Skip to content

build: bump the python-minor group with 2 updates - #160

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-minor-b530e3c812
Open

build: bump the python-minor group with 2 updates#160
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-minor-b530e3c812

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-minor group with 2 updates: openadapt-types and onnxruntime.

Updates openadapt-types from 0.10.0 to 0.17.0

Release notes

Sourced from openadapt-types's releases.

v0.17.0 (2026-09-01)

Features

  • types: Add calibration scope and issuer to the reward certificate (#38, cbadccf)

A self-signed reward certificate may carry only synthetic scope. certified requires oracle tier 2 or 3, a current certificate, a calibration corpus digest, and a stated calibration scope. The only computable scope today is synthetic.

Merged by an agent session, not the founder.


Detailed Changes: v0.16.0...v0.17.0

v0.16.0 (2026-09-01)

Features

  • types: Add reward contract, certificate, and evidence receipt (#37, ef42cd7)

RewardContractV1, RewardCertificateV1, and RewardEvidenceReceiptV1 for training against a verified terminal effect with a certified false-accept bound. RECONCILIATION_REQUIRED and FAILED_PLATFORM are unscored and never 0.0. certified requires oracle tier 2 or 3 plus a current certificate. The reward receipt is not an Execute Seal.

Merged by an agent session, not the founder.


Detailed Changes: v0.15.0...v0.16.0

v0.15.0 (2026-09-01)

Features

  • types: Add clinic inbox, outbox, and MCP result contracts (#36, 7af28a7)

Public JSON for the workbench-to-OpenAdapt job handoff. Identity is patient_token only. HALTED and RECONCILIATION_REQUIRED do not map to success. needs_human true refuses actuation.


Detailed Changes: v0.14.0...v0.15.0

v0.14.0 (2026-09-01)

Features

  • types: Authoring observe, command, and bind schemas (#35, 9a4e46f)

Merged by an agent session, not the founder.


... (truncated)

Changelog

Sourced from openadapt-types's changelog.

v0.17.0 (2026-09-01)

Features

  • types: Add calibration scope and issuer to the reward certificate (#38, cbadccf)

A self-signed reward certificate may carry only synthetic scope. certified requires oracle tier 2 or 3, a current certificate, a calibration corpus digest, and a stated calibration scope. The only computable scope today is synthetic.

Merged by an agent session, not the founder.

v0.16.0 (2026-09-01)

Features

  • types: Add reward contract, certificate, and evidence receipt (#37, ef42cd7)

RewardContractV1, RewardCertificateV1, and RewardEvidenceReceiptV1 for training against a verified terminal effect with a certified false-accept bound. RECONCILIATION_REQUIRED and FAILED_PLATFORM are unscored and never 0.0. certified requires oracle tier 2 or 3 plus a current certificate. The reward receipt is not an Execute Seal.

Merged by an agent session, not the founder.

v0.15.0 (2026-09-01)

Features

  • types: Add clinic inbox, outbox, and MCP result contracts (#36, 7af28a7)

Public JSON for the workbench-to-OpenAdapt job handoff. Identity is patient_token only. HALTED and RECONCILIATION_REQUIRED do not map to success. needs_human true refuses actuation.

v0.14.0 (2026-09-01)

Features

  • types: Authoring observe, command, and bind schemas (#35, 9a4e46f)

... (truncated)

Commits
  • 14eca2d chore: release 0.17.0
  • cbadccf feat(types): add calibration scope and issuer to the reward certificate (#38)
  • 4361eaf chore: release 0.16.0
  • ef42cd7 feat(types): add reward contract, certificate, and evidence receipt (#37)
  • 50f72c7 chore: release 0.15.0
  • 7af28a7 feat(types): add clinic inbox, outbox, and MCP result contracts (#36)
  • f653dd9 chore: release 0.14.0
  • 9a4e46f feat(types): authoring observe, command, and bind schemas (#35)
  • a8db373 chore: release 0.13.0
  • 07e89a4 feat: add portable process capability contracts (#34)
  • Additional commits viewable in compare view

Updates onnxruntime from 1.20.1 to 1.29.0

Release notes

Sourced from onnxruntime's releases.

ONNX Runtime v1.29.0

Announcements & Breaking Changes

  • onnxruntime-web has announced the deprecation of WebGL and JSEP. The native WebGPU EP is the recommended path going forward. See the deprecation and migration plans for details (#29716, #31683).
  • POSIX telemetry is now available on Linux, macOS, Android, and iOS when ONNX Runtime is built with telemetry enabled. It does not change the public ABI, WebAssembly remains telemetry-free, and setting ORT_DISABLE_TELEMETRY=1 before initialization disables non-Windows telemetry for the process (#27379, #29872).
  • The unused internal onnxruntime/python/tools/tensorrt dashboard tooling was removed. This does not affect the TensorRT Execution Provider APIs (#29395).

Security Fixes

Path, bounds, and input validation

  • Fixed a path traversal vulnerability in TensorRT and NvTensorRTRTX engine refitting by making external-data path validation unconditional (#29396).
  • Validated the CPU MoE k attribute against the number of experts and fixed a CPU TensorScatter security issue (#29907, #29916).
  • Added missing rank, shape, and parameter validation for pooling, LSTM and DynamicQuantizeLSTM, Sampling, FeatureVectorizer, SkipLayerNorm, QLinearConv, Whisper decoding, RNN activations, GridSample, contrib Range, and CropAndResize (#29254, #29255, #29265, #29579, #29595, #29605, #29871, #31636, #31671, #31675, #31676, #31684).
  • Hardened CUDA indexing and buffer handling in GridSample, transpose, GatherBlockQuantized, InstanceNormalization, LayerNorm/RMSNorm, BeamSearch, DeformConv, AveragePool, and MaxPool (#29581, #29631, #29638, #31640, #31642, #31644, #31645, #31647, #31650).
  • Fixed packed sub-byte tensor over-copying in OrtApi::GetValue and validated DML constant tensor byte sizes (#29157, #31665).

Supply chain and tooling

  • Updated npm lockfiles, refreshed the Next.js end-to-end fixture lockfile for security advisories, and upgraded adm-zip for onnxruntime-node (#29827, #29926, #31192).

New Features

Core APIs & Runtime

  • Default intra-op and inter-op thread-pool sizes can now be set with ORT_INTRA_OP_NUM_THREADS and ORT_INTER_OP_NUM_THREADS. Explicit thread settings still take precedence, and 0 preserves machine-sized defaults (#29688).
  • Added weightless-model support for all initializer types, allowed zero-input EpContext nodes, and wired maximum-shape inference into workspace estimation (#29607, #29799, #31613).
  • Added ONNX-domain support for rotary embedding and a fused MRotaryEmbedding contrib operator for Qwen mRoPE variants (#29261, #31728).
  • Added multi-shape profiling to onnxruntime_perf_test through --data_shape, plus verbose graph-transformer tracing and broader inference-session error-path coverage (#29555, #29558, #29569, #29571).

Execution Provider ABI & Plugin EPs

  • WebGPU now supports device-free compile-only sessions for offline graph transformation (#29681).
  • Expanded CUDA plugin EP packaging and testing, including Windows ARM64 package and size options, updated package outputs, and aligned architecture selections across Python, C API, TensorRT, Node.js, and plugin packages (#31635, #31722, #31992).
  • Improved plugin lifecycle handling by unloading failed EP library loads and fixing allocator-deleter lifetime (#29634, #29770).

Execution Provider Updates

NVIDIA CUDA EP

Attention and decoding

  • Added PagedAttention with quantized KV cache, XQA decode, MLA, QK-Norm, and head-sink support (#29912).
  • Extended quantized KV-cache support with attention sinks, independent and per-channel scales, sliding-window cache support, and a fused K/V dequantization launch (#29900, #29904, #31480).
  • Added a cuDNN SDPA decode tier to the standard ONNX Attention CUDA kernel and enabled cuDNN SDPA for contrib Attention (#29715, #29717).
  • Added attention_bias support to the GroupQueryAttention unfused path and state_window support to LinearAttention and CausalConvWithState for MTP (#29525, #31157).
  • Fixed LinearAttention on GPUs with limited shared memory (#31982).

MoE and quantized GEMM

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-minor group with 2 updates: [openadapt-types](https://github.com/OpenAdaptAI/openadapt-types) and [onnxruntime](https://github.com/microsoft/onnxruntime).


Updates `openadapt-types` from 0.10.0 to 0.17.0
- [Release notes](https://github.com/OpenAdaptAI/openadapt-types/releases)
- [Changelog](https://github.com/OpenAdaptAI/openadapt-types/blob/main/CHANGELOG.md)
- [Commits](OpenAdaptAI/openadapt-types@v0.10.0...v0.17.0)

Updates `onnxruntime` from 1.20.1 to 1.29.0
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](microsoft/onnxruntime@v1.20.1...v1.29.0)

---
updated-dependencies:
- dependency-name: openadapt-types
  dependency-version: 0.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor
- dependency-name: onnxruntime
  dependency-version: 1.29.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants