Repository navigation
fix(deps): resolve high and critical dependabot alerts - #9723
Merged
joshistoast merged 2 commits intoOct 9, 2026
Merged
Conversation
Replace python-jose with PyJWT and raise transformers, onnx, sentencepiece, pillow and locked transitive deps to patched versions. Adapt CLIP skip, CLIP LoRA patching and SDNQ CLIP loading to transformers' flattened CLIPTextModel; update Qwen-Image and LTX2 loaders. Remove the Qwen3-VL pos-embed device patch, which transformers 5.10 no longer reaches.
joshistoast
approved these changes
Oct 9, 2026
joshistoast
enabled auto-merge (squash)
October 9, 2026 23:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the open High and Critical Dependabot alerts for Python dependencies, except protobuf (see Review).
PyJWT>=2.15.0ecdsa(unfixed Minerva timing attack),rsa,pyasn1. Every PyJWT release before 2.14 has its own High/Critical advisories.>=5.10.4,<5.11save_pretrainedpath traversal, remote generation-code download>=12.3.0transformers 5.6+ removed the
text_modelwrapper fromCLIPTextModel(CLIPTextModelWithProjectionkeeps it). The existing tests did not catch this, but it broke three things, now fixed:AttributeErroron SD1/SD2/SDXL text encoder 1 (model_patcher.py).text_model.*/lora_te_text_model_*, and 0 of 72 text-encoder layers resolved (layer_patcher.py).text_model.prefix, and the embedding dequantization looked under the removed wrapper (flux.py).Other adaptations:
Qwen2_5_VLForConditionalGeneration._checkpoint_conversion_mapping, which transformers 5.10 removed. It now carries the mapping itself.fast_pos_embed_interpolate; it builds its indices ongrid_thw's device, which H3 already moves to the compute device.token_service.pynow uses PyJWT. Expiry is enforced byjwt.decode(sameexp <= nowboundary as before), and only HS256 is accepted.Related Issues / Discussions
QA Instructions
uv run --no-sync pytest -n 4on the rebased branch: 12,602 passed, 182 skipped, 8 xfailed, 0 failed.uvx uv@0.11.28 lock --lockedpasses; ruff check and format pass.tests/backend/test_clip_text_model_wrapper.pybuilds tiny real CLIP models and covers clip skip, kohya and dottedtext_modelLoRA keys on both CLIP classes, and SDNQ CLIP loading and embedding dequantization. Each test fails with its fix reverted.alg=none, HS512 with the real secret, and a numeric-stringexp. A token minted by python-jose was confirmed to verify under PyJWT, so existing sessions survive the upgrade.Not run, and worth doing before merge:
Review
Review found the CLIP breakage above, a 500 from
/auth/media-cookieon a token whoseexpis a numeric string, and an untested SDNQ dequantization path. All are fixed and covered by tests.Remaining risks and limitations:
mediapipe.python.solutions, whichfacetools.pyimports. Fixing it means porting the face tools to MediaPipe's Tasks API.CLIPTextModelweights without thetext_model.prefix. They reload correctly here, but software on transformers < 5.6 would load an uninitialized text encoder from them.Compatibility / Rollout
transformersis capped<5.11because 5.x minor releases keep restructuring model classes this code walks by name.Checklist
What's Newcopy (if doing a release after this PR)