From 017d42c47da0e92b745ce2103f8bfc3de1fdaacc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 09:34:59 +0000 Subject: [PATCH 01/14] build(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.3.0 to 4.4.1. - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...f87e5991a6d7451dcb8d9637bfbc97413f497069) --- updated-dependencies: - dependency-name: docker/setup-buildx-action dependency-version: 4.4.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- .github/workflows/release-images.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-images.yml b/.github/workflows/release-images.yml index 3c61536..2d5d0f7 100644 --- a/.github/workflows/release-images.yml +++ b/.github/workflows/release-images.yml @@ -18,7 +18,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io @@ -63,7 +63,7 @@ jobs: tag: markdiffusion steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io From bbf0824ef75dfe628b97c9c295e259485c6cf409 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 09:34:49 +0000 Subject: [PATCH 02/14] build(deps): bump docker/build-push-action from 7.3.0 to 7.4.0 Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.3.0 to 7.4.0. - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc) --- updated-dependencies: - dependency-name: docker/build-push-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- .github/workflows/release-images.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-images.yml b/.github/workflows/release-images.yml index 2d5d0f7..3ca5227 100644 --- a/.github/workflows/release-images.yml +++ b/.github/workflows/release-images.yml @@ -36,7 +36,7 @@ jobs: TAG="$REF_NAME" echo "tags=ghcr.io/pymodel/watermark-remover:${TAG},ghcr.io/pymodel/watermark-remover:latest" >> "$GITHUB_OUTPUT" echo "version=${TAG#v}" >> "$GITHUB_OUTPUT" - - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . file: Dockerfile @@ -80,7 +80,7 @@ jobs: fi TAG="$REF_NAME" echo "tags=ghcr.io/pymodel/watermark-remover:${{ matrix.tag }}-${TAG},ghcr.io/pymodel/watermark-remover:${{ matrix.tag }}-latest" >> "$GITHUB_OUTPUT" - - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 with: context: . file: ${{ matrix.dockerfile }} From 4799812254aba08baf46e93d663f10085f8a57d4 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:52:33 +0000 Subject: [PATCH 03/14] build(deps): update ruff requirement from <1,>=0.16.6 to >=0.16.8,<1 Updates the requirements on [ruff](https://github.com/astral-sh/ruff) to permit the latest version. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](https://github.com/astral-sh/ruff/compare/0.16.6...0.16.8) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.8 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- requirements-test.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements-test.txt b/requirements-test.txt index 075297e..8b6cba9 100644 --- a/requirements-test.txt +++ b/requirements-test.txt @@ -1,6 +1,6 @@ # Test/lint dependencies for local dev and CI. pytest>=9.1.1,<10 pypdf>=6.16.2,<7 -ruff>=0.16.6,<1 +ruff>=0.16.8,<1 # OpenAPI contract validation for wm-serve (CI validates /openapi.json). openapi-spec-validator==0.9.0 From 0c97f449e9bf5e688eec73f607adcb62199f15b1 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:31 +0000 Subject: [PATCH 04/14] build(deps): bump matplotlib in /skills/remove-ai-marks/scripts Bumps [matplotlib](https://github.com/matplotlib/matplotlib) from 3.11.1 to 3.11.2. - [Release notes](https://github.com/matplotlib/matplotlib/releases) - [Commits](https://github.com/matplotlib/matplotlib/compare/v3.11.1...v3.11.2) --- updated-dependencies: - dependency-name: matplotlib dependency-version: 3.11.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-markllm.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index 55e0203..f860783 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -26,7 +26,7 @@ SentencePiece==0.2.2 nltk==3.10.3 jieba==0.42.1 tqdm==4.70.0 -matplotlib==3.11.1 +matplotlib==3.11.2 Cython==3.3.0 numpy==2.5.2 scipy==1.18.1 From 6f5e44e69fec4f858cfc0c9c79465a48b2d3c0db Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:26 +0000 Subject: [PATCH 05/14] build(deps): bump huggingface-hub in /skills/remove-ai-marks/scripts Bumps [huggingface-hub](https://github.com/huggingface/huggingface_hub) from 1.30.0 to 1.32.0. - [Release notes](https://github.com/huggingface/huggingface_hub/releases) - [Commits](https://github.com/huggingface/huggingface_hub/compare/v1.30.0...v1.32.0) --- updated-dependencies: - dependency-name: huggingface-hub dependency-version: 1.32.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-ctrlregen.txt | 2 +- skills/remove-ai-marks/scripts/requirements-markllm.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt b/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt index fade493..81f09a7 100644 --- a/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt +++ b/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt @@ -27,6 +27,6 @@ safetensors==0.8.0 # huggingface_hub must stay <=0.25.0: 0.26.0+ removed the cached_download # symbol that diffusers 0.27.2 still imports. Unpinned, pip resolves latest # (0.36.2) and the backend fails to import. -huggingface_hub==1.30.0 +huggingface_hub==1.32.0 Pillow==12.3.0 piexif==1.1.3 diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index f860783..bf631b8 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -30,5 +30,5 @@ matplotlib==3.11.2 Cython==3.3.0 numpy==2.5.2 scipy==1.18.1 -huggingface_hub==1.30.0 +huggingface_hub==1.32.0 Pillow==12.3.0 From 0305822c6dc89e4f7858c2935c60bc88892bfb65 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:52:31 +0000 Subject: [PATCH 06/14] build(deps): update pypdf requirement from <7,>=6.16.2 to >=6.19.0,<7 Updates the requirements on [pypdf](https://github.com/py-pdf/pypdf) to permit the latest version. - [Release notes](https://github.com/py-pdf/pypdf/releases) - [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md) - [Commits](https://github.com/py-pdf/pypdf/compare/6.16.2...6.19.0) --- updated-dependencies: - dependency-name: pypdf dependency-version: 6.19.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- requirements-test.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements-test.txt b/requirements-test.txt index 8b6cba9..6d5de01 100644 --- a/requirements-test.txt +++ b/requirements-test.txt @@ -1,6 +1,6 @@ # Test/lint dependencies for local dev and CI. pytest>=9.1.1,<10 -pypdf>=6.16.2,<7 -ruff>=0.16.8,<1 +pypdf>=6.19.0,<7 +ruff>=0.16.6,<1 # OpenAPI contract validation for wm-serve (CI validates /openapi.json). openapi-spec-validator==0.9.0 From c0ceb8f83646cb13e698378e2c1f225ff643002d Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:53:03 +0000 Subject: [PATCH 07/14] build(deps): update gradio requirement from <7,>=6.26.0 to >=6.28.0,<7 Updates the requirements on [gradio](https://github.com/gradio-app/gradio) to permit the latest version. - [Release notes](https://github.com/gradio-app/gradio/releases) - [Changelog](https://github.com/gradio-app/gradio/blob/main/CHANGELOG.md) - [Commits](https://github.com/gradio-app/gradio/compare/gradio@6.26.0...gradio@6.28.0) --- updated-dependencies: - dependency-name: gradio dependency-version: 6.27.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- requirements-demo.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements-demo.txt b/requirements-demo.txt index c0ca630..87c2d4e 100644 --- a/requirements-demo.txt +++ b/requirements-demo.txt @@ -1 +1 @@ -gradio>=6.26.0,<7 +gradio>=6.28.0,<7 From 7e3de2847d02853eb0960ce0ecf6a42136e7920b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:23 +0000 Subject: [PATCH 08/14] build(deps): bump transformers in /skills/remove-ai-marks/scripts Bumps [transformers](https://github.com/huggingface/transformers) from 5.16.1 to 5.17.0. - [Release notes](https://github.com/huggingface/transformers/releases) - [Commits](https://github.com/huggingface/transformers/compare/v5.16.1...v5.17.0) --- updated-dependencies: - dependency-name: transformers dependency-version: 5.17.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-ctrlregen.txt | 2 +- skills/remove-ai-marks/scripts/requirements-markllm.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt b/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt index 81f09a7..3f00a67 100644 --- a/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt +++ b/skills/remove-ai-marks/scripts/requirements-ctrlregen.txt @@ -19,7 +19,7 @@ # merge these pins into the core requirements or the Docker images, and # run a scoped pip-audit against this file if you need a report. diffusers==0.40.0 -transformers==5.16.1 +transformers==5.17.0 accelerate==1.15.0 controlnet-aux==0.0.10 color-matcher==0.6.0 diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index bf631b8..f8eabf8 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -16,7 +16,7 @@ # GPU when nvidia-smi is present), then this file's remaining pins resolve # against the already-installed torch. torch==2.13.0.* -transformers==5.16.1 +transformers==5.17.0 # transformers 5.15.0 caps tokenizers at <=0.23.0; there is no 0.23.0 # release (0.22.2 -> 0.23.1), so the highest compatible pin is 0.22.2. tokenizers==0.23.2 From bc4a41fc20c805b161856806fdb99a4f205a032c Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:28 +0000 Subject: [PATCH 09/14] build(deps): bump scikit-learn in /skills/remove-ai-marks/scripts Bumps [scikit-learn](https://github.com/scikit-learn/scikit-learn) from 1.9.0 to 1.9.1. - [Release notes](https://github.com/scikit-learn/scikit-learn/releases) - [Commits](https://github.com/scikit-learn/scikit-learn/compare/1.9.0...1.9.1) --- updated-dependencies: - dependency-name: scikit-learn dependency-version: 1.9.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt index a1bc1ba..0832c15 100644 --- a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt +++ b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt @@ -13,5 +13,5 @@ numpy==2.5.2 scipy==1.18.1 opencv-python==5.0.0.93 PyWavelets==1.9.0 -scikit-learn==1.9.0 +scikit-learn==1.9.1 Pillow==12.3.0 From 9d97cce18cfde181967388767c1ec4c9c11cc5ea Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:27 +0000 Subject: [PATCH 10/14] build(deps): bump numpy in /skills/remove-ai-marks/scripts Bumps [numpy](https://github.com/numpy/numpy) from 2.5.2 to 2.5.3. - [Release notes](https://github.com/numpy/numpy/releases) - [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst) - [Commits](https://github.com/numpy/numpy/compare/v2.5.2...v2.5.3) --- updated-dependencies: - dependency-name: numpy dependency-version: 2.5.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-markllm.txt | 2 +- skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index f8eabf8..eb1fdd9 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -28,7 +28,7 @@ jieba==0.42.1 tqdm==4.70.0 matplotlib==3.11.2 Cython==3.3.0 -numpy==2.5.2 +numpy==2.5.3 scipy==1.18.1 huggingface_hub==1.32.0 Pillow==12.3.0 diff --git a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt index 0832c15..d397455 100644 --- a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt +++ b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt @@ -9,7 +9,7 @@ # Pillow was bumped 10.4.0 -> 12.3.0 for PYSEC-2026-165/2249-2257/2874/3451-3456 # (24 known CVEs, e.g. CVE-2026-* image parsing). The pinned upstream commit # (b1108367) only uses stable Pillow APIs (Image.fromarray/open/convert). -numpy==2.5.2 +numpy==2.5.3 scipy==1.18.1 opencv-python==5.0.0.93 PyWavelets==1.9.0 From 320205aa395a78080cd9deb5f66861af25b7e79f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:18 +0000 Subject: [PATCH 11/14] build(deps): bump tqdm in /skills/remove-ai-marks/scripts Bumps [tqdm](https://github.com/tqdm/tqdm) from 4.70.0 to 4.70.1. - [Release notes](https://github.com/tqdm/tqdm/releases) - [Commits](https://github.com/tqdm/tqdm/compare/v4.70.0...v4.70.1) --- updated-dependencies: - dependency-name: tqdm dependency-version: 4.70.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-markllm.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index eb1fdd9..419a55b 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -25,8 +25,8 @@ accelerate==1.15.0 SentencePiece==0.2.2 nltk==3.10.3 jieba==0.42.1 -tqdm==4.70.0 -matplotlib==3.11.2 +tqdm==4.70.1 +matplotlib==3.11.1 Cython==3.3.0 numpy==2.5.3 scipy==1.18.1 From 85037e0a3fa3b1df372bdb5a41326cdfab3a9bee Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:57:16 +0000 Subject: [PATCH 12/14] build(deps): bump pywavelets in /skills/remove-ai-marks/scripts Bumps [pywavelets](https://github.com/PyWavelets/pywt) from 1.9.0 to 1.10.0. - [Release notes](https://github.com/PyWavelets/pywt/releases) - [Commits](https://github.com/PyWavelets/pywt/compare/v1.9.0...v1.10.0) --- updated-dependencies: - dependency-name: pywavelets dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- .../remove-ai-marks/scripts/requirements-synthid-scorer.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt index d397455..25e409d 100644 --- a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt +++ b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt @@ -12,6 +12,6 @@ numpy==2.5.3 scipy==1.18.1 opencv-python==5.0.0.93 -PyWavelets==1.9.0 -scikit-learn==1.9.1 +PyWavelets==1.10.0 +scikit-learn==1.9.0 Pillow==12.3.0 From f7b3f86b27284431b5fbf28532342ee12050ec12 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 01:58:01 +0000 Subject: [PATCH 13/14] build(deps): update torch requirement in /skills/remove-ai-marks/scripts Updates the requirements on [torch](https://github.com/pytorch/pytorch) to permit the latest version. - [Release notes](https://github.com/pytorch/pytorch/releases) - [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md) - [Commits](https://github.com/pytorch/pytorch/compare/v2.13.0-rc1...v2.14.0) --- updated-dependencies: - dependency-name: torch dependency-version: 2.14.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- skills/remove-ai-marks/scripts/requirements-markllm.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index 419a55b..4370e21 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -15,8 +15,8 @@ # pick the right index first (Dockerfile.markllm: CPU; setup_markllm.sh: # GPU when nvidia-smi is present), then this file's remaining pins resolve # against the already-installed torch. -torch==2.13.0.* -transformers==5.17.0 +torch==2.14.0.* +transformers==5.16.1 # transformers 5.15.0 caps tokenizers at <=0.23.0; there is no 0.23.0 # release (0.22.2 -> 0.23.1), so the highest compatible pin is 0.22.2. tokenizers==0.23.2 From 4e694234d0c9da96e90feeb78daf2a39d6b70549 Mon Sep 17 00:00:00 2001 From: elkaix Date: Thu, 24 Sep 2026 22:26:26 -0400 Subject: [PATCH 14/14] Finish dependency batch: ruff, matplotlib, scikit-learn; torch pin readable by dependency review torch==2.14.0 accepts the same wheels as torch==2.14.0.* (PEP 440 ignores a candidate's local label, so +cpu and +cuXXX builds still match), and dependency review can parse it; the wildcard made it flag every old torch advisory. Dockerfile.markllm's CPU torch range moves to 2.14 to match. --- Dockerfile.markllm | 2 +- requirements-test.txt | 2 +- .../remove-ai-marks/scripts/requirements-markllm.txt | 10 ++++++---- .../scripts/requirements-synthid-scorer.txt | 2 +- 4 files changed, 9 insertions(+), 7 deletions(-) diff --git a/Dockerfile.markllm b/Dockerfile.markllm index 3f6a23c..1593187 100644 --- a/Dockerfile.markllm +++ b/Dockerfile.markllm @@ -53,7 +53,7 @@ COPY skills/remove-ai-marks/scripts/common.py /app/common.py # the remaining pinned deps then resolve against it. No GPU wheel index inside # the image — CUDA users should run setup_markllm.sh on the host instead. RUN python3 -m pip install --no-cache-dir "pip==26.2.1" \ - && python3 -m pip install --no-cache-dir --index-url https://download.pytorch.org/whl/cpu "torch>=2.13,<2.14" \ + && python3 -m pip install --no-cache-dir --index-url https://download.pytorch.org/whl/cpu "torch>=2.14,<2.15" \ && python3 -m pip install --no-cache-dir -r /app/requirements-markllm.txt # Unprivileged runtime user. The harness only reads input files and writes to diff --git a/requirements-test.txt b/requirements-test.txt index 6d5de01..445bda8 100644 --- a/requirements-test.txt +++ b/requirements-test.txt @@ -1,6 +1,6 @@ # Test/lint dependencies for local dev and CI. pytest>=9.1.1,<10 pypdf>=6.19.0,<7 -ruff>=0.16.6,<1 +ruff>=0.16.8,<1 # OpenAPI contract validation for wm-serve (CI validates /openapi.json). openapi-spec-validator==0.9.0 diff --git a/skills/remove-ai-marks/scripts/requirements-markllm.txt b/skills/remove-ai-marks/scripts/requirements-markllm.txt index 4370e21..ccb76ff 100644 --- a/skills/remove-ai-marks/scripts/requirements-markllm.txt +++ b/skills/remove-ai-marks/scripts/requirements-markllm.txt @@ -10,12 +10,14 @@ # # Pillow is pinned to 12.3.0 (same as requirements-synthid-scorer.txt) for # the 24 known CVEs fixed after the upstream 9.4.0 pin. -# torch is pinned with a wildcard so a platform wheel (e.g. 2.13.0+cpu from -# the CPU index, or 2.13.0+cuXXX from a GPU index) satisfies it. Installers +# torch is pinned without a local label, so a platform wheel (e.g. 2.14.0+cpu +# from the CPU index, or 2.14.0+cuXXX from a GPU index) satisfies it (PEP 440 +# ignores the candidate's local label). No ".*" wildcard: dependency review +# cannot parse one and matches every old torch advisory against it. Installers # pick the right index first (Dockerfile.markllm: CPU; setup_markllm.sh: # GPU when nvidia-smi is present), then this file's remaining pins resolve # against the already-installed torch. -torch==2.14.0.* +torch==2.14.0 transformers==5.16.1 # transformers 5.15.0 caps tokenizers at <=0.23.0; there is no 0.23.0 # release (0.22.2 -> 0.23.1), so the highest compatible pin is 0.22.2. @@ -26,7 +28,7 @@ SentencePiece==0.2.2 nltk==3.10.3 jieba==0.42.1 tqdm==4.70.1 -matplotlib==3.11.1 +matplotlib==3.11.2 Cython==3.3.0 numpy==2.5.3 scipy==1.18.1 diff --git a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt index 25e409d..40608f9 100644 --- a/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt +++ b/skills/remove-ai-marks/scripts/requirements-synthid-scorer.txt @@ -13,5 +13,5 @@ numpy==2.5.3 scipy==1.18.1 opencv-python==5.0.0.93 PyWavelets==1.10.0 -scikit-learn==1.9.0 +scikit-learn==1.9.1 Pillow==12.3.0