diff --git a/.github/workflows/release-images.yml b/.github/workflows/release-images.yml index 3c61536..3ca5227 100644 --- a/.github/workflows/release-images.yml +++ b/.github/workflows/release-images.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io @@ -36,7 +36,7 @@ jobs: TAG="$REF_NAME" echo "tags=ghcr.io/pymodel/watermark-remover:${TAG},ghcr.io/pymodel/watermark-remover:latest" >> "$GITHUB_OUTPUT" echo "version=${TAG#v}" >> "$GITHUB_OUTPUT" - - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . file: Dockerfile @@ -63,7 +63,7 @@ jobs: tag: markdiffusion steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io @@ -80,7 +80,7 @@ jobs: fi TAG="$REF_NAME" echo "tags=ghcr.io/pymodel/watermark-remover:${{ matrix.tag }}-${TAG},ghcr.io/pymodel/watermark-remover:${{ matrix.tag }}-latest" >> "$GITHUB_OUTPUT" - - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . file: ${{ matrix.dockerfile }} diff --git a/Dockerfile.markllm b/Dockerfile.markllm index 3f6a23c..1593187 100644 --- a/Dockerfile.markllm +++ b/Dockerfile.markllm @@ -53,7 +53,7 @@ COPY skills/remove-ai-marks/scripts/common.py /app/common.py # the remaining pinned deps then resolve against it. No GPU wheel index inside # the image — CUDA users should run setup_markllm.sh on the host instead. RUN python3 -m pip install --no-cache-dir "pip==26.2.1" \ - && python3 -m pip install --no-cache-dir --index-url https://download.pytorch.org/whl/cpu "torch>=2.13,<2.14" \ + && python3 -m pip install --no-cache-dir --index-url https://download.pytorch.org/whl/cpu "torch>=2.14,<2.15" \ && python3 -m pip install --no-cache-dir -r /app/requirements-markllm.txt # Unprivileged runtime user. The harness only reads input files and writes to diff --git a/requirements-demo.txt b/requirements-demo.txt index c0ca630..87c2d4e 100644 --- a/requirements-demo.txt +++ b/requirements-demo.txt @@ -1 +1 @@ -gradio>=6.26.0,<7 +gradio>=6.28.0,<7 diff --git a/requirements-test.txt b/requirements-test.txt index 075297e..445bda8 100644 --- a/requirements-test.txt +++ b/requirements-test.txt @@ -1,6 +1,6 @@ # Test/lint dependencies for local dev and CI. pytest>=9.1.1,<10 -pypdf>=6.16.2,<7 -ruff>=0.16.6,<1 +pypdf>=6.19.0,<7 +ruff>=0.16.8,<1 # OpenAPI contract validation for wm-serve (CI validates /openapi.json). openapi-spec-validator==0.9.0 diff --git a/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt b/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt index fade493..3f00a67 100644 --- a/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt +++ b/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt @@ -19,7 +19,7 @@ # merge these pins into the core requirements or the Docker images, and # run a scoped pip-audit against this file if you need a report. diffusers==0.40.0 -transformers==5.16.1 +transformers==5.17.0 accelerate==1.15.0 controlnet-aux==0.0.10 color-matcher==0.6.0 @@ -27,6 +27,6 @@ safetensors==0.8.0 # huggingface_hub must stay <=0.25.0: 0.26.0+ removed the cached_download # symbol that diffusers 0.27.2 still imports. Unpinned, pip resolves latest # (0.36.2) and the backend fails to import. -huggingface_hub==1.30.0 +huggingface_hub==1.32.0 Pillow==12.3.0 piexif==1.1.3 diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index 55e0203..ccb76ff 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -10,12 +10,14 @@ # # Pillow is pinned to 12.3.0 (same as requirements-synthid-scorer.txt) for # the 24 known CVEs fixed after the upstream 9.4.0 pin. -# torch is pinned with a wildcard so a platform wheel (e.g. 2.13.0+cpu from -# the CPU index, or 2.13.0+cuXXX from a GPU index) satisfies it. Installers +# torch is pinned without a local label, so a platform wheel (e.g. 2.14.0+cpu +# from the CPU index, or 2.14.0+cuXXX from a GPU index) satisfies it (PEP 440 +# ignores the candidate's local label). No ".*" wildcard: dependency review +# cannot parse one and matches every old torch advisory against it. Installers # pick the right index first (Dockerfile.markllm: CPU; setup_markllm.sh: # GPU when nvidia-smi is present), then this file's remaining pins resolve # against the already-installed torch. -torch==2.13.0.* +torch==2.14.0 transformers==5.16.1 # transformers 5.15.0 caps tokenizers at <=0.23.0; there is no 0.23.0 # release (0.22.2 -> 0.23.1), so the highest compatible pin is 0.22.2. @@ -25,10 +27,10 @@ accelerate==1.15.0 SentencePiece==0.2.2 nltk==3.10.3 jieba==0.42.1 -tqdm==4.70.0 -matplotlib==3.11.1 +tqdm==4.70.1 +matplotlib==3.11.2 Cython==3.3.0 -numpy==2.5.2 +numpy==2.5.3 scipy==1.18.1 -huggingface_hub==1.30.0 +huggingface_hub==1.32.0 Pillow==12.3.0 diff --git a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt index a1bc1ba..40608f9 100644 --- a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt +++ b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt @@ -9,9 +9,9 @@ # Pillow was bumped 10.4.0 -> 12.3.0 for PYSEC-2026-165/2249-2257/2874/3451-3456 # (24 known CVEs, e.g. CVE-2026-* image parsing). The pinned upstream commit # (b1108367) only uses stable Pillow APIs (Image.fromarray/open/convert). -numpy==2.5.2 +numpy==2.5.3 scipy==1.18.1 opencv-python==5.0.0.93 -PyWavelets==1.9.0 -scikit-learn==1.9.0 +PyWavelets==1.10.0 +scikit-learn==1.9.1 Pillow==12.3.0