Skip to content

Bump the ml-runtime group across 1 directory with 6 updates - #4

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/ml-runtime-12a8151b44
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/ml-runtime-12a8151b44

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 25, 2026 •

Copy link
Copy Markdown

Bumps the ml-runtime group with 6 updates in the / directory:

Package From To
torch 2.3.1+cpu 2.13.0+cpu
torchaudio 2.3.1+cpu 2.11.0+cpu
nemo-toolkit 2.4.0 2.7.3
transformers 4.56.0 5.14.1
datasets 4.0.0 5.0.1
nltk 3.9.1 3.10.0

Updates torch from 2.3.1+cpu to 2.13.0+cpu

Updates torchaudio from 2.3.1+cpu to 2.11.0+cpu

Updates nemo-toolkit from 2.4.0 to 2.7.3

Release notes

Sourced from nemo-toolkit's releases.

NVIDIA Neural Modules 2.7.3

Highlights

Uncategorized:

NVIDIA Neural Modules 2.7.2

ASR

Uncategorized:

NVIDIA Neural Modules 2.7.1

ASR

  • cp: Fix cuda-python usage for CUDA graphs ([#15416](https://github.com/nvidia/nemo/issues/15416)) by @​ko3n1g :: PR: #15471

Uncategorized:

... (truncated)

Commits

Updates transformers from 4.56.0 to 5.14.1

Release notes

Sourced from transformers's releases.

Patch release: v5.14.1

Patch release v5.14.1

This patch solves a few issues which appeared when integrating Inkling model, most notably an issue affecting models using EncoderDecoderCache during assisted generation. It also fixes an issue that could appear during prefill with StaticCache and sdpa without padding for Inkling which uses a position_bias. It contains the following commits:

Release v5.14.0

New Model additions

Inkling (fresh from Thinking Machines): 975B total, 41B active

Inkling is a general-purpose multimodal model that accepts text, image and audio inputs and generates text outputs. It is intended for use in English and other languages, and across multiple coding languages. The model is designed to be used by developers building AI- powered applications, including agentic and tool-use systems, coding assistants, chatbots, and retrieval-augmented generation systems, and is suitable for general-purpose conversational use, instruction-following, and other natural language and multimodal tasks. It is released with open weights to support research, fine-tuning and integration into third-party products by downstream developers.

TIPSv2

Links: Documentation

TIPSv2 DPT

Links: Documentation

🚨 Breaking changes

... (truncated)

Commits

Updates datasets from 4.0.0 to 5.0.1

Release notes

Sourced from datasets's releases.

5.0.1

Bug fixes

Docs

New Contributors

... (truncated)

Commits
  • 921c2a7 release: 5.0.1 (#8370)
  • c6fc5cd Preserve nullable integer columns in to_json/to_csv/to_sql (#8366)
  • 6747b87 Fix DatasetDict.push_to_hub leaving removed splits in the dataset card (#8367)
  • b305031 fix buckets on windows (#8369)
  • 030a3e5 Decode Json() columns in Dataset.to_pandas() (#8344)
  • 0f207a0 Rebatch arrow source before formatting in IterableDataset.filter to fix resum...
  • adad35d Keep integers on the python read path for fixed-shape ArrayXD columns with nu...
  • 8966746 Fix CSV loader dropping on_bad_lines/encoding_errors on pandas 2.0-2.2 (#8358)
  • b8e861a Fix bucket dataset card handling and push metadata accounting (#8354)
  • 521a590 Keep flat numeric columns with nulls numeric in numpy format (#8352)
  • Additional commits viewable in compare view

Updates nltk from 3.9.1 to 3.10.0

Release notes

Sourced from nltk's releases.

v3.10.0-rc1

What's Changed

... (truncated)

Changelog

Sourced from nltk's changelog.

Version 3.10.1 2026-07-29

  • Expand ~ in env-var paths
  • Validate types after WordNet app pickle deserialization
  • Fix uncontrolled search path in HunposTagger
  • Use exact thirds in masi_distance
  • Avoid retaining bllip import exceptions
  • Fix word_tokenize: pad opening single quote before multi-letter words.
  • Implement Tree.pformat_latex_forest.
  • Prevent module hijacking in inline imports.
  • Fix ReDoS in TweetTokenizer URL and email regexes.

Thanks to the following contributors to 3.10.1: Abhinav, Litesh Ghute, Eric Kafe, Eryk Kaźmierczak, Selim C., Muhtasim Munif Fahim, Triniti K., and Tom Y. Mitich.

Version 3.10.0 2026-06-11

  • Enforce the stricter nltk.pathsec security policy by default
  • Document the new security model and migration guidance
  • Harden resource loading against path traversal and SSRF/DNS-rebinding
  • Harden downloader path handling and block XML entity expansion
  • Close remaining corpus-reader security edge cases
  • Replace unsafe exec() usage in the utility CLI
  • Warn on unpickling user-provided pickles
  • Add HuggingFace datasets integration (nltk.huggingface)
  • Align TnT with Brants (2000) specifications
  • Fix PorterStemmer irregular-form lowercasing in NLTK mode
  • Fix TransitionParser sparse index dtype for scikit-learn 1.9
  • Fix TextCat tie handling
  • Fix WordNet object comparisons for incompatible types
  • Cache WordNet max depth lazily for lch_similarity()
  • Fix CCG variable direction, substitution, and type-raising bugs
  • Fix Jaro similarity for single-character and empty-string cases
  • Improve CI and release-maintenance workflows

Thanks to the following contributors to 3.10.0: 13rac1, alvations, bowiechen, devesh-2002, ekaf, elias-ba, haosenwang1018, HyperPS, ihitamandal, jancallewaert, jhnwnstd, JuanIMartinezB, Lemm1, LinZiyuu, Mr-Neutr0n, PastelStorm, scruge1, Syzygy2048, ylwango613, yzhaoinuw

Version 3.9.4 2026-03-24

  • Support Python 3.14
  • Fix bug in Levenshtein distance when substitution_cost > 2
  • Fix bug in Treebank detokeniser re quote ordering
  • Fix bug in Jaro similarity for empty strings
  • Several security enhancements
  • Fix GHSA-rf74-v2fm-23pw: unbounded recursion in JSONTaggedDecoder

... (truncated)

Commits
  • bd49f90 allow escaped brackets in Tree.fromstring (#3694)
  • 27b8ad6 don't crash chomsky_normal_form on terminals with siblings (#3693)
  • 52227d2 Use os.name for Windows path handling (#3605)
  • 06c0e2c Avoid RIBES zero division on empty inputs (#3604)
  • a167389 Treat missing unzip output as stale (#3607)
  • c94c967 Fix EOF empty document bug in IEER corpus reader (#3648)
  • 94a259c Enforce restrictive primitive type checking in pathsec wrappers (#3692)
  • 5ac475d fix(security): isolate Stanford Java options and clean temp files (#3683)
  • 986f26e ci(deps): bump the github-actions group with 3 updates (#3691)
  • f26b375 fix(security): prevent pickle RCE in TransitionParser model loading (CWE-502)...
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github May 25, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot changed the title Bump the ml-runtime group with 6 updates Bump the ml-runtime group across 1 directory with 6 updates Jun 22, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/ml-runtime-12a8151b44 branch 2 times, most recently from d69c609 to 32354e1 Compare June 29, 2026 04:23
Bumps the ml-runtime group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| torch | `2.3.1+cpu` | `2.13.0+cpu` |
| torchaudio | `2.3.1+cpu` | `2.11.0+cpu` |
| [nemo-toolkit](https://github.com/nvidia/nemo) | `2.4.0` | `2.7.3` |
| [transformers](https://github.com/huggingface/transformers) | `4.56.0` | `5.14.1` |
| [datasets](https://github.com/huggingface/datasets) | `4.0.0` | `5.0.1` |
| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.0` |



Updates `torch` from 2.3.1+cpu to 2.13.0+cpu

Updates `torchaudio` from 2.3.1+cpu to 2.11.0+cpu

Updates `nemo-toolkit` from 2.4.0 to 2.7.3
- [Release notes](https://github.com/nvidia/nemo/releases)
- [Commits](NVIDIA-NeMo/Speech@v2.4.0...v2.7.3)

Updates `transformers` from 4.56.0 to 5.14.1
- [Release notes](https://github.com/huggingface/transformers/releases)
- [Commits](huggingface/transformers@v4.56.0...v5.14.1)

Updates `datasets` from 4.0.0 to 5.0.1
- [Release notes](https://github.com/huggingface/datasets/releases)
- [Commits](huggingface/datasets@4.0.0...5.0.1)

Updates `nltk` from 3.9.1 to 3.10.0
- [Release notes](https://github.com/nltk/nltk/releases)
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](nltk/nltk@3.9.1...v3.10.0)

---
updated-dependencies:
- dependency-name: datasets
  dependency-version: 4.8.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ml-runtime
- dependency-name: nemo-toolkit
  dependency-version: 2.7.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ml-runtime
- dependency-name: nltk
  dependency-version: 3.9.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ml-runtime
- dependency-name: torch
  dependency-version: 2.12.0+cpu
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ml-runtime
- dependency-name: torchaudio
  dependency-version: 2.11.0+cpu
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ml-runtime
- dependency-name: transformers
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ml-runtime
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/ml-runtime-12a8151b44 branch from 32354e1 to a950615 Compare August 3, 2026 04:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants