Skip to content

chore(deps): bump the python-deps group across 1 directory with 6 updates - #4

Merged
parkghost merged 1 commit into
mainfrom
dependabot/uv/cortex-tts/python-deps-2406a20dad
Oct 3, 2026
Merged

parkghost merged 1 commit into
mainfrom
dependabot/uv/cortex-tts/python-deps-2406a20dad

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-deps group with 6 updates in the /cortex-tts directory:

Package From To
numpy 2.5.2 2.5.3
onnx 1.22.0 1.23.0
huggingface-hub 1.30.0 1.33.0
onnxruntime 1.29.0 1.30.0
ruff 0.16.6 0.16.9
pyright 1.1.411 1.1.414

Updates numpy from 2.5.2 to 2.5.3

Release notes

Sourced from numpy's releases.

v2.5.3 (Sep 6, 2026)

NumPy 2.5.3 Release Notes

The NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2 release. Apart from the usual bug and maintenance work, there are a number of StringDType related fixes for problems discovered during the ongoing string work in the main branch.

This release supports Python versions 3.12-3.15

Changes

  • Casting a fixed-width byte string array (np.bytes_) to StringDType now raises TypeError when the bytes are not valid UTF-8. Previously the invalid bytes were stored as-is and later caused undefined behavior in string operations.

    (gh-32296)

  • MaskedArray._fill_value would become stale when ufuncs that change dtype left the result holding a fill_value typed for the old dtype. The mismatch was silent until something later called _check_fill_value, such as .view(), and then a TypeError would be raised. Now, when the copied fill_value is no longer valid for the new dtype, fall back to the default fill_value for that dtype instead of propagating the stale value. This may raise a ComplexWarning if the fill_value is complex and the new dtype is real.

    (gh-32423)

Contributors

A total of 9 people contributed to this release. People with a "+" by their names contributed a patch for the first time.

  • Charles Harris
  • Iason Krommydas
  • James Davies +
  • Joren Hammudoglu
  • Maanas Arora
  • Matti Picus
  • Nathan Goldbaum
  • Shikhar Goel +
  • Yeonho Kim +

Pull requests merged

A total of 27 pull requests were merged for this release.

  • #32235: MAINT: Prepare 2.5.x for further development

... (truncated)

Commits
  • dd88c0c Merge pull request #32511 from charris/prepare-2.5.3
  • edcac6a REL: Prepare for the NumPy 2.5.3 release
  • fd4d908 Merge pull request #32509 from charris/backport-32496
  • 65bb1da BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (#32496)
  • 294956e Merge pull request #32506 from charris/backport-32503
  • 26428d9 DOC: fix scipy docs links in intersphinx mapping (#32507)
  • 5fab1cb DOC: use static scipy doc site for intershpinx (#32503)
  • 7beed2f Merge pull request #32481 from ngoldbaum/stringdtype-backport
  • 8972f70 Merge pull request #32478 from charris/backport-32466
  • ab1b589 Merge pull request #32477 from charris/backport-32423
  • Additional commits viewable in compare view

Updates onnx from 1.22.0 to 1.23.0

Release notes

Sourced from onnx's releases.

v1.23.0

ONNX v1.23.0 is now available with exciting new features! We would like to thank everyone who contributed to this release! Please visit onnx.ai to learn more about ONNX and associated projects.

What's Changed

IR Version 14

IR Version is changed from 13->14

Breaking Changes and Deprecations

Spec and Operator

New Operator SwiGLU is added [SwiGLU]

Reference Implementation

Utilities and Tools

... (truncated)

Commits
  • ee3ccbd Version changed to 1.23.0 (#8469)
  • 5f0e948 Version change to rc1 (#8407)
  • 3515c31 Update RELEASE-MANAGEMENT.md (#8406)
  • 0b1ce25 RFC Proposal for Grouped MatMul operator (#8193)
  • f0430f0 fix(shape_inference): prevent Einsum ellipsis-rank segfault (#8273)
  • 7f55643 build(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.8 (#8...
  • 41326c4 build(deps): bump github/codeql-action/init from 4.37.3 to 4.37.8 (#8397)
  • 7e98dfa build(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.8 (#8401)
  • f9b0137 build(deps): bump mypy from 2.3.0 to 2.3.1 (#8395)
  • 765abb0 build(deps): bump actions/stale from 10.4.0 to 11.0.0 (#8398)
  • Additional commits viewable in compare view

Updates huggingface-hub from 1.30.0 to 1.33.0

Release notes

Sourced from huggingface-hub's releases.

[v1.33.0] Better UX on large uploads and simpler skills installs

📤 See progress while large Xet uploads validate

Very large Xet uploads used to sit silently between "Uploading" and "Committing" while shards were being finalized, which could take a long time with no feedback. The upload live display now shows a dedicated Validating bar — reported as a percentage instead of opaque internal validation-entry counts — both in the upload_folder display and in XetUploadProgressReporter (used by upload_file, create_commit and bucket uploads). This requires hf-xet>=1.6.0.

  • [Xet] Show Validating progress during shard finalization by @​seanses in #4478

🧩 Skills are now installed for every agent by default

hf skills add no longer requires a special flag for Claude Code. The skill is now always installed to .agents/skills (or ~/.agents/skills with -g) and symlinked into .claude/skills (honoring CLAUDE_CONFIG_DIR when set), so a single command covers Claude Code, Codex, Cursor, OpenCode, Pi and any other agent that loads skills from .agents/skills. The --claude flag is deprecated: it still works as a no-op but prints a warning, and --dest keeps installing only to the directory you provide. hf skills update refreshes both roots the same way. Along the way, CLAUDE_CONFIG_DIR is now properly honored everywhere (it was previously ignored, which left skills invisible to relocated Claude Code installs).

# works with Claude Code, Codex, Cursor, OpenCode, Pi and any agent that loads skills from `.agents/skills`
hf skills add

📚 Documentation: CLI guide

💔 Breaking Change

  • Send PrivateLink config under privateService in create_inference_endpoint by @​co42 in #4966
    • AWS PrivateLink settings are now sent as privateService.accountId and privateService.region. Use the new private_link_account_id and private_link_region parameters (the region is required when the account ID is set, and is independent of the compute region). The legacy account_id keyword still exists but is ignored and emits a FutureWarning; it is no longer included as a top-level payload field.

🖥️ CLI

  • [CLI] Honor --format / --json / -q on jobs run commands by @​Wauplin in #4936 — docs
    • These flags previously leaked into the container command on hf jobs run, hf jobs uv run and their scheduled variants (--format became the script path, -q became the image name). They are now consumed wherever they appear; use -- when your script needs them.
  • [CLI] Allow bucket as a watched item type in hf webhooks create --watch by @​davanstrien in #4958 — docs

📖 Documentation

🐛 Bug and typo fixes

... (truncated)

Commits
  • 9eeace5 Release: v1.33.0
  • 4805a13 Release: v1.33.0.rc1
  • 1a4db76 Release: v1.33.0.rc0
  • ac3ed2f [Xet] Show Validating progress during shard finalization (#4478)
  • b904b94 Apply the repo_id length limit to the namespace as well (#4988)
  • 1e0c305 Send PrivateLink config under privateService in create_inference_endpoint (#4...
  • da5e244 Scope GITHUB_TOKEN permissions per job (#4982)
  • 7532272 Fix HfFileSystem.get_file with a bare local filename (#4981)
  • 0f88f32 [Download] Extend tmp .incomplete path on Windows when too long (#4978)
  • ce69fdb [Buckets] Raise when a batch reports failed operations (#4954)
  • Additional commits viewable in compare view

Updates onnxruntime from 1.29.0 to 1.30.0

Release notes

Sourced from onnxruntime's releases.

ONNX Runtime v1.30.0

ONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.

Highlights

  • Expanded CUDA inference support with variable-length causal convolution for continuous batching, speculative decoding in paged XQA, and INT4 paged KV caches with per-channel scales (#32168, #32340, #32515).
  • Improved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache block quantization, and extended convolution optimizations (#31727, #32277, #32284, #32420).
  • Added fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, plus AVX2 LayerNorm/RMSNorm acceleration (#31674, #31973, #32178, #32356).
  • Added Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib operators (#29615, #32268).

Announcements & Compatibility

  • FP4 QMoE kernels are now enabled by default in CUDA builds, with Windows build support added in this release. Source builds can opt out with -Donnxruntime_USE_FP4_QMOE=OFF (#32096, #32163).
  • CUDA fpA-intB builds now default to a compact kernel set for FP16 activations, INT4/INT8 weights, scale-only quantization, and block_size=32. Set -Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON when building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (#32324).
  • CPU FP16 Gemm and MatMul execution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (#32301, #32197).
  • WebGPU plugin EP packaging now supports Linux AArch64. Plugin versions were advanced to WebGPU 0.4.0 and CUDA 0.2 (#32287, #31960, #31970).

Security & Reliability

Model Loading, Memory, and Input Validation

  • Limited nested model-graph depth and canonicalized external-data locations to harden model loading (#32344, #32135).
  • Added checked rounding for BFC arena allocations and fixed prepacked-weight reference lifetimes (#32010, #32040).
  • Strengthened shape, rank, and parameter validation for Split, Scan, GatherND, ScatterND, SpaceToDepth/DepthToSpace, Crop, Conv, Normalizer, and pooling (#29461, #31668, #32034, #32039, #32076, #32157, #32160, #32161, #32345, #32349).
  • Hardened generation and attention input handling, including attention-attribute narrowing, BifurcationDetector inputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (#31648, #31701, #32009, #32078, #32144).
  • Validated TreeEnsemble node references and bounded subtree comparison, rejected non-finite CPU RoiAlign coordinates, and required ImageScaler bias to match the channel count (#32031, #32043, #32011, #32002).
  • Added an allowlist of safe LoRA adapter parameter data types, validated MatMulFpQ4 shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (#31682, #32032, #32007).

GPU Bounds and Resource Lifetimes

  • Hardened CUDA indexing and buffer-size arithmetic in MatMulNBits, RemovePadding, RotaryEmbedding, SparseAttention, Whisper beam search, NMS, QDQ, and GatherElements (#31643, #31994, #31995, #31996, #31998, #32014, #32029, #32030).
  • Fixed overflow in CUDA reduction scans and Softmax offset arithmetic, and handled zero-sized outputs in CUDA random-generator kernels (#32137, #32330, #31997).
  • Fixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept CudaAsyncBuffer staging storage alive across CUDA graph replay (#31968, #32121).
  • Fixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, zero-initialized writable device-allocator buffers, and rejected foreign GPU handles in built-in data transfers (#32364, #32063, #32317).

Dependencies and Tooling

  • Upgraded Protobuf to 33.6 and refreshed Python documentation dependencies, including an ONNX security-related update (#29906, #32190, #32424).
  • Updated JavaScript dependencies including js-yaml, joi, fast-uri, and the Next.js end-to-end fixture (#32397, #32486, #32488, #32505, #32508).
  • Pinned GitHub Actions to full-length commit SHAs and strengthened packaging infrastructure with authenticated package feeds and NPM network isolation (#32176, #32005, #32440).

New Features

Core APIs & Runtime

  • Added Go bindings for the ONNX Runtime C API (#29615).
  • Extended memory importing with host-pointer support and added access to preallocated outputs through KernelContext::GetPreallocatedOutput (#29726, #32089).
  • Added packed-attention workspace recipes and estimates, and made workspace input-shape handling aware of optional inputs (#32283, #32321, #32312).
  • Added DeepSeek Engram contrib operators, EngramGate and NGramHashMapping, and expanded kernel coverage for Qwen-3.5 operators (#32268, #32106).

... (truncated)

Commits
  • f2c39fe [CUDA] Add INT4 paged KV cache with per-channel scales (#32515)
  • 5894ba8 Add portable random-access file reads to Env (#32503)
  • a2ee3eb Fix CUDA plugin device discovery on WSL (#32517)
  • b652e59 [WebGPU] Prepack Conv weights for the im2col-matmul path (#32420)
  • 0f0f29f Get rid of spurious warning about not being able to find spectre mitigation (...
  • 23dd651 Register ONNX schemas only when static registration is disabled (#32353)
  • 33af5d3 Release external data loaders after graph initialization (#32502)
  • 2e3c24d Clarify external initializer and EP context path interaction (#32442)
  • e76036b [CUDA] Pin FP8 GEMV residency for grids just past two blocks per SM (#32433)
  • 82583c5 Add session option for a BNHS GroupQueryAttention Value cache layout (#32139)
  • Additional commits viewable in compare view

Updates ruff from 0.16.6 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates pyright from 1.1.411 to 1.1.414

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ates

Bumps the python-deps group with 6 updates in the /cortex-tts directory:

| Package | From | To |
| --- | --- | --- |
| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |
| [onnx](https://github.com/onnx/onnx) | `1.22.0` | `1.23.0` |
| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.30.0` | `1.33.0` |
| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.29.0` | `1.30.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.9` |
| [pyright](https://github.com/RobertCraigie/pyright-python) | `1.1.411` | `1.1.414` |



Updates `numpy` from 2.5.2 to 2.5.3
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](numpy/numpy@v2.5.2...v2.5.3)

Updates `onnx` from 1.22.0 to 1.23.0
- [Release notes](https://github.com/onnx/onnx/releases)
- [Changelog](https://github.com/onnx/onnx/blob/main/docs/Changelog-ml.md)
- [Commits](onnx/onnx@v1.22.0...v1.23.0)

Updates `huggingface-hub` from 1.30.0 to 1.33.0
- [Release notes](https://github.com/huggingface/huggingface_hub/releases)
- [Commits](huggingface/huggingface_hub@v1.30.0...v1.33.0)

Updates `onnxruntime` from 1.29.0 to 1.30.0
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](microsoft/onnxruntime@v1.29.0...v1.30.0)

Updates `ruff` from 0.16.6 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.9)

Updates `pyright` from 1.1.411 to 1.1.414
- [Release notes](https://github.com/RobertCraigie/pyright-python/releases)
- [Commits](RobertCraigie/pyright-python@v1.1.411...v1.1.414)

---
updated-dependencies:
- dependency-name: numpy
  dependency-version: 2.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: onnx
  dependency-version: 1.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: huggingface-hub
  dependency-version: 1.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: onnxruntime
  dependency-version: 1.30.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: pyright
  dependency-version: 1.1.414
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from parkghost as a code owner October 3, 2026 06:44
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@parkghost
parkghost merged commit d21cc92 into main Oct 3, 2026
11 of 12 checks passed
@parkghost
parkghost deleted the dependabot/uv/cortex-tts/python-deps-2406a20dad branch October 3, 2026 06:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant