Skip to content

fix(deps): update dependency xgboost to v3 - #167

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/xgboost-3.x
Open

fix(deps): update dependency xgboost to v3#167
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/xgboost-3.x

Conversation

@renovate

@renovate renovate Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
xgboost ^2.0.0^3.0.0 age confidence

Release Notes

dmlc/xgboost (xgboost)

v3.4.0: Release 3.4.0 stable

Compare Source

Release notes

https://xgboost.readthedocs.io/en/latest/changes/v3.4.0.html

Additional artifacts

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
af4588b34c7fa1bfde258006beebbe181454f1fb74266f81883b23059af3b9fb  xgboost-src-3.4.0.tar.gz
8feb5a559cd869e9c9b8ed1a60475c34b7ba689c6f7b9c41dc9ba16fae4d19fe  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

Source tarball

v3.3.0: Release 3.3.0 stable

Compare Source

Release notes

https://xgboost.readthedocs.io/en/latest/changes/v3.3.0.html

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
22d4fba822fba5cd02299bf0c63ec68ff72606bc1b1bd910423d4b83c2f108ff  xgboost-src-3.3.0.tar.gz
df276bf14ebda98319da70fa88874746d9275ffbcde77e18e171d809cdbda86a  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

Source tarball

v3.2.0: Release 3.2.0 stable

Compare Source

Release note

https://xgboost.readthedocs.io/en/latest/changes/v3.2.0.html

Additional artifacts

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
16a31dfbc0c54544c9c36ab5f696fa7b646c125f161c52c814d757a58241a404  xgboost-src-3.2.0.tar.gz
41ce6798ed032380d4efed08cb1e4fadb87a5eba401b530fefcb90f1deb367d0  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.2.0.tar.gz: Download

Source tarball

v3.1.3: 3.1.3 Patch Release

Compare Source

What's Changed

  • Scikit-learn 1.8 compatibility fix (#​11858)
  • Add ARM CUDA wheels for PyPI. (#​11827) Add nccl as dep for aarch64. (#​11753)
  • [R] Fix off-by-one bug: nrounds=0 resulted in 2 iterations #​11856
  • [R] Fix mingw warnings, winbuilder check warnings, memory safety issues. (#​11859, #​11847, #​11830, #​11906)
  • Avoid overflow in rounding estimation. (#​11910)
  • Workaround compiler issue on Windows, affects the use of max_delta_step with CUDA. (#​11916)

Full Changelog: dmlc/xgboost@v3.1.2...v3.1.3

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
67800a7c1c0455c22c9be73dbf3c39bfd9ac9627b2cb617eb2795fd675a9d49e  xgboost-src-3.1.3.tar.gz
f3586dc2da415bba7c3a632b290d653b74eea0caf2ea9e8ffb488cacb57a1dcf  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.1.3.tar.gz: Download

Source tarball

v3.1.2: 3.1.2 Patch Release

Compare Source

What's Changed
  • Fix ordering of Python callbacks. (#​11812)
  • Fix loading nccl 2.28. (#​11806)
  • Infer the enable_categorical during model load. (#​11816)
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
12f2d6f735fa71e007c40171fd926c12306276dd299dc48f6c923e4f3891c33e  xgboost-src-3.1.2.tar.gz
2f83f1b24affb50bf65a8dd80d4ac9d19fe95cf181df35fa8a335a06d2eb9cfd  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.1.2.tar.gz: Download

Source tarball

v3.1.1: 3.1.1 Patch Release

Compare Source

What's Changed

  • Emit correct error when performing inplace-predict using a CPU-only version of XGBoost, but with a GPU input. (#​11761)
  • Enhance the error message for loading the removed binary model format. (#​11760)
  • Use the correct group ID for SHAP when the intercept is a vector. (#​11764)

Full Changelog: dmlc/xgboost@v3.1.0...v3.1.1

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
b2bb9c93f28fe7e401dbe592eb7990f5382baa712b02301eb8fd4cdb6c676731  xgboost-src-3.1.1.tar.gz
ae6f2f2397aea02c77e77435cd9f617b5990756d5800218ff44f4ff5eba9104a  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.1.1.tar.gz: Download

Source tarball

v3.1.0: Release 3.1.0 stable

Compare Source

Release note

https://xgboost.readthedocs.io/en/latest/changes/v3.1.0.html

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
4c42d35976067270a9255bf9ee290a706917bb3929a60cdd74d4dd3f1a9c86cc  xgboost-src-3.1.0.tar.gz
79b3407f19ccfa7344ee1a7ae9afb845cff9472c5a736fbdbdf95d98950c8290  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.1.0.tar.gz: Download

Source tarball

v3.0.5: 3.0.5 Patch Release

Compare Source

What's Changed

Full Changelog: dmlc/xgboost@v3.0.4...v3.0.5

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
0776b59fad03548c447cb1e188469761241ffb3b36154dc8a59735f11d262dc2  xgboost-src-3.0.5.tar.gz
516759a0dd40da18d46fa84a945dce48a7612c9ddc4cfb3bc99df7575e889318  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.0.5.tar.gz: Download

Source tarball

v3.0.4: 3.0.4 Patch Release

Compare Source

What's Changed

  • Remove the use of all __restrict__. (#​11616)
  • Make CUDA lineinfo optional. (#​11606)
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
5388cc28f4f7725edc7d9eed4c4794a818df7c76c2d39652debe6fca7df770cf  xgboost-src-3.0.4.tar.gz
e43482127db15039f2ea2eb834adde885fa6a1d685a0526fed4293f863a793d5  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.0.4.tar.gz: Download

Source tarball

v3.0.3: 3.0.3 Patch Release

Compare Source

  • Fix NDCG metric with non-exp gain. (#​11534)
  • Avoid using mean intercept for rmsle. (#​11588)
  • [jvm-packages] add setNumEarlyStoppingRounds API (#​11571)
  • Avoid implicit synchronization in GPU evaluation. (#​11542)
  • Remove CUDA check in the array interface handler (#​11386)
  • Fix check in GPU histogram. (#​11574)
  • Support Rapids 25.06 (#​11504)
  • Adding enable_categorical to the sklearn .apply method (#​11550)
  • Make xgboost.testing compatible with scikit-learn 1.7 (#​11502)
  • Add support for building xgboost wheels on Win-ARM64 (#​11572, #​11597, #​11559)
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
6598adf6a073a55cc87a31e6712fc6dab938a5317aeae7134a07067d51acdf3a  xgboost-src-3.0.3.tar.gz
162eb7811313eac5c55f686920b32c5c29c929872bdbc65af147c6f4f19bc38d  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.0.3.tar.gz: Download

Source tarball

v3.0.2: 3.0.2 Patch Release

Compare Source

What's Changed

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
8f909899f5dc64d4173662a3efa307100713e3c2e2b831177c2e56af0e816caf  xgboost-src-3.0.2.tar.gz
c169cb92fe378d99f1938da5d2830da1cef731129701db480b03dbbd04333ae2  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.0.2.tar.gz: Download

Source tarball

v3.0.1: 3.0.1 Patch Release

Compare Source

  • Use nvidia-smi to detect the driver version and handle old drivers that don't support virtual memory. (#​11391)
  • Optimize deep trees for GPU external memory. (#​11387)
  • Small fix for page concatenation with external memory (#​11338)
  • Build xgboost-cpu for manylinux_2_28_x86_64 (#​11406)
  • Workaround for different Dask versions (#​11436)
  • Output models now use denormal floating-point instead of nan. (#​11428)
  • Fix aarch64 CI. (#​11454)
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
46e6815fd24dec7e17ed6e9327cc062da098387ee36358e3e0a43fc43939a8b1  xgboost-src-3.0.1.tar.gz
c00bc34a070d25557b06ccb684b4dff44a0f578cbe84442957742f3aba4f0c32  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.0.1.tar.gz: Download

Source tarball

v3.0.0: Release 3.0.0 stable

Compare Source

Release note

https://xgboost.readthedocs.io/en/latest/changes/v3.0.0.html

Additional artifacts:

You can verify the downloaded packages by running the following command with your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
431222b47085b9c3504d77ef59cfa23ae4fe9d701085313f47217e49e8823326  xgboost-src-3.0.0.tar.gz
a5dafa6ccc1a3df3d7e3c84d61dae4dcc6921b56e0b1932309ebd519253e11b1  xgboost_r_gpu_linux.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_3.0.0.tar.gz: Download

Source tarball

v2.1.4: 2.1.4 Patch Release

Compare Source

The 2.1.4 patch release incorporates the following fixes on top of the 2.1.3 release:

Full Changelog: dmlc/xgboost@v2.1.3...v2.1.4

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
b6ce5870d03cc1233cad5ff8460f670a2aff78625adfb578c0b9eec3b8b88406  xgboost-2.1.4.tar.gz
9780ba8314824eac7b8565cc2af8ea692fd4898712052a49132ac3fdf7c0ab2b  xgboost_r_gpu_linux_2.1.4.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_2.1.4.tar.gz: Download

Source tarball

v2.1.3: 2.1.3 Patch release

Compare Source

The 2.1.3 patch release makes the following bug fixes:

  • [pyspark] Support large model size (#​10984).
  • Fix rng for the column sampler (#​10998).
  • Handle cudf.pandas proxy objects properly (#​11014).
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
90b1b7b770803299b337dd9b9206760d9c16f418403c77acce74b350c6427667  xgboost-2.1.3.tar.gz
96b41da84769920408c5733d05fa2d56b53feeefd209e3d96842cf9c266e27ea  xgboost_r_gpu_linux_2.1.3.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_2.1.3.tar.gz: Download

Source tarball

v2.1.2: 2.1.2 Patch Release

Compare Source

The 2.1.2 patch release makes the following bug fixes:

  • Clean up and modernize release-artifacts.py (#​10818)
  • Fix ellpack categorical feature with missing values. (#​10906)
  • Fix unbiased ltr with training continuation. (#​10908)
  • Fix potential race in feature constraint. (#​10719)
  • Fix boolean array for arrow-backed DF. (#​10527)
  • Ensure that pip check does not fail due to a bad platform tag (#​10755)
  • Check cub errors (#​10721)
  • Limit the maximum number of threads. (#​10872)
  • Fixes for large size clusters. (#​10880)
  • POSIX compliant poll.h and mmap (#​10767)
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
a84fc7d9846c24659a2ad16788a7eefa9640b19eea9bbc65f30e0a9d53c52453  xgboost-2.1.2.tar.gz
999eff38533ea79ab3a1f0da524c54f6d0abd2ef220b6dbb9ba1331703e898bc  xgboost_r_gpu_linux_2.1.2.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_2.1.2.tar.gz: Download

Source tarball

v2.1.1: 2.1.1 Patch Release

Compare Source

The 2.1.1 patch release make the following bug fixes:

In addition, it contains several enhancements:

Full Changelog: dmlc/xgboost@v2.1.0...v2.1.1

Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
eddbc5200b7c5210f2b8974b9d2a0328a30753416bfb81fdaf5040f4f7abb222  xgboost-2.1.1.tar.gz
3ba5a6e0c609bd5cc0a667d83c57457c06778bece50863e58c8bc1b4eb415fc6  xgboost_r_gpu_linux_2.1.1.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_2.1.1.tar.gz: Download

Source tarball

v2.1.0: Release 2.1.0 stable

Compare Source

2.1.0 (2024 Jun 20)

We are thrilled to announce the XGBoost 2.1 release. This note will start by summarizing some general changes and then highlighting specific package updates. As we are working on a new R interface, this release will not include the R package. We'll update the R package as soon as it's ready. Stay tuned!

Networking Improvements

An important ongoing work for XGBoost, which we've been collaborating on, is to support resilience for improved scaling and federated learning on various platforms. The existing networking library in XGBoost, adopted from the RABIT project, can no longer meet the feature demand. We've revamped the RABIT module in this release to pave the way for future development. The choice of using an in-house version instead of an existing library is due to the active development status with frequent new feature requests like loading extra plugins for federated learning. The new implementation features:

  • Both CPU and GPU communication (based on NCCL).
  • A reusable tracker for both the Python package and JVM packages. With the new release, the JVM packages no longer require Python as a runtime dependency.
  • Supports federated communication patterns for both CPU and GPU.
  • Supports timeout. The high-level interface parameter is currently hard-coded to 30 minutes, which we plan to improve.
  • Supports significantly more data types.
  • Supports thread-based workers.
  • Improved handling for worker errors, including better error messages when one of the peers dies during training.
  • Work with IPv6. Currently, this is only supported by the dask interface.
  • Built-in support for various operations like broadcast, allgatherV, allreduce, etc.

Related PRs (#​9597, #​9576, #​9523, #​9524, #​9593, #​9596, #​9661, #​10319, #​10152, #​10125, #​10332, #​10306, #​10208, #​10203, #​10199, #​9784, #​9777, #​9773, #​9772, #​9759, #​9745, #​9695, #​9738, #​9732, #​9726, #​9688, #​9681, #​9679, #​9659, #​9650, #​9644, #​9649, #​9917, #​9990, #​10313, #​10315, #​10112, #​9531, #​10075, #​9805, #​10198, #​10414).

The existing option of using MPI in RABIT is removed in the release. (#​9525)

NCCL is now fetched from PyPI.

In the previous version, XGBoost statically linked NCCL, which significantly increased the binary size and led to hitting the PyPI repository limit. With the new release, we have made a significant improvement. The new release can now dynamically load NCCL from an external source, reducing the binary size. For the PyPI package, the nvidia-nccl-cu12 package will be fetched during installation. With more downstream packages reusing NCCL, we expect the user environments to be slimmer in the future as well. (#​9796, #​9804, #​10447)

Parts of the Python package now require glibc 2.28+

Starting from 2.1.0, XGBoost Python package will be distributed in two variants:

  • manylinux_2_28: for recent Linux distros with glibc 2.28 or newer. This variant comes with all features enabled.
  • manylinux2014: for old Linux distros with glibc older than 2.28. This variant does not support GPU algorithms or federated learning.

The pip package manager will automatically choose the correct variant depending on your system.

Starting from May 31, 2025, we will stop distributing the manylinux2014 variant and exclusively distribute the manylinux_2_28 variant. We made this decision so that our CI/CD pipeline won't have depend on software components that reached end-of-life (such as CentOS 7). We strongly encourage everyone to migrate to recent Linux distros in order to use future versions of XGBoost.

Note. If you want to use GPU algorithms or federated learning on an older Linux distro, you have two alternatives:

  1. Upgrade to a recent Linux distro with glibc 2.28+. OR
  2. Build XGBoost from the source.
Multi-output

We continue the work on multi-target and vector leaf in this release:

  • Revise the support for custom objectives with a new API, XGBoosterTrainOneIter. This new function supports strided matrices and CUDA inputs. In addition, custom objectives now return the correct shape for prediction. (#​9508)
  • The hinge objective now supports multi-target regression (#​9850)
  • Fix the gain calculation with vector leaf (#​9978)
  • Support graphviz plot for multi-target tree. (#​10093)
  • Fix multi-output with alternating strategies. (#​9933)

Please note that the feature is still in progress and not suitable for production use.

Federated Learning

Progress has been made on federated learning with improved support for column-split, including the following updates:

Ongoing work for SYCL support.

XGBoost is developing a SYCL plugin for SYCL devices, starting with the hist tree method. (#​10216, #​9800, #​10311, #​9691, #​10269, #​10251, #​10222, #​10174, #​10080, #​10057, #​10011, #​10138, #​10119, #​10045, #​9876, #​9846, #​9682) XGBoost now supports launchable inference on SYCL devices, and work on adding SYCL support for training is ongoing.

Looking ahead, we plan to complete the training in the coming releases and then focus on improving test coverage for SYCL, particularly for Python tests.

Optimizations
  • Implement column sampler in CUDA for GPU-based tree methods. This helps us get faster training time when column sampling is employed (#​9785)
  • CMake LTO and CUDA arch (#​9677)
  • Small optimization to external memory with a thread pool. This reduces the number of threads launched during iteration. (#​9605, #​10288, #​10374)
Deprecation and breaking changes

Package-specific breaking changes are outlined in respective sections. Here we list general breaking changes in this release:

  • The command line interface is deprecated due to the increasing complexity of the machine learning ecosystem. Building a machine learning model using a command shell is no longer feasible and could mislead newcomers. (#​9485)
  • Universal binary JSON is now the default format for saving models (#​9947, #​9958, #​9954, #​9955). See #​7547 for more info.
  • The XGBoosterGetModelRaw is now removed after deprecation in 1.6. (#​9617)
  • Drop support for loading remote files. Users are encouraged to use dedicated libraries to fetch remote content. (#​9504)
  • Remove the dense libsvm parser plugin. This plugin is never tested or documented (#​9799)
  • XGDMatrixSetDenseInfo and XGDMatrixSetUIntInfo are now deprecated. Use the array interface based alternatives instead.
Features

This section lists some new features that are general to all language bindings. For package-specific changes, please visit respective sections.

  • Adopt a new XGBoost logo (#​10270)
  • Now supports dataframe data format in native XGBoost. This improvement enhances performance and reduces memory usage when working with dataframe-based structures such as pandas, arrow, and R dataframe. (#​9828, #​9616, #​9905)
  • Change default metric for gamma regression to deviance. (#​9757)
  • Normalization for learning to rank is now optional with the introduction of the new lambdarank_normalization parameter. (#​10094)
  • Contribution prediction with QuantileDMatrix on CPU. (#​10043)
  • XGBoost on macos no longer bundles OpenMP runtime. Users can install the latest runtime from their dependency manager of choice. (#​10440). Along with which, JVM packages on MacoOS are now built with OpenMP support (#​10449).
Bug fixes
  • Fix training with categorical data from external memory. (#​10433)
  • Fix compilation with CTK-12. (#​10123)
  • Fix inconsistent runtime library on Windows. (#​10404)
  • Fix default metric configuration. (#​9575)
  • Fix feature names with special characters. (#​9923)
  • Fix global configuration for external memory training. (#​10173)
  • Disable column sample by node for the exact tree method. (#​10083)
  • Fix the FieldEntry constructor specialization syntax error (#​9980)
  • Fix pairwise objective with NDCG metric along with custom gain. (#​10100)
  • Fix the default value for lambdarank_pair_method. (#​10098)
  • Fix UBJSON with boolean values. No existing code is affected by this fix. (#​10054)
  • Be more lenient on floating point errors for AUC. This prevents the AUC > 1.0 error. (#​10264)
  • Check support status for categorical features. This prevents gblinear from treating categorical features as numerical. (#​9946)
Document

Here is a list of documentation changes not specific to any XGBoost package.

Python package
  • Dask
    Other than the changes in networking, we have some optimizations and document updates in dask:
  • Filter models on workers instead of clients; this prevents an OOM error on the client machine. (#​9518)
  • Users are now encouraged to use from xgboost import dask instead of import xgboost.dask to avoid drawing in unnecessary dependencies for non-dask users. (#​9742)
  • Add seed to demos. (#​10009)
  • New document for using dask XGBoost with k8s. (#​10271)
  • Workaround potentially unaligned pointer from an empty partition. (#​10418)
  • Workaround a race condition in the latest dask. (#​10419)
  • Add typing to dask demos. (#​10207)
  • PySpark
    PySpark has several new features along with some small fixes:
  • Support stage-level scheduling for training on various platforms, including yarn/k8s. (#​9519, #​10209, #​9786, #​9727)
  • Support GPU-based transform methods (#​9542)
  • Avoid expensive repartition when appropriate. (#​10408)
  • Refactor the logging and the GPU code path (#​10077, 9724)
  • Sort workers by task ID. This helps the PySpark interface obtain deterministic results. (#​10220)
  • Fix PySpark with verbosity=3. (#​10172)
  • Fix spark estimator doc. (#​10066)
  • Rework transform for improved code reusing. (#​9292)
  • Breaking changes
    For the Python package, eval_metric, early_stopping_rounds, and callbacks from now removed from the fit method in the sklearn interface. They were deprecated in 1.6. Use the parameters with the same name in constructors instead. (#​9986)

  • Features
    Following is a list of new features in the Python package:

  • Support sample weight in sklearn custom objective. (#​10050)
  • New supported data types, including cudf.pandas (#​9602), torch.Tensor (#​9971), and more scipy types (#​9881).
  • Support pandas 2.2 and numpy 2.0. (#​10266, #​9557, #​10252, #​10175)
  • Support the latest rapids including rmm. (#​10435)
  • Improved data cache option in data iterator. (#​10286)
  • Accept numpy generators as random_state (#​9743)
  • Support returning base score as intercept in the sklearn interface. (#​9486)
  • Support arrow through pandas ext types. This is built on top of the new DataFrame API in XGBoost. See general features for more info. (#​9612)
  • Handle np integer in model slice and prediction. (#​10007)
  • Improved sklearn tags support. (#​10230)
  • The base image for building Linux binary wheels is updated to rockylinux8. (#​10399)
  • Improved handling for float128. (#​10322)
  • Fixes
  • Fix DMatrix with None input. (#​10052)
  • Fix native library discovery logic. (#​9712, #​9860)
  • Fix using categorical data with the score function for the ranker. (#​9753)
  • Document
JVM package

Here is a list of JVM-specific changes. Like the PySpark package, the JVM package also gains stage-level scheduling.

  • Features and related documents
  • Bug Fixes
  • Fixes memory leak in error handling. (#​10307)
  • Fixes group col for GPU packages (#​10254)
Additional artifacts:

You can verify the downloaded packages by running the following command on your Unix shell:

echo "<hash> <artifact>" | shasum -a 256 --check
28bec8e821b1fefcea722d96add66024adba399063f723bc5c815f7af4a5f5e4  xgboost-2.1.0.tar.gz
60c715d8c97ef710185469b27f30303b6efa655600d035963f96e6acf65f4dac  xgboost_r_gpu_linux_2.1.0.tar.gz

Experimental binary packages for R with CUDA enabled

  • xgboost_r_gpu_linux_2.1.0.tar.gz: Download

Source tarball


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jul 30, 2026
@renovate

renovate Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock
Updating dependencies
Resolving dependencies...

Creating virtualenv boost-loss-0zZvGsur-py3.14 in /home/ubuntu/.cache/pypoetry/virtualenvs

The current project's Python requirement (>=3.8,<4.0) is not compatible with some of the required packages Python requirement:
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.10, so it will not be satisfied for Python >=3.8,<3.10
  - xgboost requires Python >=3.12, so it will not be satisfied for Python >=3.8,<3.12
  - xgboost requires Python >=3.12, so it will not be satisfied for Python >=3.8,<3.12

Because no versions of xgboost match >3.0.0,<3.0.1 || >3.0.1,<3.0.2 || >3.0.2,<3.0.3 || >3.0.3,<3.0.4 || >3.0.4,<3.0.5 || >3.0.5,<3.1.0 || >3.1.0,<3.1.1 || >3.1.1,<3.1.2 || >3.1.2,<3.1.3 || >3.1.3,<3.2.0 || >3.2.0,<3.3.0 || >3.3.0,<3.4.0 || >3.4.0,<4.0.0
 and xgboost (3.0.0) requires Python >=3.10, xgboost is forbidden.
And because xgboost (3.0.1) requires Python >=3.10, xgboost is forbidden.
And because xgboost (3.0.2) requires Python >=3.10
 and xgboost (3.0.3) requires Python >=3.10, xgboost is forbidden.
And because xgboost (3.0.4) requires Python >=3.10
 and xgboost (3.0.5) requires Python >=3.10, xgboost is forbidden.
And because xgboost (3.1.0) requires Python >=3.10
 and xgboost (3.1.1) requires Python >=3.10, xgboost is forbidden.
And because xgboost (3.1.2) requires Python >=3.10
 and xgboost (3.1.3) requires Python >=3.10, xgboost is forbidden.
And because xgboost (3.2.0) requires Python >=3.10
 and xgboost (3.3.0) requires Python >=3.12, xgboost is forbidden.
So, because xgboost (3.4.0) requires Python >=3.12
 and boost-loss depends on xgboost (^3.0.0), version solving failed.

  • Check your dependencies Python requirement: The Python requirement can be specified via the `python` or `markers` properties
    
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.10,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.12,<4.0"
    For xgboost, a possible solution would be to set the `python` property to ">=3.12,<4.0"

    https://python-poetry.org/docs/dependency-specification/#python-restricted-dependencies,
    https://python-poetry.org/docs/dependency-specification/#using-environment-markers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants