Skip to content

Bump transformers from 4.35.2 to 5.17.0 in /ai_agents - #11

Closed
dependabot[bot] wants to merge 283 commits into
productionfrom
dependabot/pip/ai_agents/transformers-5.17.0
Closed

dependabot[bot] wants to merge 283 commits into
productionfrom
dependabot/pip/ai_agents/transformers-5.17.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown

Bumps transformers from 4.35.2 to 5.17.0.

Release notes

Sourced from transformers's releases.

Release 5.17.0

Release v5.17.0

New Model additions

HYV4

Hy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per token. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every token to 8 of them. The context window is 1M tokens.

The architecture combines four features:

  • Multi-head Latent Attention (MLA) compresses keys and values into a low-rank latent (kv_lora_rank) that kv_b_proj expands back to one key/value per query head.
  • DeepSeek Sparse Attention (DSA) selects index_topk keys per query with a lightweight indexer. Following IndexShare, only the layers marked "full" in indexer_types run an indexer; "shared" layers reuse the previous full layer's selection.
  • Gated MLA with learnable attention sinks, where each head owns a sink logit that participates in the softmax and contributes no value, as in GPT-OSS.
  • Independent Hyper-Connections (iHC) replace the plain residual path with hc_mult parallel residual streams that are collapsed before, and redistributed after, every sublayer.

The implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints keep those weights so that other runtimes can use them for speculative decoding; they are ignored at load time.

Links: Documentation

VibeVoice

VibeVoice is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational "vibe" and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.

Links: Documentation

NeoMME

NeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.

NeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).

Links: Documentation

... (truncated)

Commits
  • 856157a v5.17.0
  • 5b7dcb0 MRoPE continued (#48594)
  • 50bbcc6 [fix] Update stale expected strings in HunYuanVL integration tests (#48646)
  • e8bcd79 [Quantizaiton]support 5/6/7 bits in AutoRound (#48481)
  • 3283d5f [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...
  • 5f47b5a [tests] Fix integration test golden values broken by fast image processor def...
  • fc50134 Add Fun-ASR-Nano model (#46180)
  • d9fe823 Fix YOLOS device mismatch with device_map="auto" (#46886)
  • cbc1651 [Generate] Avoid unconditionally downloading remote hub file (#48620)
  • bd05a4b Honor shift_labels in decoder-only LLM/VLM losses (#48493)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Completed service layer architecture
Still need to do direct messaging functionality
kylezwang and others added 22 commits February 16, 2026 15:33
Analyzed Certio codebase to extract Geoffrey-style quantifiable achievements:

Documents created:
- CERTIO_PERFORMANCE_METRICS_FOR_RESUME.md: Complete metrics (159K LOC, 74 tests, 62+ entities)
- RESUME_BULLET_COMPARISON.md: Current vs improved bullet comparisons
- KYLE_RESUME_UPDATED_DRAFT.md: Full updated resume ready to use
- PERFORMANCE_TESTING_GUIDE.md: Guide for running tests to generate more metrics
- PROJECT_SUMMARY.md: Executive summary with action items

Key achievements identified:
- Performance: sub-50ms permission resolution (50-75% improvement) via dual-layer caching
- AI optimization: 60% cost reduction achieving $11K+ annual savings at scale
- Testing: 74 unit tests covering 3,025 LOC with 25 security-specific tests
- Architecture: 62+ entities, 42 migrations, 4 SignalR hubs across 159K LOC
- Security: 6-layer authorization with 23 granular permissions preventing IDOR

All metrics are real, measurable, and defensible in interviews.

Co-authored-by: kylezwang <kylezwang@users.noreply.github.com>
Added START_HERE.md: User-friendly quick start guide with:
- 30-minute action plan to update resume
- Key bullets ready to copy-paste
- Interview preparation for top 3 questions
- Direct links to all documents
- Key numbers to memorize
- Before/after comparison examples

This is the entry point for using all the resume optimization documents.

Co-authored-by: kylezwang <kylezwang@users.noreply.github.com>
Stop tracking build output and local caches, and replace the old notes with a short guide plus a pass that removes emoji and em dashes from the tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
The check was failing before the host could build a DbContext, so the script never ran.

Co-authored-by: Cursor <cursoragent@cursor.com>
Prepare the repository for a public read-through
Bumps [transformers](https://github.com/huggingface/transformers) from 4.35.2 to 5.17.0.
- [Release notes](https://github.com/huggingface/transformers/releases)
- [Commits](huggingface/transformers@v4.35.2...v5.17.0)

---
updated-dependencies:
- dependency-name: transformers
  dependency-version: 5.17.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 29, 2026
@kylezwang kylezwang closed this Sep 29, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/ai_agents/transformers-5.17.0 branch September 29, 2026 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants