Problem
Dependabot alerts #14 (torch, low) and #15 (setuptools, medium) in tools/training/uv.lock cannot currently be fixed independently without breaking the shipped training runtime:
Do not use --no-deps, edit wheel metadata, force setuptools 83 beside Torch 2.11, or ship a custom PyTorch backport.
Upstream unblock conditions
Proceed only after released PyPI artifacts establish all of the following:
- Unsloth admits Torch 2.13.
- Unsloth Zoo admits Torch 2.13.
- The released pair still admits Python 3.13 and the repository's Transformers/TRL/PEFT/xformers closure.
- Official CUDA 12.9 CPython 3.13 x86-64 Torch 2.13 / torchvision 0.28 wheels remain available.
- Upstream or local evidence demonstrates Unsloth CUDA training on Torch 2.13; metadata widening alone is insufficient.
Upstream tracking:
Future implementation lane
In one dedicated PR, update together:
torch==2.13.0
torchvision==0.28.0
- first exact released compatible Unsloth and Unsloth Zoo versions
- PyTorch source/index from cu128 to cu129
setuptools==83.0.0 or the minimal later resolver-compatible safe release
Regenerate tools/training/uv.lock, verify all Torch artifacts come from the official cu129 index, then validate imports/versions, CUDA 12.9/RTX 5090 device detection, bitsandbytes and xformers native operations, a real deterministic QLoRA job with measured GPU use, checkpoint/export, and staged llama.cpp GGUF conversion/promotion. Finish with repository Python, targeted training, Release build/test, CI, and Dependabot rescans.
Current disposition
Leave both alerts open as upstream trackers. They are not false positives. If policy later requires dashboard suppression before upstream support exists, use only a documented temporary tolerable_risk dismissal linked to this issue.
Problem
Dependabot alerts #14 (
torch, low) and #15 (setuptools, medium) intools/training/uv.lockcannot currently be fixed independently without breaking the shipped training runtime:torch 2.11.0+cu128declaressetuptools<82, while alert build(deps-dev): bump the frontend-openapi-codegen group in /XE-Local-AI-Engine.Client.React with 2 updates #15 requires setuptools 83.0.0+torch<2.12, and released Unsloth Zoo requirestorch<2.13Do not use
--no-deps, edit wheel metadata, force setuptools 83 beside Torch 2.11, or ship a custom PyTorch backport.Upstream unblock conditions
Proceed only after released PyPI artifacts establish all of the following:
Upstream tracking:
Future implementation lane
In one dedicated PR, update together:
torch==2.13.0torchvision==0.28.0setuptools==83.0.0or the minimal later resolver-compatible safe releaseRegenerate
tools/training/uv.lock, verify all Torch artifacts come from the official cu129 index, then validate imports/versions, CUDA 12.9/RTX 5090 device detection, bitsandbytes and xformers native operations, a real deterministic QLoRA job with measured GPU use, checkpoint/export, and staged llama.cpp GGUF conversion/promotion. Finish with repository Python, targeted training, Release build/test, CI, and Dependabot rescans.Current disposition
Leave both alerts open as upstream trackers. They are not false positives. If policy later requires dashboard suppression before upstream support exists, use only a documented temporary
tolerable_riskdismissal linked to this issue.