Skip to content

security: unblock Torch and Setuptools training runtime alerts #25

Description

@w0rldx

Problem

Dependabot alerts #14 (torch, low) and #15 (setuptools, medium) in tools/training/uv.lock cannot currently be fixed independently without breaking the shipped training runtime:

Do not use --no-deps, edit wheel metadata, force setuptools 83 beside Torch 2.11, or ship a custom PyTorch backport.

Upstream unblock conditions

Proceed only after released PyPI artifacts establish all of the following:

  1. Unsloth admits Torch 2.13.
  2. Unsloth Zoo admits Torch 2.13.
  3. The released pair still admits Python 3.13 and the repository's Transformers/TRL/PEFT/xformers closure.
  4. Official CUDA 12.9 CPython 3.13 x86-64 Torch 2.13 / torchvision 0.28 wheels remain available.
  5. Upstream or local evidence demonstrates Unsloth CUDA training on Torch 2.13; metadata widening alone is insufficient.

Upstream tracking:

Future implementation lane

In one dedicated PR, update together:

  • torch==2.13.0
  • torchvision==0.28.0
  • first exact released compatible Unsloth and Unsloth Zoo versions
  • PyTorch source/index from cu128 to cu129
  • setuptools==83.0.0 or the minimal later resolver-compatible safe release

Regenerate tools/training/uv.lock, verify all Torch artifacts come from the official cu129 index, then validate imports/versions, CUDA 12.9/RTX 5090 device detection, bitsandbytes and xformers native operations, a real deterministic QLoRA job with measured GPU use, checkpoint/export, and staged llama.cpp GGUF conversion/promotion. Finish with repository Python, targeted training, Release build/test, CI, and Dependabot rescans.

Current disposition

Leave both alerts open as upstream trackers. They are not false positives. If policy later requires dashboard suppression before upstream support exists, use only a documented temporary tolerable_risk dismissal linked to this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions