Skip to content

build(deps): Update transformers requirement from >=4.40 to >=5.16.0 in /requirements - #8

Closed
dependabot[bot] wants to merge 20 commits into
mainfrom
dependabot/pip/requirements/transformers-gte-5.16.0
Closed

build(deps): Update transformers requirement from >=4.40 to >=5.16.0 in /requirements#8
dependabot[bot] wants to merge 20 commits into
mainfrom
dependabot/pip/requirements/transformers-gte-5.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown

Updates the requirements on transformers to permit the latest version.

Release notes

Sourced from transformers's releases.

Release: v5.16.0

Release v5.16.0

New Model additions

Qwen4-Exp

Qwen4-Exp builds on Qwen3.5's hybrid text and multimodal architecture with three key components: GatedResidual (GR), Qwen Sparse Attention (QSA), and Per-Layer Embedding (PLE).

GR is a Qwen-developed residual architecture that combines Hyper-Connection with GatedNorm. It mixes multiple residual streams with fine-grained elementwise gating before each attention and Mixture-of-Experts (MoE) block, then controls how much of the block output is injected back into each stream.

QSA uses multiple query heads to score compressed key blocks, selects the most relevant contiguous token blocks, and keeps the incomplete trailing block uncompressed. This block-level selection reduces indexing overhead and improves memory locality for long sequences. Combined with Gated DeltaNet, QSA makes Qwen4-Exp the first hybrid architecture to integrate linear and sparse attention, substantially improving inference efficiency for long-context workloads.

PLE enriches selected decoder layers with layer-specific lexical features derived from hashed token n-grams and a dilated depthwise convolution.

Links: Documentation

GraniteSpeech5

Granite Speech 5.0 Turbo CTC is a lightweight (~470M parameters) conformer encoder for automatic speech recognition, trained with Connectionist Temporal Classification (CTC) on BPE targets. It is a fast, encoder-only member of the Granite Speech family: transcription requires a single forward pass followed by greedy CTC decoding, with no autoregressive decoder.

Architecturally, it extends the Granite Speech conformer CTC encoder with:

  1. Frame stacking + block-wise time subsampling: the feature extractor stacks pairs of log-mel(+delta) frames (2x), and the first two conformer blocks each subsample time by 2 through a stride-2 depthwise convolution (with a mean-pooled residual), for a total 8x time reduction at 10 ms mel hop.

  2. Block attention with Shaw's relative positional embeddings: attention is computed over fixed-size blocks (the sequence is right-padded to a whole number of blocks, with padded frames masked out), using separate bias-free query/key/value projections.

  3. Self-conditioned CTC: the CTC posteriors of the middle layer are projected and fed back into the hidden states, and the CTC head is shared between this mid-layer self-conditioning and the final prediction.

Links: Documentation

Step3p7

Step-3.7-Flash was proposed in Step 3.7 Flash by StepFun. It is a 198B-parameter sparse Mixture-of-Experts vision-language model, pairing a 196B-parameter MoE language backbone with a 1.8B-parameter vision encoder for native image understanding.

StepFun hasn't published a technical report for Step-3.7-Flash, so the details below are drawn from the released checkpoint's configuration rather than a paper.

  • Sparse MoE decoder: all but the first 3 decoder layers route through a MoE block of 288 routed experts (top-8 per token) plus a single shared expert. The router scores experts with a sigmoid and a learned per-expert bias instead of an auxiliary load-balancing loss, the same strategy as DeepSeek-V3.
  • Gated attention: each attention layer adds an extra projection whose sigmoid output gates the attention output per head, before the output projection — the same Gated Attention mechanism used in Qwen3-Next. A subset of layers use fewer heads and a sliding window instead of full attention.
  • Multi-token prediction: some checkpoints ship extra decoder layers trained for multi-token prediction, which [~GenerationMixin.generate] can use for speculative decoding via use_mtp=True.
  • Vision encoder: a SigLIP-style ViT with 2-D rotary position embeddings and a learned per-layer scale on the attention and MLP branches. Its output is downsampled 4x by two stride-2 convolutions before a linear projector maps it into the text model's hidden size.
  • Dynamic image tiling: instead of a fixed tile grid, the image processor picks its tiling window from each image's own aspect ratio, producing one downscaled global view plus zero or more local high-resolution crops per image.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

ilyautov and others added 20 commits June 29, 2026 12:54
…-safe

Открываются сразу с данными (хлор / Акридис / СИБУР / пример отхода) + чипы быстрого выбора. Дисклеймеры (надзор/методика/ФККО) и honest-gap сохранены. Мобайл 390px без переполнения (таблица инспектора — table-layout:fixed). XSS-фикс: полный атрибутный экранировщик в inspection/ppe.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
Главная: 5 плиток в разделе для специалистов. Карточка вещества → СИЗ/диспетчер; авария → оперативная карточка диспетчера; реестр завода → карта склада/режим инспектора. Все переходы — deep-link с encodeURIComponent.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
Хроника: разведка болей/кода, 5 модулей, демо-полировка, кросс-ссылки, мобайл-QA, security-фикс.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
…ционная сеть замкнута

Мобильная /card: «Подбор СИЗ» всегда + «Карточка диспетчера» для АХОВ (по той же логике is_ahov, что /emergency: учитывает ERG). safety.html: вкладка Совместимость → карта склада, вкладка Зона → диспетчер + СИЗ (deep-link по выбранному АХОВ). Всё URL-кодировано, мобайл 390px без переполнения.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
…етчер

5 новых модулей+экранов+эндпоинтов, демо-полировка (автозагрузка/чипы), замкнутая навигационная сеть (карточка/авария/реестр/QR-карточка/safety → инструменты), мобайл-QA 390px, XSS-фикс экранирования. Святое правило соблюдено везде (провенанс, honest-gap, плейсхолдеры, дисклеймеры).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
engine/shift_alert.py + shift.html + GET /shift/{name}?value=&unit=. Замер газоанализатора vs ПДК/IDLH, кратность, СИЗ (переиспользует ppe.recommend_ppe), при АХОВ — ссылка на карточку диспетчера. СВЯТОЕ ПРАВИЛО: единицы НЕ пересчитываем — кратность ПДК только при совпадении единиц, иначе honest-gap «единицы разные, сверьте вручную» (видно в UI). Плитка на главной + ссылка в карточке вещества.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
docs/ЛЕНДИНГ-ИНСТРУМЕНТЫ.md (hero, блок доверия, 6 инструментов со строкой «Честно:», CTA). Хроника: 6-й инструмент, демо-сценарий, лендинг-копи, вывод про headless-обрезку скриншотов (mobile через Playwright fullPage).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
docs/brochure/: brochure.html (книжная A4) + deck.html (16:9) с плейсхолдерами {{IMG}}, shots.sh (снять кадры), build.py (вшить base64 + печать через headless Chrome), README. Живой B2B-русский, реальные числа, нормативка по делу. PDF/*_embed.html — в .gitignore. WORKLOG #45.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CdKHxsviJk5nhTy5VdYw23
Юридический контур, safety-контур, community-обвязка и первые тесты. Обвязка
перенесена по образцу consilium-principis и адаптирована под safety-домен.

Тесты (было ноль): 105 офлайн-тестов, проходят без Ollama, сети и индекса;
исходящие соединения запрещены песочницей сокетов. Покрыт контур честности —
запрет пересчёта единиц, honest-gap класса отхода, градация passport/baseline,
отказ вне базы, провенанс, целостность CAS, гигиена репозитория.

Найдено тестами и исправлено:
- 27 CAS не проходят контрольную цифру (все в bulk, ядро чистое, обогащение
  пустое — fail-closed сработал). Добавлен engine/cas.py, флаг на карточке,
  cas_integrity в /quality. Номера НЕ исправляются автоматически.
- Прочерк «-» в CAS давал «регистрационный номер CAS -.» — генератор корпуса
  научен писать «не указан в источнике» (engine/fix_cas_placeholders.py).
- Дефолты путей указывали на промежуточный corpus_full.json: из свежего клона
  сервис не поднялся бы. Переведены на канонические clean-файлы.
- Реальные названия площадок были захардкожены в retriever.py и generate_ui.py —
  вынесены в data/plant_aliases.json, триггеры строятся из реестра (A/B 18/18).

Документы: LICENSE (MIT + отсылка к данным и дисклеймеру), DATA-LICENSE.md,
DISCLAIMER.md, LIMITATIONS.md, SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md,
GOVERNANCE.md, SUPPORT.md, README.en.md. README переписан под публичную
аудиторию (в шапке стояло 48 веществ вместо 2597), питч-рамка вынесена в docs/.

Инфраструктура: CI на 3.10-3.13 + macOS, Makefile, scripts/guard.sh,
requirements/{core,dev,full}.txt, шаблоны issue и PR, dependabot.
Обезличивание реестра площадок: engine/anonymize_plants.py + make demo.

Чистка индекса: -38 МБ (промежуточный корпус, доочистные id, исходные .docx).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Системный python3 может обновиться до версии, под которую зависимости не
ставились. Makefile берёт первый python3.x с установленным fastapi.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
После нормализации прочерка «-» подозрительных номеров стало 26 из 2071.
Актуальный счёт всегда отдаёт /quality -> cas_integrity.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Решение: в открытый доступ проект идёт без юрлиц. Перечень обращающихся на
площадке веществ — утверждение о промышленной безопасности организации;
собранное из публичных каталогов продукции, оно выглядит как инвентаризация,
ею не являясь. Проект, чья ценность в отказе утверждать без основания, такое
публиковать не может.

Выведено из репозитория (остаётся локально, внесено в .gitignore):
data/plants.json, plants_linked.json, plant_aliases.json. Вычищены также
неочевидные места: реальный ИНН в самотесте warehouse.py, golden-запросы
evaluate.py, комментарий semantic_hybrid_eval.py, подсказка console.html,
константа DEMO в inspection.html, автовыбор по регекспу в warehouse.html,
демо-сценарий, скрипт скриншотов брошюры, 8 мест в WORKLOG.

Вместо реестра публикуется data/plants.example.json: схема полей, вымышленный
пример, предупреждение о происхождении перечня веществ.

Функции по площадке сохранены и деградируют честно: /plant, /registry,
/warehouse, /inspection, /export/registry.csv без реестра отвечают «реестр
площадок не подключён» с объяснением, что делать, — не «завод не найден»
(это толкало бы искать опечатку) и не падением.

Попутно исправлена настоящая поломка: раскладки склада адресовались по ИНН,
после обезличивания шаблона демо-раскладка перестала бы находиться и экран
молча показывал бы пустоту. Адресация переведена на название площадки +
фолбэк на единственную раскладку со статусом template.

Сторож усилен: реестр не трекается, ИНН отсутствует, названия организаций
проверяются по денайлисту из .private/ (приватный файл — публичный скрипт не
носит список компаний).

Тесты: 113 (было 105), покрывают оба состояния — с реестром и без.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
PRODUCT.md — продуктовый контур: две сцены (цех/телефон, кабинет/монитор), кто чем
пользуется, что система не вправе утверждать. DESIGN.md + .impeccable/design.json —
токены, 17 именованных правил, компоненты, принятые отклонения.

Сведено 16 расхождений: строка сигнальных токенов теперь одна на все 18 экранов байт
в байт, радиусы в четыре ступени (вне шкалы — ноль), кегли без половинных пикселей,
40 литеральных цветов сведены к 12 каноническим, фокус и prefers-reduced-motion 18/18,
направление градиента шкалы одно, тёмные концы градиентов вынесены в токены
--red-d / --green-d / --amber-d / --orange-d.

Закрыто девять дефектов, три с ценой ошибки:

- главная кнопка пяти экранов давала 2.72:1 при пороге AA 4.5:1 — стала оранжевой,
  8.82:1; это же закрыло нарушение правила одного оранжевого;
- на карте склада цвет группы сегрегации брался из статусной палитры, из-за чего
  хлор-выделяющие вещества были помечены зелёным рядом с вердиктом «нельзя рядом».
  Заведена отдельная категориальная шкала (10 тонов OKLCH вне триады красный/янтарь/
  зелёный, каждый ≥7:1 к фону), квадратик группы получил aria-label — до этого имя
  группы жило только в title и на телефоне не существовало;
- быстрый выбор вещества был 30–38px при норме 46px для цеха, а на экране мастера
  смены растягивался во всю ширину и выдавливал форму за пределы экрана.

Измерено, а не оценено: 171 пара «текст на залитом фоне» с резолвом var() — ниже
4.5:1 ноль; 18 из 18 экранов на 390px — перелива по горизонтали нет; 6 из 6 цеховых
экранов — целей нажатия меньше 40px нет.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1. Денайлист сторожа отставал от реестра. Он был рукописным: 11 записей на 13 площадок,
   без «Авиабора» и «Экопола» и без доменов. Утечки они не дали, но проверка 6в молча
   пропустила бы новое название. Теперь список производный (scripts/sync_denylist.py:
   названия, варианты без скобок, содержимое скобок, домены и метки доменов), а guard.sh
   шагом 6г падает, если список отстал от данных. Псевдонимы, совпадающие с названиями
   веществ, исключаются автоматически: «корунд» — абразив, «тосол» — этиленгликоль,
   «синтанол» — ПАВ из СанПиН; сторож, который всегда красный, — это сторож, который
   отключают.

2. Названия организаций в двух местах, куда сторож не смотрел: имена переменных SIBUR и
   AKRIDIS в скрипте скриншотов (значения брались из окружения, а сами идентификаторы
   называли компании) и упоминание площадки в описании правки в WORKLOG.

3. Презентационные материалы выведены из поставки. Брошюра и слайд-дек — коммерческие
   документы с личными контактами владельца (почта, телефон), а не документация продукта;
   публичный репозиторий индексируется и вычёсывается ботами. Каталог docs/brochure/
   целиком в .gitignore, исходники остаются у владельца локально.

Заодно: абсолютные пути с именем пользователя в ollama-mcp/README.md заменены
плейсхолдерами.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…йн-система

Ветка chore/open-source-readiness: репозиторий приведён к состоянию, в котором его можно
открыть. Сведений о юридических лицах нет ни в данных, ни в коде, ни в примерах интерфейса,
ни в истории; сторож проверяет это сам и не отстаёт от реестра; дизайн-система зафиксирована
в PRODUCT.md и DESIGN.md и приведена в соответствие с кодом.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
При удалении путей с реестром площадок из истории под нож попал и docs/ДЕМО-СЦЕНАРИЙ.md:
я счёл, что файла нет в HEAD, потому что `git ls-files` печатает кириллические имена
в escape-виде, и мой поиск по имени ничего не нашёл. Файл был в HEAD и на него ссылается
README; тест целостности ссылок это и поймал.

Возвращён в том виде, в каком его обезличил владелец, — названий организаций в нём нет.
Ранние, необезличенные версии файла остались вычищенными из истории, и это верно.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Updates the requirements on [transformers](https://github.com/huggingface/transformers) to permit the latest version.
- [Release notes](https://github.com/huggingface/transformers/releases)
- [Commits](huggingface/transformers@v4.40.0...v5.16.0)

---
updated-dependencies:
- dependency-name: transformers
  dependency-version: 5.16.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 29, 2026
@ilyautov ilyautov closed this Aug 29, 2026
@ilyautov
ilyautov deleted the dependabot/pip/requirements/transformers-gte-5.16.0 branch August 29, 2026 12:50
@dependabot @github

dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant