Skip to content

build: bump the python-minor group across 1 directory with 3 updates - #105

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-minor-d678182993
Open

build: bump the python-minor group across 1 directory with 3 updates#105
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-minor-d678182993

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-minor group with 3 updates in the / directory: openadapt-types, openadapt-flow and onnxruntime.

Updates openadapt-types from 0.7.0 to 0.10.0

Release notes

Sourced from openadapt-types's releases.

v0.10.0 (2026-08-08)

Documentation

  • Align entry commands and substrate maturity across repo READMEs (#24, 097d11d)

Adopt the canonical first-run path (pip install 'openadapt[browser]' + openadapt quickstart), keep engine-direct commands as explicit variants of the same loop, use the shared substrate-maturity table verbatim, name the tutorial fixture MockMed (a synthetic practice-management fixture) on first mention, and show the cmd.exe double-quoted install form.

Co-authored-by: Claude Fable 5 noreply@anthropic.com

Features

  • Add portable business decision contracts (#25, 826cbb3)
  • feat: add portable business decision contracts

  • docs: clarify decision presentation trust

  • fix: bind reviewed business decision presentation


Detailed Changes: v0.9.0...v0.10.0

v0.9.0 (2026-07-30)

Features

  • Add Execute reference clients (f0c08c4)

Add the public Execute OpenAPI client, secure reference clients, and integration examples.


Detailed Changes: v0.8.0...v0.9.0

v0.8.0 (2026-07-29)

Features

  • Add qualified entity decision task v2 (#22, d6e6e11)

Add a versioned signed task contract for qualification-approved entity labels. Preserve V1 bytes, bind the qualification project and exact step, keep a neutral fallback, and use a strict cross-language timestamp and action contract.


Detailed Changes: v0.7.0...v0.8.0

Changelog

Sourced from openadapt-types's changelog.

v0.10.0 (2026-08-08)

Documentation

  • Align entry commands and substrate maturity across repo READMEs (#24, 097d11d)

Adopt the canonical first-run path (pip install 'openadapt[browser]' + openadapt quickstart), keep engine-direct commands as explicit variants of the same loop, use the shared substrate-maturity table verbatim, name the tutorial fixture MockMed (a synthetic practice-management fixture) on first mention, and show the cmd.exe double-quoted install form.

Co-authored-by: Claude Fable 5 noreply@anthropic.com

Features

  • Add portable business decision contracts (#25, 826cbb3)
  • feat: add portable business decision contracts

  • docs: clarify decision presentation trust

  • fix: bind reviewed business decision presentation

v0.9.0 (2026-07-30)

Features

  • Add Execute reference clients (f0c08c4)

Add the public Execute OpenAPI client, secure reference clients, and integration examples.

v0.8.0 (2026-07-29)

Features

  • Add qualified entity decision task v2 (#22, d6e6e11)

Add a versioned signed task contract for qualification-approved entity labels. Preserve V1 bytes, bind the qualification project and exact step, keep a neutral fallback, and use a strict cross-language timestamp and action contract.

Commits
  • 75e4471 chore: release 0.10.0
  • 826cbb3 feat: add portable business decision contracts (#25)
  • 097d11d docs: align entry commands and substrate maturity across repo READMEs (#24)
  • 0a9b720 chore: release 0.9.0
  • f0c08c4 feat: add Execute reference clients
  • 72bf95b chore: release 0.8.0
  • d6e6e11 feat: add qualified entity decision task v2 (#22)
  • See full diff in compare view

Updates openadapt-flow from 1.27.1 to 1.31.0

Release notes

Sourced from openadapt-flow's releases.

v1.31.0 (2026-08-09)

This release is published under the MIT License.

Bug Fixes

  • Authenticate decision renewal history (#339, 3b6d33e)

  • Bind decision task v2 to pause authority (#308, e010c9f)

  • Bind identity-armed templates to landmark state (#327, ff1a80c)

  • Bind portable decision receipts to exact answers (#341, 079bbc8)

  • Bind RDP acceptance campaign to remote surface (#327, ff1a80c)

  • Bind RDP application label (#327, ff1a80c)

  • Bind RDP campaign qualification authority (#327, ff1a80c)

  • Bind RDP campaign verifier tiers (#327, ff1a80c)

  • Bind RDP client session identity (#327, ff1a80c)

  • Bind RDP qualification environment (#327, ff1a80c)

  • Bind RDP qualification target (#327, ff1a80c)

  • Bind remote mask to fresh protected regions (#322, 3b56041)

  • Bind remote masks to resolution evidence (#322, 3b56041)

  • Bind remote review to the exact run (#348, cdbe958)

  • Bound RDP campaign observation and coverage (#327, ff1a80c)

  • Close identity-armed remote actuation evidence (#327, ff1a80c)

  • Continue bounded scroll after OCR ambiguity (#327, ff1a80c)

  • Enforce decision service local trust (#350, 8160dc4)

  • Enforce qualified remote frame input gates (#322, 3b56041)

  • Expose RDP environment evidence (#327, ff1a80c)

  • Expose RDP environment markers (#327, ff1a80c)

  • Harden business decision authority (#339, 3b6d33e)

... (truncated)

Commits
  • 2d225de chore: release 1.31.0
  • faf9945 fix: keep qualified bundles consistent through sanitization (#351)
  • d1b1ced feat(tutorial): add guided human recording and paced replay (#315)
  • 3b56041 feat: bind remote volatility comparison contract (#322)
  • 8160dc4 feat: add non-actuating business decision service (#350)
  • 0146429 feat: route typed decisions across customer runs (#349)
  • cdbe958 feat: bind mobile business decisions during qualification (#348)
  • a93f535 feat: add typed decision qualification CLI (#346)
  • 3babe8d feat: connect typed decisions to Cloud relay (#347)
  • ba8ab0e feat: attest typed decision relay envelopes (#345)
  • Additional commits viewable in compare view

Updates onnxruntime from 1.20.1 to 1.28.0

Release notes

Sourced from onnxruntime's releases.

ONNX Runtime v1.28.0

Announcements & Breaking Changes

  • Upgraded to ONNX 1.22.0 and protobuf 6.33.5 (#28754, #29606, #28967). Graph optimizer opset version checks were updated accordingly (#28966).
  • cuDNN and cuFFT are now optional at runtime for the CUDA EP, and nvrtc is no longer linked, which significantly reduces the required CUDA redistributable footprint (#29252, #29808, #29705, #29620).
  • An experimental C/C++ API surface was introduced. OrtModelPackageApi now lives in the experimental C API and may change in future releases (#28746, #29142, #28990).
  • Deprecated / removed:
    • SkipLayerNorm strict mode is deprecated (#29388).
    • The TensorRT fused causal attention kernels were removed from the CUDA EP (#29143).
    • The dynamic WGSL generator (duktape/Node) path was removed in favor of the Python wgsl-gen implementation (#29141, #28355).
    • CUDA_QUANT_PREPROCESS is off by default (#29687).
  • NPM packages are now published from the CUDA 13 pipeline (#28773).
  • The CUDA 12.8 package architecture list was refreshed for this release (#29711).

Security Fixes

Memory safety & input validation

  • Hardened the ORT FlatBuffer model loader against malformed buffers, and removed now-redundant table offset validation (#28186, #29068)
  • Fixed type confusion in raw-pointer bind_input causing an out-of-bounds write (#28839)
  • Fixed out-of-bounds pointer in TensorAt for sub-byte packed types (#28973)
  • Fixed arbitrary memory read, out-of-bounds dereference, and other OOB accesses in kernels (#28991, #29011, #29012, #29014)
  • Validated Col2Im inputs to prevent heap over-read (#28706)
  • Hardened CropAndResize against malformed crop_size tensors (#28766)
  • Validated BeamSearch vocab_size against logits width (#28774)
  • Fixed bounds in WhisperDecoderSubgraph::CreateInitialFeeds (#29239)
  • Validated SparseAttention CSR indices/key lengths and rejected zero-dimension block_row_indices (#29015, #29242)
  • Clamped derived sequence lengths and KV-cache index in CUDA GroupQueryAttention, and fixed a CPU GQA out-of-bounds read in the past-KV buffer (#29240, #29447)
  • Clamped 1D attention mask_index to valid bounds (#29449)
  • Validated MaxpoolWithMask kernel rank against input spatial rank (#29253)
  • Rejected CUDA BERT EmbedLayerNorm/SkipLayerNorm shapes exceeding 32-bit output indexing (#29264)
  • Fixed the optional-output guard in DecoderAttention/MultiHeadAttention shape inference and negative-axis handling in ExpandDims shape inference (#29268, #29448)
  • Fixed TreeEnsemble target id validation and added input validation to LinearClassifier (#29293, #29060)
  • Fixed DynamicQuantizeLSTM zero-point/scale validation typos (#29462)
  • Handled non-trivially-copyable types in Loop/Scan output concatenation (#29397)
  • Normalized bool tensor raw_data to {0, 1} on unpack (#29238)
  • Addressed hardening gaps in Resize, PadFusion, and LoRA handling (#28779, #28780, #28801)
  • Fixed unbounded lifetime on WithOutputTensor in the Rust bindings (#29251)

Integer overflow & allocation size

  • Guarded MlasConvPrepare working-buffer products and ConvTranspose pad computation with SafeInt (#29444, #29446)
  • Fixed signed-int overflow in SamplingState::Init that could cause a heap buffer overflow (#29443)
  • Hardened QMoE against integer overflow and partial K tiles (#29067)
  • Validated B/scales/zero-points shape in MatMulNBits::PrePack (#29445)
  • Pre-checked ConstantOfShape output size against the input initializer before constant folding (#28751)
  • Fixed integer overflow in RKNPU implicit bias allocation (#29249)
  • Fixed WebGPU out-of-bounds reads in Pad (int64/int32 truncation), Slice, and GatherBlockQuantized (#28721, #28704, #28718)

Supply chain & tooling

... (truncated)

Commits
  • da9b5e3 Fix Windows zip artifact to include .inc header files (#29874)
  • 45de2a8 Fix NuGet packaging to include .inc files alongside .h headers (#29868)
  • 0368187 ORT 1.28.0 release cherry-pick round 2 (#29821)
  • e1bbb64 ORT 1.28.0 release cherry-pick round 1 (#29771)
  • a06675e Fix web e2e (npm/vite) and Python DML CI pipelines (#29609)
  • c4f1961 Bump onnx to 1.22.0 and protobuf to 6.33.5 to fix security CVEs (#29606)
  • e0ad071 [CUDA] Enable native SM90, block_size=32, and fused bias for fpA_intB MatMulN...
  • a1fc71e [CUDA] Fix QMoE profiler cross-stream race and CUDA-graph-capture safety (#29...
  • 5eb4aee Fix CustomOp forward compatibility: cap version instead of rejecting (#29574)
  • 7a12371 adjusts conv kernel to use get/set by offset helpers (#29463)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 8, 2026
Bumps the python-minor group with 3 updates in the / directory: [openadapt-types](https://github.com/OpenAdaptAI/openadapt-types), [openadapt-flow](https://github.com/OpenAdaptAI/openadapt-flow) and [onnxruntime](https://github.com/microsoft/onnxruntime).


Updates `openadapt-types` from 0.7.0 to 0.10.0
- [Release notes](https://github.com/OpenAdaptAI/openadapt-types/releases)
- [Changelog](https://github.com/OpenAdaptAI/openadapt-types/blob/main/CHANGELOG.md)
- [Commits](OpenAdaptAI/openadapt-types@v0.7.0...v0.10.0)

Updates `openadapt-flow` from 1.27.1 to 1.31.0
- [Release notes](https://github.com/OpenAdaptAI/openadapt-flow/releases)
- [Changelog](https://github.com/OpenAdaptAI/openadapt-flow/blob/main/CHANGELOG.md)
- [Commits](OpenAdaptAI/openadapt-flow@v1.27.1...v1.31.0)

Updates `onnxruntime` from 1.20.1 to 1.28.0
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](microsoft/onnxruntime@v1.20.1...v1.28.0)

---
updated-dependencies:
- dependency-name: onnxruntime
  dependency-version: 1.28.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor
- dependency-name: openadapt-flow
  dependency-version: 1.29.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor
- dependency-name: openadapt-types
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build: bump the python-minor group with 3 updates build: bump the python-minor group across 1 directory with 3 updates Aug 15, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-minor-d678182993 branch from d88368a to ed3cf2f Compare August 15, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants