George
aa4c8ea693
fix: fix description limits ( #741 )
2026-09-28 20:09:09 +07:00
George
f245fe8c67
ci: enable tests on push to main ( #740 )
2026-09-27 04:25:30 +07:00
George
cbfe97ac4f
ci: skip late multimodal tests on windows ( #739 )
2026-09-27 04:22:16 +07:00
George
ff699e81a6
ci: disable late multimodal test on mac ( #738 )
...
* ci: disable late multimodal test on mac
* ci: disable one more test on macos, enable pytest --duration=10 everywhere
2026-09-27 04:06:38 +07:00
George
3490f69a28
new: add python3.14 to ci ( #737 )
2026-09-27 03:46:00 +07:00
George
21680f4a6a
fix: enable type checkers in PR CI ( #736 )
2026-09-27 00:36:20 +07:00
George
1647dc81e6
fix: fix mypy ( #735 )
2026-09-27 00:34:36 +07:00
Aditya Nikam and George Panchuk
9667d11037
Raise ValueError for non-positive batch_size in iter_batch ( #721 )
...
* Raise ValueError for non-positive batch_size in iter_batch
iter_batch passed batch_size straight into islice with no lower-bound
check. A batch_size of 0 made every islice call return an empty list
immediately, so embed and rerank returned an empty result with no error
across every modality that shares this helper. A negative batch_size hit
islice's own argument validation and raised a cryptic ValueError instead
of a clear one.
Validate batch_size >= 1 once in iter_batch itself, since every embed
and rerank entrypoint across dense text, sparse text, image,
late-interaction and cross-encoder rerank funnels through it.
Added test_iter_batch_rejects_non_positive_size and
test_iter_batch_accepts_positive_size to tests/test_common.py. The new
rejection test fails on unmodified code (batch_size=0 returns silently
instead of raising) and passes with the fix.
Fixes #719
* fix: fix batch size check for parallel execution
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-27 00:30:07 +07:00
Mohith Gajjela and George Panchuk
9ab3ffe9bc
new: support pluggable stemmer and inline stopwords for Bm25 ( #655 )
...
* feat: support pluggable stemmer and inline stopwords for BM25
Allow passing a custom stemmer (any object with a stem_word(word) -> str
method, per the new Stemmer protocol) to Bm25, overriding the default
SnowballStemmer. When a custom stemmer is provided, the supported-languages
check is skipped, enabling languages without a Snowball algorithm such as
Polish, Czech, Ukrainian, Slovak, Bulgarian, or Vietnamese.
Also allow passing stopwords inline, overriding the per-language stopwords
file shipped with the model. Both parameters are forwarded to parallel
workers. Default behavior is unchanged when neither parameter is given.
Fixes #654
* test: cover pluggable stemmer and inline stopwords for BM25
- custom stemmer callable is applied to tokens
- default Snowball path is unchanged
- unsupported language (Polish) works with a custom stemmer and still
raises without one
- inline stopwords override the file-based stopwords
* fix: refine BM25 custom stemmer and stopword handling
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-27 00:20:19 +07:00
Pothan and George Panchuk
44d0c4ef6d
Fix MUVERA encoding for empty documents ( #733 )
...
* Fix MUVERA encoding for empty documents
* Test MUVERA empty multivector encodings
* fix: raise on empty vectors in muvera
* Test ValueError for empty MUVERA inputs
* replace getattr with explicit calls in tests
Updated error messages for empty inputs in tests.
* remove redundant fixture
* remove unused import
* pytest import is actually required
* fix exception match message
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-26 23:27:04 +07:00
George
43531ea320
fix: improve parallel processes cleanup ( #734 )
...
* fix: improve parallel processes cleanup
* fix: fix mypy
2026-09-26 21:22:16 +07:00
e572d004f7
fix: terminate interrupted parallel workers ( #670 )
...
* fix: terminate interrupted parallel workers
* fix: reap terminated parallel workers
* test: cover worker cleanup after pool reuse
* fix: bound parallel worker shutdown and free unsent input batches
* fix: reset emergency shutdown on start
---------
Co-authored-by: FU-max-boop <214359569+FU-max-boop@users.noreply.github.com >
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-26 19:59:29 +07:00
David Heath and George Panchuk
4474111301
fix: verify the cached model files and re-fetch a corrupt one ( #642 )
...
* fix: re-download model when cached files fail verification
An interrupted or externally truncated download can leave a corrupt
file in the Hugging Face cache. On the next load the offline-first
probe sees the file on disk and returns it, so the model fails with
INVALID_PROTOBUF and the only fix is to delete the cache by hand.
This makes the cache self-heal. The probe now raises when a model
file's size does not match the recorded metadata, so download_model
falls through to an online retry with force_download=True
(huggingface_hub's cache check is existence-only and will not
re-fetch a present-but-truncated blob).
Verification also walks the repo tree recursively and matches files
by their repo-relative path. Without that, weights kept in a
subdirectory (onnx/model.onnx, more than half the models) were never
recorded in the metadata, so neither the new check nor the existing
one ever looked at them. A mismatch on an auxiliary config file is
still left to best-effort loading, as before.
* fix: merge force_download into kwargs on the recovery retry
If a caller passes force_download through kwargs, the explicit
force_download=True on the recovery retry would raise a duplicate
keyword error. Merge it into kwargs so the recovery value wins
without the collision.
* fix: only force a re-download when a cached model file is corrupt
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-26 01:18:42 +07:00
George
7ca84e26e8
fix: don't depend on the hub's case-normalizing redirect for model sources ( #732 )
...
* fix: don't depend on the hub's case-normalizing redirect for model sources
* fix: fall back to a differently cased cache entry when loading offline
2026-09-25 18:17:07 +07:00
George
d0b0478f57
fix: round Jina CLIP crop offsets to match Jina's reference ( #731 )
2026-09-25 13:49:22 +07:00
Hua.T and George Panchuk
92aa6a52f6
fix: preserve nearest interpolation for Jina CLIP ( #725 )
...
* fix: preserve nearest interpolation for Jina CLIP
* tests: remove redundant tests
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-25 13:02:31 +07:00
George
e3867c8dcc
fix: time out model_info so a silent hf endpoint can't hang download_model ( #730 )
2026-09-25 03:51:19 +07:00
George
8583de39d5
fix: use cached gcs copies after hf failures, don't warn for custom urls ( #729 )
2026-09-25 03:11:11 +07:00
George
6ee58d5239
fix: load bm25 offline by listing only files present in its hf repo ( #728 )
2026-09-25 03:08:40 +07:00
George
f61e7ab474
deprecate: drop fallback url to a google bucket ( #726 )
...
* deprecate: drop fallback url to a google bucket
* deprecation: add a deprecation warning when a model is loaded using cached gcs data
2026-09-25 02:23:15 +07:00
George
09cab68a47
fix: extend the pool of network errors caught during download ( #727 )
2026-09-25 02:14:12 +07:00
George
a4616aef62
fix: fix license for colpali and unicom ( #723 )
2026-09-24 16:40:52 +07:00
George
8de28b8f2d
fix: fix mypy ( #720 )
v0.8.1
2026-09-23 02:44:32 +07:00
George Panchuk
a2bef9821d
bump version to v0.8.1
2026-09-23 01:23:18 +07:00
George
fb68e86c23
fix: stage GCS downloads instead of deleting the caller's cache dir ( #718 )
...
* fix: stage GCS downloads instead of deleting the caller's cache dir
* fix: verify archive integrity and give each download its own staging dir
2026-09-23 01:15:54 +07:00
Yufeng He and George Panchuk
0c63b6ab52
fix: block unsafe tar extraction paths ( #647 )
...
* fix: block unsafe tar extraction paths
* fix: correct the version gate and fallback in tar extraction
* fix: fix windows vulnerability
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-22 15:59:52 +07:00
Serhii Zghama and George Panchuk
cbe60bf9dc
fix(image): normalize batched (N, C, H, W) input along the channel axis ( #682 )
...
* fix(image): normalize batched input along the channel axis
normalize() advertises 4D (N, C, H, W) support via its num_channels
branch and the channel-count validation, but the actual math used
((image.T - mean) / std).T. Transpose reverses every axis, so on 4D
input the channels no longer line up with mean/std: it raises when
N != C and silently normalizes along the batch axis when N == C.
Reshape mean/std to broadcast on the real channel axis instead; the
(C, H, W) path is unchanged.
* test(image): cover channel-wise normalize for 3D and batched input
* refactor
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-22 15:59:21 +07:00
Baojiang Lee and George Panchuk
40cca63d5f
fix: make tokenizer metadata files optional ( #693 )
...
* fix: support optional tokenizer metadata files
* fix: pad id fallback chain and additional_special_tokens lists
* refactor: remove redundant tests and comments
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-22 01:37:52 +07:00
5c4d9b04bd
fix: pass (width, height) to Pillow in the Resize transform ( #697 )
...
* fix: pass (width, height) to Pillow in the Resize transform
`resize()` handed a tuple size straight to `PIL.Image.resize()`. fastembed
keeps sizes as (height, width) — `Transform.from_config` builds the tuple
as `(size["height"], size["width"])` — while Pillow takes (width, height),
so a non-square image processor configuration produced a transposed image:
Resize(size=(100, 200))(Image.new("RGB", (300, 300)))[0].size
# (100, 200), expected (200, 100)
Square sizes are unaffected, which is why this went unnoticed. The int
branch of `resize()` already emits Pillow order and is untouched, as are
`resize_ndarray()`'s callers, which pass (width, height) explicitly.
`Resize.__call__` is the only caller of this function and always supplies
fastembed's height-first order, so converting here is safe.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com >
* tests: simplify tests
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-21 23:07:15 +07:00
George and Mohammed Alshyakh
a3a798f4f3
fix: preserve pad_to_multiple_of when normalizing padding ( #717 )
...
Co-authored-by: Mohammed Alshyakh <zzzzmmmm298@gmail.com >
2026-09-21 22:13:43 +07:00
George
bdf6816da8
fix: normalize tokenizer padding to batch-longest ( #716 )
...
* fix: normalize tokenizer padding to batch-longest
* fix: don't use max position embeddings as max len
2026-09-21 21:05:57 +07:00
dependabot[bot]
5dc53ebf49
chore(deps-dev): bump the security-updates group across 1 directory with 2 updates ( #705 )
...
Bumps the security-updates group with 2 updates in the / directory: [mkdocs-material](https://github.com/squidfunk/mkdocs-material ) and [mistune](https://github.com/lepture/mistune ).
Updates `mkdocs-material` from 9.7.4 to 9.7.7
- [Release notes](https://github.com/squidfunk/mkdocs-material/releases )
- [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG )
- [Commits](https://github.com/squidfunk/mkdocs-material/compare/9.7.4...9.7.7 )
Updates `mistune` from 3.3.0 to 3.3.3
- [Release notes](https://github.com/lepture/mistune/releases )
- [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst )
- [Commits](https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3 )
---
updated-dependencies:
- dependency-name: mistune
dependency-version: 3.3.3
dependency-type: indirect
dependency-group: security-updates
- dependency-name: mkdocs-material
dependency-version: 9.7.7
dependency-type: direct:development
dependency-group: security-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-21 15:06:59 +07:00
George and S0rryHorizon
b461314660
fix: fix registering custom models in child workers ( #714 )
...
* fix: fix registering custom models in child workers
Co-authored-by: S0rryHorizon <151612757+S0rryHorizon@users.noreply.github.com >
* fix: fix mypy
---------
Co-authored-by: S0rryHorizon <151612757+S0rryHorizon@users.noreply.github.com >
2026-09-21 15:05:47 +07:00
Darsh and George Panchuk
cc4d101828
fix case insensitive lookup for custom text models ( #645 )
...
* fix case insensitive lookup for custom text models
* refactor: refactor a bit
---------
Co-authored-by: George Panchuk <george.panchuk@qdrant.tech >
2026-09-16 17:46:21 +07:00
0dab99c23e
fix: use the canonical Hugging Face source for BGE-small ( #707 )
...
* fix: use the canonical Hugging Face source for BGE-small
* tests: remove excess test
---------
Co-authored-by: Basil Chen <192173459+rastagan-git@users.noreply.github.com >
Co-authored-by: George <george.panchuk@qdrant.tech >
2026-09-09 17:16:00 +07:00
Harnas
113bd565ec
Correct Qdrant/bge-base-en-v1.5-onnx-Q model name ( #593 )
...
Wrong name causes HTTP redirection, what may be wrongly handled by proxies.
2026-09-09 17:13:43 +07:00
Stephan Tulkens and Dylan Couzon
d5f552b6ad
new: add minish models ( #692 )
...
* new: add minish models
* add canonical values to test
* amend description
* Apply suggestions from code review
Co-authored-by: Dylan Couzon <dylancouzon@gmail.com >
* Update fastembed/text/onnx_embedding.py
Co-authored-by: Dylan Couzon <dylancouzon@gmail.com >
* fix typo
* fix keys in tests
---------
Co-authored-by: Dylan Couzon <dylancouzon@gmail.com >
2026-09-07 17:40:07 +07:00
dependabot[bot]
70c8f3cbc0
chore(deps-dev): bump tornado ( #698 )
...
Bumps the security-updates group with 1 update in the / directory: [tornado](https://github.com/tornadoweb/tornado ).
Updates `tornado` from 6.5.7 to 6.5.8
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst )
- [Commits](https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8 )
---
updated-dependencies:
- dependency-name: tornado
dependency-version: 6.5.8
dependency-type: indirect
dependency-group: security-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-07 16:34:37 +07:00
Bastian Hofmann
a34e7bcc42
Set copyright holder in LICENSE files ( #696 )
...
Replace the Apache 2.0 placeholder with Qdrant Solutions GmbH and the
year 2026.
2026-09-01 14:54:52 +02:00
George
c48247f15d
new: add siglip ( #683 )
2026-08-19 23:02:56 +07:00
George
f9d757ffc6
fix: fix qwen ( #680 )
2026-08-18 23:47:02 +07:00
George
a5a702acad
new: add qwen embedding ( #678 )
2026-08-18 19:26:16 +07:00
dependabot[bot]
a0fe741532
chore(deps-dev): bump mypy from 1.19.1 to 2.3.0 ( #663 )
...
Bumps [mypy](https://github.com/python/mypy ) from 1.19.1 to 2.3.0.
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md )
- [Commits](https://github.com/python/mypy/compare/v1.19.1...v2.3.0 )
---
updated-dependencies:
- dependency-name: mypy
dependency-version: 2.3.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:53:31 +07:00
dependabot[bot]
525642bd74
chore(deps): bump actions/setup-python from 6.2.0 to 7.0.0 ( #658 )
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 6.2.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...5fda3b95a4ea91299a34e894583c3862153e4b97 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:39:23 +07:00
dependabot[bot]
39426c282e
chore(deps): bump pypa/gh-action-pypi-publish ( #657 )
...
Bumps the version-updates group with 1 update in the / directory: [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish ).
Updates `pypa/gh-action-pypi-publish` from 1.14.0 to 1.14.2
- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases )
- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...dc37677b2e1c63e2034f94d8a5b11f265b73ba33 )
---
updated-dependencies:
- dependency-name: pypa/gh-action-pypi-publish
dependency-version: 1.14.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: version-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:39:10 +07:00
dependabot[bot]
eff93e3cb3
chore(deps-dev): bump pytest from 7.4.4 to 9.1.1 ( #664 )
...
Bumps [pytest](https://github.com/pytest-dev/pytest ) from 7.4.4 to 9.1.1.
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/7.4.4...9.1.1 )
---
updated-dependencies:
- dependency-name: pytest
dependency-version: 9.1.1
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:36:05 +07:00
dependabot[bot]
5cbf4f8947
chore(deps): bump actions/cache from 5.0.5 to 6.1.0 ( #659 )
...
Bumps [actions/cache](https://github.com/actions/cache ) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fccae...55cc8345863c7cc4c66a329aec7e433d2d1c52a9 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: 6.1.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:34:47 +07:00
dependabot[bot]
817fca3fab
chore(deps): bump actions/checkout from 6.0.2 to 7.0.1 ( #660 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.2 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...3d3c42e5aac5ba805825da76410c181273ba90b1 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:34:31 +07:00
dependabot[bot]
e60d5493bb
chore(deps-dev): bump mkdocstrings from 0.24.3 to 1.0.6 ( #665 )
...
Bumps [mkdocstrings](https://github.com/mkdocstrings/mkdocstrings ) from 0.24.3 to 1.0.6.
- [Release notes](https://github.com/mkdocstrings/mkdocstrings/releases )
- [Changelog](https://github.com/mkdocstrings/mkdocstrings/blob/main/CHANGELOG.md )
- [Commits](https://github.com/mkdocstrings/mkdocstrings/compare/0.24.3...1.0.6 )
---
updated-dependencies:
- dependency-name: mkdocstrings
dependency-version: 1.0.6
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:33:11 +07:00
dependabot[bot]
b2494cb321
chore(deps): bump the security-updates group across 1 directory with 15 updates ( #672 )
...
Bumps the security-updates group with 14 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [pillow](https://github.com/python-pillow/Pillow ) | `12.1.1` | `12.3.0` |
| [notebook](https://github.com/jupyter/notebook ) | `7.5.4` | `7.5.6` |
| [onnx](https://github.com/onnx/onnx ) | `1.20.1` | `1.22.0` |
| [bleach](https://github.com/mozilla/bleach ) | `6.3.0` | `6.4.0` |
| [gitpython](https://github.com/gitpython-developers/GitPython ) | `3.1.46` | `3.1.58` |
| [idna](https://github.com/kjd/idna ) | `3.11` | `3.15` |
| [jupyter-server](https://github.com/jupyter-server/jupyter_server ) | `2.17.0` | `2.20.0` |
| [mistune](https://github.com/lepture/mistune ) | `3.2.0` | `3.3.0` |
| [nbconvert](https://github.com/jupyter/nbconvert ) | `7.17.0` | `7.17.1` |
| [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions ) | `10.21` | `11.0.1` |
| [setuptools](https://github.com/pypa/setuptools ) | `82.0.0` | `83.0.0` |
| [soupsieve](https://github.com/facelessuser/soupsieve ) | `2.8.3` | `2.8.4` |
| [tornado](https://github.com/tornadoweb/tornado ) | `6.5.4` | `6.5.7` |
| [urllib3](https://github.com/urllib3/urllib3 ) | `2.6.3` | `2.7.0` |
Updates `pillow` from 12.1.1 to 12.3.0
- [Release notes](https://github.com/python-pillow/Pillow/releases )
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst )
- [Commits](https://github.com/python-pillow/Pillow/compare/12.1.1...12.3.0 )
Updates `notebook` from 7.5.4 to 7.5.6
- [Release notes](https://github.com/jupyter/notebook/releases )
- [Changelog](https://github.com/jupyter/notebook/blob/@jupyter-notebook/tree@7.5.6/CHANGELOG.md )
- [Commits](https://github.com/jupyter/notebook/compare/@jupyter-notebook/tree@7.5.4...@jupyter-notebook/tree@7.5.6 )
Updates `onnx` from 1.20.1 to 1.22.0
- [Release notes](https://github.com/onnx/onnx/releases )
- [Changelog](https://github.com/onnx/onnx/blob/main/docs/Changelog-ml.md )
- [Commits](https://github.com/onnx/onnx/compare/v1.20.1...v1.22.0 )
Updates `bleach` from 6.3.0 to 6.4.0
- [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES )
- [Commits](https://github.com/mozilla/bleach/compare/v6.3.0...v6.4.0 )
Updates `gitpython` from 3.1.46 to 3.1.58
- [Release notes](https://github.com/gitpython-developers/GitPython/releases )
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES )
- [Commits](https://github.com/gitpython-developers/GitPython/compare/3.1.46...3.1.58 )
Updates `idna` from 3.11 to 3.15
- [Release notes](https://github.com/kjd/idna/releases )
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md )
- [Commits](https://github.com/kjd/idna/compare/v3.11...v3.15 )
Updates `jupyter-server` from 2.17.0 to 2.20.0
- [Release notes](https://github.com/jupyter-server/jupyter_server/releases )
- [Changelog](https://github.com/jupyter-server/jupyter_server/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jupyter-server/jupyter_server/compare/v2.17.0...v2.20.0 )
Updates `jupyterlab` from 4.5.5 to 4.5.10
- [Release notes](https://github.com/jupyterlab/jupyterlab/releases )
- [Changelog](https://github.com/jupyterlab/jupyterlab/blob/main/RELEASE.md )
- [Commits](https://github.com/jupyterlab/jupyterlab/compare/@jupyterlab/lsp@4.5.5...@jupyterlab/lsp@4.5.10 )
Updates `mistune` from 3.2.0 to 3.3.0
- [Release notes](https://github.com/lepture/mistune/releases )
- [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst )
- [Commits](https://github.com/lepture/mistune/compare/v3.2.0...v3.3.0 )
Updates `nbconvert` from 7.17.0 to 7.17.1
- [Release notes](https://github.com/jupyter/nbconvert/releases )
- [Changelog](https://github.com/jupyter/nbconvert/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jupyter/nbconvert/compare/v7.17.0...v7.17.1 )
Updates `pymdown-extensions` from 10.21 to 11.0.1
- [Release notes](https://github.com/facelessuser/pymdown-extensions/releases )
- [Commits](https://github.com/facelessuser/pymdown-extensions/compare/10.21...11.0.1 )
Updates `setuptools` from 82.0.0 to 83.0.0
- [Release notes](https://github.com/pypa/setuptools/releases )
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst )
- [Commits](https://github.com/pypa/setuptools/compare/v82.0.0...v83.0.0 )
Updates `soupsieve` from 2.8.3 to 2.8.4
- [Release notes](https://github.com/facelessuser/soupsieve/releases )
- [Commits](https://github.com/facelessuser/soupsieve/compare/2.8.3...2.8.4 )
Updates `tornado` from 6.5.4 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst )
- [Commits](https://github.com/tornadoweb/tornado/compare/v6.5.4...v6.5.7 )
Updates `urllib3` from 2.6.3 to 2.7.0
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
---
updated-dependencies:
- dependency-name: pillow
dependency-version: 12.3.0
dependency-type: direct:production
dependency-group: security-updates
- dependency-name: notebook
dependency-version: 7.5.6
dependency-type: direct:development
dependency-group: security-updates
- dependency-name: onnx
dependency-version: 1.22.0
dependency-type: direct:development
dependency-group: security-updates
- dependency-name: bleach
dependency-version: 6.4.0
dependency-type: indirect
dependency-group: security-updates
- dependency-name: gitpython
dependency-version: 3.1.58
dependency-type: indirect
dependency-group: security-updates
- dependency-name: idna
dependency-version: '3.15'
dependency-type: indirect
dependency-group: security-updates
- dependency-name: jupyter-server
dependency-version: 2.20.0
dependency-type: indirect
dependency-group: security-updates
- dependency-name: jupyterlab
dependency-version: 4.5.10
dependency-type: indirect
dependency-group: security-updates
- dependency-name: mistune
dependency-version: 3.3.0
dependency-type: indirect
dependency-group: security-updates
- dependency-name: nbconvert
dependency-version: 7.17.1
dependency-type: indirect
dependency-group: security-updates
- dependency-name: pymdown-extensions
dependency-version: 11.0.1
dependency-type: indirect
dependency-group: security-updates
- dependency-name: setuptools
dependency-version: 83.0.0
dependency-type: indirect
dependency-group: security-updates
- dependency-name: soupsieve
dependency-version: 2.8.4
dependency-type: indirect
dependency-group: security-updates
- dependency-name: tornado
dependency-version: 6.5.7
dependency-type: indirect
dependency-group: security-updates
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
dependency-group: security-updates
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 20:32:35 +07:00