Skip to content

fix(deps): resolve high and critical dependabot alerts - #9723

Merged
joshistoast merged 2 commits into
invoke-ai:mainfrom
lstein:chore/dependabot-high-critical
Oct 9, 2026
Merged

joshistoast merged 2 commits into
invoke-ai:mainfrom
lstein:chore/dependabot-high-critical

Conversation

@lstein

@lstein lstein commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

Fixes the open High and Critical Dependabot alerts for Python dependencies, except protobuf (see Review).

Package Change Why
python-jose → PyJWT replaced, PyJWT>=2.15.0 Critical algorithm-confusion advisory with no python-jose fix; also drops ecdsa (unfixed Minerva timing attack), rsa, pyasn1. Every PyJWT release before 2.14 has its own High/Critical advisories.
transformers 5.5.4 → >=5.10.4,<5.11 save_pretrained path traversal, remote generation-code download
onnx 1.16.1 → 1.21.0 6 advisories
sentencepiece 0.2.0 → 0.2.2 heap overflow
pillow → >=12.3.0 11 advisories
starlette, urllib3, anyio, cryptography, tornado, virtualenv lockfile only remaining advisories

transformers 5.6+ removed the text_model wrapper from CLIPTextModel (CLIPTextModelWithProjection keeps it). The existing tests did not catch this, but it broke three things, now fixed:

  • CLIP skip raised AttributeError on SD1/SD2/SDXL text encoder 1 (model_patcher.py).
  • CLIP LoRA layers were silently skipped. LoRA formats still address the encoder as text_model.* / lora_te_text_model_*, and 0 of 72 text-encoder layers resolved (layer_patcher.py).
  • SDNQ FLUX CLIP failed to load. The checkpoint carries the text_model. prefix, and the embedding dequantization looked under the removed wrapper (flux.py).

Other adaptations:

  • The Qwen-Image loader read Qwen2_5_VLForConditionalGeneration._checkpoint_conversion_mapping, which transformers 5.10 removed. It now carries the mapping itself.
  • The LTX2 loader dropped a warning filter for an unregistered Gemma4 model type that transformers now registers.
  • The MiniMax H3 Qwen3-VL pos-embed device patch is removed. In 5.10 the vision forward no longer calls the patched fast_pos_embed_interpolate; it builds its indices on grid_thw's device, which H3 already moves to the compute device.
  • token_service.py now uses PyJWT. Expiry is enforced by jwt.decode (same exp <= now boundary as before), and only HS256 is accepted.

Related Issues / Discussions

QA Instructions

  • uv run --no-sync pytest -n 4 on the rebased branch: 12,602 passed, 182 skipped, 8 xfailed, 0 failed.
  • uvx uv@0.11.28 lock --locked passes; ruff check and format pass.
  • New tests/backend/test_clip_text_model_wrapper.py builds tiny real CLIP models and covers clip skip, kohya and dotted text_model LoRA keys on both CLIP classes, and SDNQ CLIP loading and embedding dequantization. Each test fails with its fix reverted.
  • New auth tests cover tokens signed with another key, alg=none, HS512 with the real secret, and a numeric-string exp. A token minted by python-jose was confirmed to verify under PyJWT, so existing sessions survive the upgrade.

Not run, and worth doing before merge:

  • Real-weights generation on a GPU: SD1.5 and SDXL with CLIP skip and a LoRA that includes text-encoder layers, a FLUX generation (ideally an SDNQ model and a FLUX LoRA with CLIP layers), and a MiniMax H3 reference-image prompt under partial loading.
  • Windows: sentencepiece and onnx were pinned because sentencepiece 0.2.1 coredumped loading the T5 tokenizer, and newer onnx wheels needed uncommon DLLs. Neither upgrade has been tried on Windows.

Review

Review found the CLIP breakage above, a 500 from /auth/media-cookie on a token whose exp is a numeric string, and an untested SDNQ dequantization path. All are fixed and covered by tests.

Remaining risks and limitations:

  • protobuf (needs 5.29.6) is not fixed. mediapipe 0.10.14–0.10.21 caps protobuf below 5, and 0.10.30+ removes mediapipe.python.solutions, which facetools.py imports. Fixing it means porting the face tools to MediaPipe's Tasks API.
  • Converting a checkpoint to diffusers now writes CLIPTextModel weights without the text_model. prefix. They reload correctly here, but software on transformers < 5.6 would load an uninitialized text encoder from them.

Compatibility / Rollout

  • Existing login sessions stay valid: PyJWT accepts HS256 tokens issued by python-jose.
  • transformers is capped <5.11 because 5.x minor releases keep restructuring model classes this code walks by name.

Checklist

  • The PR has a short but descriptive title, suitable for a changelog
  • Meaningful regression coverage added / updated where needed; obsolete tests/code removed
  • Persisted-state and API changes include required migrations / compatibility validation
  • Relevant performance/efficiency opportunities considered; material claims have evidence
  • Material review findings resolved and relevant checks rerun
  • Documentation added / updated (if applicable)
  • Updated What's New copy (if doing a release after this PR)

Replace python-jose with PyJWT and raise transformers, onnx, sentencepiece, pillow and locked transitive deps to patched versions.
Adapt CLIP skip, CLIP LoRA patching and SDNQ CLIP loading to transformers' flattened CLIPTextModel; update Qwen-Image and LTX2 loaders.
Remove the Qwen3-VL pos-embed device patch, which transformers 5.10 no longer reaches.
@github-actions github-actions Bot added python PRs that change python files Root backend PRs that change backend files services PRs that change app services python-tests PRs that change python tests python-deps PRs that change python dependencies labels Oct 9, 2026
@joshistoast
joshistoast enabled auto-merge (squash) October 9, 2026 23:25
@joshistoast
joshistoast merged commit 4e9b032 into invoke-ai:main Oct 9, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend PRs that change backend files python PRs that change python files python-deps PRs that change python dependencies python-tests PRs that change python tests Root services PRs that change app services

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants