to 5.18.0

Release notes

Sourced from transformers's releases.

Release 5.18.0

New Model additions

Nemotron 3 Diarization

Nemotron 3 Diarization is an open-weight streaming speaker diarization model designed to determine "who spoke when" in real-world audio. It supports both streaming and offline inference, handles up to eight speakers, and orders speaker outputs by each speaker's first arrival in the input audio.

The model uses the Arrival-Order Speaker Cache (AOSC) 1 and FIFO queue introduced for Streaming Sortformer 1, 2. A single checkpoint supports configurable latency profiles, from an 80 ms input buffer to a 30.4 s offline-style buffer, and configurable output frame resolution in multiples of 10 ms. With chunked inference, the maximum audio duration is not limited.

Links: Documentation

NemotronH Omni

NemotronH Omni is a multimodal reasoning model from NVIDIA that pairs the NemotronH hybrid Mamba-Transformer language model with a RADIO vision encoder and an optional Parakeet-based sound encoder. Image (and video) patches are projected through a RADIO tower and a pixel-shuffle MLP into the language model's embedding space at the <image> / <video> context-token positions; audio clips are projected in the same way at <audio> positions. The result is a single autoregressive model that reasons jointly over text, images, video and sound.

Links: Documentation

HyperCLOVAX Vision V2

HyperCLOVAX Vision V2 is a multimodal vision-language model developed by NAVER. It combines the HyperClovaX language model backbone with a Qwen2.5-VL vision encoder. The model supports text, image, and video inputs and is capable of chain-of-thought reasoning via built-in thinking tokens (<think>...</think>).

Links: Documentation

GTE

GTE was proposed in mGTE: Generalized Long-Context Text Representation and Reranking Models for Multilingual Text Retrieval by Xin Zhang, Yanzhao Zhang, Dingkun Long, Wen Xie, Ziqi Dai, Jialong Tang, Huan Lin, Baosong Yang, Pengjun Xie, Fei Huang, Meishan Zhang, Wenjie Li and Min Zhang.

GTE is a BERT-style bidirectional encoder that replaces absolute position embeddings with RoPE, uses a gated MLP, and applies layer normalization after each residual connection. The same architecture backs Alibaba's gte-*-v1.5, gte-multilingual-* and gte-en-mlm-* checkpoints as well as Snowflake's snowflake-arctic-embed-m-v2.0.

Links: Documentation

Breaking changes

... (truncated)

Commits
  • a906d3c v5.18.0
  • 57296d1 model: Add GTE to Transformers (#48416)
  • 88536f2 [Nemotron3Diarization] fix streaming last stft frame dropped (#49167)
  • 5cd2877 Fix missing router_logits in Qwen3.5-MoE and other MoE models (#49179)
  • 4fcb1ff Fix MiniMax M3 partial 3D vision rotary embeddings (#49164)
  • 8520b15 Add Strix Halo (gfx1151) Atlas Inference Hub-kernel path for Qwen3.5/3.6/3.8 ...
  • a877116 Fix MPS GQA version gating (#49210)
  • e0299e2 Fix additional_special_tokens data loss with extra_special_tokens (#47848)
  • 5aab642 Fix stale _added_tokens_encoder entries in cpmant and wav2vec2 (#47440)
  • 0c18a63 Fix deepstack features for mixed-input (#49177)
  • Additional commits viewable in compare view

Updates peft to 0.21.2

Release notes

Sourced from peft's releases.

v0.21.2

This is a PEFT release fixes an issue that prevented encoder-decoder models to work when using Transformers ≥ 5.18.0.

Changes:

Commits

Updates fastapi to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.
Commits

Updates tomli to 2.4.1

Changelog

Sourced from tomli's changelog.

2.4.1

  • Fixed
    • Limit number of parts of a TOML key to address quadratic time complexity

2.4.0

  • Added
    • TOML v1.1.0 compatibility
    • Binary wheels for Windows arm64

2.3.0

  • Added
    • Binary wheels for Python 3.14 (also free-threaded)
  • Performance
    • Reduced import time

2.2.1

  • Fixed
    • Don't attempt to compile binary wheels for Python 3.8, 3.9 and 3.10 where cibuildwheel depends on a conflicting Tomli version

2.2.0

  • Added
    • mypyc generated binary wheels for common platforms

2.1.0

  • Deprecated
    • Instantiating TOMLDecodeError with free-form arguments. msg, doc and pos arguments should be given.
  • Added
    • msg, doc, pos, lineno and colno attributes to TOMLDecodeError

2.0.2

  • Removed
    • Python 3.7 support
  • Improved
    • Make loads raise TypeError not AttributeError on bad input types that do not have the replace attribute. Improve error message when bytes is received.
  • Type annotations
    • Type annotate load input as typing.IO[bytes] (previously typing.BinaryIO).

2.0.1

  • Improved
    • Make bundling easier by using relative imports internally and adding license and copyright notice to source files.

... (truncated)

Commits
  • c5f4469 Bump version: 2.4.0 → 2.4.1
  • 2bcd262 Add change log for 2.4.1 and 2.3.1
  • e1fdb94 Limit number of parts of a key (#286)
  • c20c491 pre-commit autoupdate
  • 920e20b Update performance benchmark and results
  • 064e492 Merge pull request #280 from hukkin/version-2.4.0
  • a678e6f Bump version: 2.3.0 → 2.4.0
  • b8a1358 Tests: remove now needless "TOML compliance"->"burntsushi" format conversion
  • 4979375 Update GitHub actions
  • f890dd1 Update pre-commit hooks
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [torch](https://github.com/pytorch/pytorch), [transformers](https://github.com/huggingface/transformers), [peft](https://github.com/huggingface/peft), [fastapi](https://github.com/fastapi/fastapi) and [tomli](https://github.com/hukkin/tomli) to permit the latest version.

Updates `torch` to 2.14.1
- [Release notes](https://github.com/pytorch/pytorch/releases)
- [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md)
- [Commits](pytorch/pytorch@ciflow/torchtitan/113258...v2.14.1)

Updates `transformers` to 5.18.0
- [Release notes](https://github.com/huggingface/transformers/releases)
- [Commits](huggingface/transformers@v5.17.0...v5.18.0)

Updates `peft` to 0.21.2
- [Release notes](https://github.com/huggingface/peft/releases)
- [Commits](huggingface/peft@v0.21.0...v0.21.2)

Updates `fastapi` to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `tomli` to 2.4.1
- [Changelog](https://github.com/hukkin/tomli/blob/master/CHANGELOG.md)
- [Commits](hukkin/tomli@2.0.0...2.4.1)

---
updated-dependencies:
- dependency-name: torch
  dependency-version: 2.14.1
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: transformers
  dependency-version: 5.18.0
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: peft
  dependency-version: 0.21.2
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: tomli
  dependency-version: 2.4.1
  dependency-type: direct:production
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants