Skip to content

chore(deps): bump the all-dependencies group in /autobot-infrastructure/shared/docker/ai-stack with 4 updates - #18176

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/autobot-infrastructure/shared/docker/ai-stack/main/all-dependencies-1c55616c57
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/autobot-infrastructure/shared/docker/ai-stack/main/all-dependencies-1c55616c57

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on langchain-core, transformers, huggingface-hub and aiohttp to permit the latest version.
Updates langchain-core to 1.6.7

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.7

Changes since langchain-core==1.6.6

release(core): 1.6.7 (#41087) fix(core): include openai redacted_content in v1 output for bedrock converse (#41086) fix(core): python 3.14 hardening around inspect.signature (#41059) chore(deps): bump notebook from 7.5.7 to 7.6.3 in /libs/core (#41057) chore(deps): bump notebook from 7.5.6 to 7.5.7 in /libs/core (#40992) chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/core (#40972) chore(deps): bump tornado from 6.5.8 to 6.5.9 in /libs/core (#40970)

Commits
  • f40f58d release(core): 1.6.7 (#41087)
  • 2c2cf93 fix(core): include openai redacted_content in v1 output for bedrock converse ...
  • 0c24e89 chore(model-profiles): refresh model profile data (#41084)
  • dc3a689 fix(core): python 3.14 hardening around inspect.signature (#41059)
  • 67ba389 chore(deps): bump notebook from 7.5.7 to 7.6.3 in /libs/core (#41057)
  • f8aaa99 chore(deps): bump notebook from 7.5.7 to 7.6.3 in /libs/langchain (#41056)
  • b564ebc chore(deps): bump notebook from 7.5.7 to 7.6.3 in /libs/text-splitters (#41055)
  • 7ca02f3 release(huggingface): 1.2.3 (#41058)
  • 7974332 chore(langchain): bump minimum FastMCP to 4.0.11 (#41054)
  • 6564f7e fix(huggingface): hide huggingfacehub_api_token from repr (#41047)
  • Additional commits viewable in compare view

Updates transformers to 5.19.0

Release notes

Sourced from transformers's releases.

Release v5.19.0

New Model additions

EmbeddingGemma2

EmbeddingGemma 2 is a multimodal embedding model from Google built on the Gemma 4 architecture. It encodes text, images, audio, and video, individually or combined in one input, into a shared 768-dimensional vector space for cross-modal retrieval, semantic similarity, clustering, and classification. It uses Matryoshka Representation Learning, so embeddings can be truncated to 512, 256, or 128 dimensions. It also offers configurable visual and video token budgets, and unused vision or audio towers can be disabled at load time to save memory.

Links: Documentation

Breaking changes

All MoE models whose routers compute logits now return them when output_router_logits=True, following the Qwen3-MoE pattern (a router_logits recorder on the base model, MoeModelOutputWithPast from the backbone, and a MoE causal LM output from the head), so code that relied on the previous outputs or their absence should read the router logits from these output classes.

Owlv2ForObjectDetection.embed_image_query now selects the query box with the highest objectness score, as in the original OWLv2 notebook, instead of the OWL-ViT heuristic, so image-guided query embeddings and detections may differ from earlier releases.

The "paged|" prefix for SDPA and flash attention implementations is deprecated, so users should set the regular attention implementation (e.g. sdpa or flash_attention_2) for continuous batching instead of paged|sdpa or paged|flash_attention_2.

  • 🚨 Attention 🚨 Deprecate "paged|" prefix for SDPA and flash (#49112) by @​remi-or

The regular flash and SDPA attention functions (flash_attention.py, sdpa_attention.py) now support continuous batching directly, and "paged|..." implementations for these are redirected to them, while eager still requires the "paged|eager" prefix.

In continuous batching, the cache update for the index-based and block-table paths is now fused into a single call, which slightly changes the cache update function's behavior and affects any custom code that calls the separate update paths.

Continuous batching internals changed in preparation for removing "paged": `max

Parallelization

Expert parallelism gains a token-dispatch implementation, selected via the new ep_dispatch_experts plan rule and now the default for Qwen3 MoE and Mellum, which removes the requirement that EP size equal TP size. The Trainer was also adapted to work with expert parallelism, and the docs now note that PEFT adapters support tensor parallelism. A CI-related fix for pipeline-parallel chart2table inference was also included.

Cache

... (truncated)

Commits

Updates huggingface-hub to 1.33.0

Release notes

Sourced from huggingface-hub's releases.

[v1.33.0] Better UX on large uploads and simpler skills installs

📤 See progress while large Xet uploads validate

Very large Xet uploads used to sit silently between "Uploading" and "Committing" while shards were being finalized, which could take a long time with no feedback. The upload live display now shows a dedicated Validating bar — reported as a percentage instead of opaque internal validation-entry counts — both in the upload_folder display and in XetUploadProgressReporter (used by upload_file, create_commit and bucket uploads). This requires hf-xet>=1.6.0.

  • [Xet] Show Validating progress during shard finalization by @​seanses in #4478

🧩 Skills are now installed for every agent by default

hf skills add no longer requires a special flag for Claude Code. The skill is now always installed to .agents/skills (or ~/.agents/skills with -g) and symlinked into .claude/skills (honoring CLAUDE_CONFIG_DIR when set), so a single command covers Claude Code, Codex, Cursor, OpenCode, Pi and any other agent that loads skills from .agents/skills. The --claude flag is deprecated: it still works as a no-op but prints a warning, and --dest keeps installing only to the directory you provide. hf skills update refreshes both roots the same way. Along the way, CLAUDE_CONFIG_DIR is now properly honored everywhere (it was previously ignored, which left skills invisible to relocated Claude Code installs).

# works with Claude Code, Codex, Cursor, OpenCode, Pi and any agent that loads skills from `.agents/skills`
hf skills add

📚 Documentation: CLI guide

💔 Breaking Change

  • Send PrivateLink config under privateService in create_inference_endpoint by @​co42 in #4966
    • AWS PrivateLink settings are now sent as privateService.accountId and privateService.region. Use the new private_link_account_id and private_link_region parameters (the region is required when the account ID is set, and is independent of the compute region). The legacy account_id keyword still exists but is ignored and emits a FutureWarning; it is no longer included as a top-level payload field.

🖥️ CLI

  • [CLI] Honor --format / --json / -q on jobs run commands by @​Wauplin in #4936 — docs
    • These flags previously leaked into the container command on hf jobs run, hf jobs uv run and their scheduled variants (--format became the script path, -q became the image name). They are now consumed wherever they appear; use -- when your script needs them.
  • [CLI] Allow bucket as a watched item type in hf webhooks create --watch by @​davanstrien in #4958 — docs

📖 Documentation

🐛 Bug and typo fixes

... (truncated)

Commits
  • 9eeace5 Release: v1.33.0
  • 4805a13 Release: v1.33.0.rc1
  • 1a4db76 Release: v1.33.0.rc0
  • ac3ed2f [Xet] Show Validating progress during shard finalization (#4478)
  • b904b94 Apply the repo_id length limit to the namespace as well (#4988)
  • 1e0c305 Send PrivateLink config under privateService in create_inference_endpoint (#4...
  • da5e244 Scope GITHUB_TOKEN permissions per job (#4982)
  • 7532272 Fix HfFileSystem.get_file with a bare local filename (#4981)
  • 0f88f32 [Download] Extend tmp .incomplete path on Windows when too long (#4978)
  • ce69fdb [Buckets] Raise when a batch reports failed operations (#4954)
  • Additional commits viewable in compare view

Updates aiohttp to 3.14.4

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

---
updated-dependencies:
- dependency-name: langchain-core
  dependency-version: 1.6.7
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: transformers
  dependency-version: 5.19.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: huggingface-hub
  dependency-version: 1.33.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: aiohttp
  dependency-version: 3.14.4
  dependency-type: direct:production
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from mrveiss as a code owner October 10, 2026 08:05
@dependabot dependabot Bot added backend dependencies Pull requests that update a dependency file labels Oct 10, 2026
@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: mrveiss/AutoBot-AI/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: ba3693a0-2ce2-40d7-ae10-1ac8ca9a2f59

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants