Releases: keras-team/keras
Release list
Keras 3.15.1
Release Notes
Keras 3.15.1 is a patch release containing important security hardening, bug fixes, and Python 3.14 compatibility improvements.
Security Fixes
- Restrict unpickling when loading IMDB and Reuters datasets — Prevents insecure deserialization (CWE-502) by replacing bare
np.load(allow_pickle=True)with a restricted unpickler that only permits numpy array reconstruction. (#23047) by @LinZiyuu - Verify all intermediary H5 groups when navigating H5 files — Manually resolves nested H5 group paths to verify group types at each step, preventing potential path traversal issues. (#23168) by @hertschuh
- Reject decompression-bomb members on the
.kerasasset extraction path — Adds per-member decompression-ratio checks before extracting.kerasarchives to disk, preventing disk-exhaustion attacks via crafted archives. (#23101) by @LinZiyuu - Restrict unpickling when loading CIFAR datasets — Replaces bare
cPickle.loadin CIFAR-10/100 batch loading with the numpy-onlyRestrictedUnpickler, blocking arbitrary code execution via pickle gadgets. (#23252) by @SABITHSAHEB
Bug Fixes
- Refactor
_load_stateto capture weight store while preserving Keras test passing — Improves model loading efficiency by capturing the weight store into a local variable, and enhances nested container detection in legacy files with isolated failure tracking. (#23226) by @buildwithsuhana - Fix TraceContext error for NNX backend — Fixes
TraceContexterrors when using JAX NNX backend with models like T5 that lack abuildmethod. Skips trace-level checks during symbolic shape inference and handles Flax 0.12 API changes. Fixes #23289. (#23326) by @divyashreepathihalli
Compatibility
- Fixes for Python 3.14 — Resolves
NotImplementedErrorboolean coercion changes in Python 3.14 and fixes dimension filtering in shape utilities. (#23259) by @hertschuh
Contributors
Thank you to all the contributors who made this release possible! 🎉
- @LinZiyuu — Security hardening for IMDB, Reuters, and
.kerasasset extraction (#23047, #23101) - @hertschuh — H5 group verification, Python 3.14 compatibility (#23168, #23259)
- @buildwithsuhana — Model loading refactor (#23226)
- @SABITHSAHEB — CIFAR dataset pickle restriction (#23252)
- @divyashreepathihalli — NNX backend TraceContext fix (#23326)
Full Changelog: v3.15.0...v3.15.1
Keras 3.12.4
Keras 3.12.4
Keras 3.12.4 is a security patch release that hardens dataset loading and model file handling against insecure deserialization and decompression-bomb attacks.
Security Fixes
- Restrict unpickling when loading IMDB and Reuters datasets — Replaces
np.load(allow_pickle=True)with a restricted unpickler that only permits numpy array reconstruction, preventing arbitrary code execution via crafted.npzfiles (CWE-502). (#23047) by @LinZiyuu - Verify all intermediary H5 groups when navigating H5 files — Manually resolves nested H5 group paths to verify group types at each step, preventing potential path traversal. (#23168) by @hertschuh
- Reject decompression-bomb members on the
.kerasasset extraction path — Adds per-member decompression-ratio checks before extracting.kerasarchives to disk, preventing disk-exhaustion attacks via crafted archives. (#23101) by @LinZiyuu - Restrict unpickling when loading CIFAR datasets — Replaces bare
cPickle.loadin CIFAR-10/100 batch loading with the numpy-onlyRestrictedUnpickler, blocking arbitrary code execution via pickle gadgets. (#23252) by @SABITHSAHEB
Contributors
Thank you to all the contributors who made this release possible! 🎉
- @LinZiyuu — Security hardening for IMDB, Reuters, and
.kerasasset extraction (#23047, #23101) - @hertschuh — H5 group verification (#23168)
- @SABITHSAHEB — CIFAR dataset pickle restriction (#23252)
Full Changelog: v3.12.3...v3.12.4
v3.12.3
Keras 3.12.3 is a security patch release that hardens model saving, loading, and deserialization against a range of attack vectors.
HDF5 Hardening
- Eject ExternalLink/SoftLink groups in KerasFileEditor (#22899)
- Prevents HDF5 external/soft links from being exploited to read arbitrary files during model editing.
- Reject ExternalLink/SoftLink on legacy
.h5dispatcher (#22900)- Extends HDF5 link rejection to the legacy
load_weightspath for.h5files.
- Extends HDF5 link rejection to the legacy
- Reject HDF5 shape-bomb datasets (#22975)
- Blocks HDF5 datasets that declare excessively large shapes to trigger out-of-memory crashes during
load_model/load_weights.
- Blocks HDF5 datasets that declare excessively large shapes to trigger out-of-memory crashes during
- Reject HDF5 virtual datasets in KerasFileEditor (#22976)
- Prevents virtual dataset references from being used to access external files.
Archive Hardening
- Reject hard-link tar members escaping extraction directory (#22973)
- Blocks tar hard links whose target resolves outside the extraction root.
- Reject decompression-bomb archive members (#23010)
- Detects and rejects
.kerasarchive members that declare far more data than is actually stored, preventing memory exhaustion.
- Detects and rejects
- Prevent symlink traversal during extraction (#23015)
- Resolves paths with
realpathto prevent symlink-based directory traversal attacks.
- Resolves paths with
- Reject npz weight bombs (#23016)
- Validates npz weight members against shape/decompression bombs before allocating memory.
- Validate DiskIOStore asset paths (#23017)
- Ensures asset paths stay within the working directory during model saving/loading.
- Use
filter="data"inTarFile.extractall(#23108)- Applies Python's built-in tar extraction safety filter on supported versions.
Deserialization Safety
- Fix insecure deserialization in dataset utilities (#23026)
- Closes an insecure deserialization path in dataset utility functions.
- Explicitly disable pickle in
np.load(#23034)- Prevents pickle execution when loading NumPy weight files.
- Make Lambda/TorchModuleWrapper
from_configfail closed (#23048)- When
safe_modeis unset,LambdaandTorchModuleWrapperdeserialization now fails closed instead of silently allowing arbitrary code execution.
- When
- Restrict reloadable APIs (#23115)
- Expands the list of APIs that should not be part of a deserialized model.
Full Changelog: v3.12.2...v3.12.3
v3.15.0
Highlights
- Keras-to-Torch Export: New
export_torchenables exporting Keras models to native PyTorchnn.Moduleformat, along with LiteRT (TFLite) export support for the PyTorch backend. - Sliding Window Attention: Added
sliding_windowparameter toMultiHeadAttentionandGroupedQueryAttentionfor efficient long-context attention. - Flash / Fused SDPA: Causal-only MHA/GQA now automatically dispatches to Flash Attention (cuDNN SDPA), and the manual attention path correctly applies causal masking.
- Multi-Optimizer Training: New
MultiOptimizersupports assigning different optimizers to sub-networks. - New Math Operations: Added
unique,pinv,matrix_rank,fabs,fmax,fmin,erfc,dsplit,percentile,nanpercentile,sobel_edges, andssim(structural similarity) tokeras.ops. - Security Hardening: Comprehensive hardening of model reloading against HDF5 exploits, tar/zip traversal attacks, insecure deserialization.
New Features and Operations
Multi-Backend Operations
- New NumPy Operations: Added
unique,fabs,fmax,fmin,dsplit,erfc,percentile,nanpercentileinkeras.ops.numpy. - New Linear Algebra Operations: Added
pinv(pseudo-inverse) andmatrix_rankinkeras.ops.linalg. - New Image Operations: Added
sobel_edgesfor edge detection andssim(structural similarity) inkeras.ops.image. - Negative Axes in Transpose:
keras.ops.transposenow supports negative axis values.
Layers and Attention
- Sliding Window Attention:
MultiHeadAttentionandGroupedQueryAttentionlayers support thesliding_windowparameter for efficient long-sequence processing. - Flash Attention Engagement: Causal-only attention in MHA/GQA now uses Flash SDPA for significant speedups.
- Fused Bidirectional LSTM/GRU: JAX backend now fuses Bidirectional LSTM into a single cuDNN call; fused bidirectional GRU added for Torch backend.
- CTC Beam Search Decoder: Added CTC beam search decoding for the Torch backend.
Training and Optimizers
- MultiOptimizer: Supports training sub-networks with different optimizers.
- SKLearn Classifier: Added
predict_probamethod toSKLearnClassifier.
Export and Deployment
- Keras-to-Torch Export: Export Keras models to native PyTorch
nn.Moduleviamodel.export(..., format="torch"). - LiteRT (TFLite) Export for PyTorch: Added LiteRT export support for models using the PyTorch backend.
- LiteRT Compatibility Fix: Fixed LiteRT export for Keras 3 + TF 2.20 + Python 3.13.
- ONNX Export: Support for dict/list inputs in Torch ONNX export; documented static input signature requirement for LiteRT PyTorch export.
Distribution and Parallelism
- ModelParallel Improvements: Defined contiguous replica-group data shard ID convention; added distribution information (
num_processes,num_model_replicas,data_shard_id). - Initializer Distribution Layout: Initializers can now handle the distribution layout directly with JAX.
- TF Dataset Distribution: Refactored TF dataset distribution with centralized sharding routing; fixed data distribution for model training in JAX.
OpenVINO Backend Support
The OpenVINO backend received continued improvements:
- New Operations: Implemented
glu,sparsemax,gaussian_blur,logdet,cholesky,lu_factor,erfc,segment_min,segment_prod,percentile,nanmedian,nanpercentile,unique,flash_attn,greedy ctc_decode,solve_triangular,compute_homography_matrix, and image transforms (affine, perspective, elastic). - Opset Upgrades: Upgraded to opset16 for select operations and full upgrade.
- Fixes: Dynamic/symbolic shape handling, mask propagation, random seed determinism, dropout during predict, Lanczos interpolation in resize, dynamic batch shape propagation, and improved efficiency using native ops.
Security
- HDF5 Hardening: Reject
ExternalLink/SoftLinkgroups, virtual datasets, and shape-bomb datasets in model loading. - Archive Hardening: Reject tar members and links escaping extraction directory, ZIP/NPZ members declaring excessive data. Validate asset paths from Orbax checkpoints.
- Deserialization Safety: Disable pickle in
np.load, fix insecure deserialization in dataset utilities, and makeLambda/TorchModuleWrapperfrom_configfail closed whensafe_modeis unset. - CI/Workflow: Fix prompt injection in issue triage workflow.
Bug Fixes and Improvements
Backend Specific Improvements
- PyTorch: Fixed
convert_to_tensorfor Python scalars,divide_no_nan()NaN gradients, BiLSTM dispatch,lstsqwith rcond,SymInt/SymFloathandling inconvert_to_tensorandslice, and median for even-length inputs. - JAX: Fused Bidirectional LSTM into cuDNN call.
- TensorFlow: Fixed depthwise/separable conv with stride and dilation. Optimized
tf.tensordotby removing redundant float casts.
Layers and Ops
- Mixed Precision Fix: Fixed float16 numerical instability in
GroupNormalizationwith small epsilon; disabled autocast for mixed precision stability. - Dense Layer OOM: Fixed GPU OOM with rank-3 input due to
BatchMatMulV2gradient materialization. - GroupQueryAttention: Fixed symbolic output shape with
return_attention_scores. - Conv Transpose: Save
output_paddinginConv1D/2D/3DTransposeget_config. - Attention Layer: Fixed stale
return_attention_scoresflag incompute_output_spec; save seed inget_config. - Ops Validation: Added comprehensive axis validation in
softmax,normalize,swapaxes,moveaxis,sort,argsort,cumsum,cumprod,take,stack,concatenate,split,diff,transpose, and more. - EinsumDense: Fixed
compute_output_shapeto work before build. - Discretization: Fixed bin boundaries calculation.
Model Saving and Loading
- Nested Sublayers: Fixed save/load for custom models/layers with sublayers in nested lists.
- Orbax: Fixed bug from Orbax's recent rename from "pytree" to "state".
- Sequential: Improved error handling for missing keys during deserialization.
- Pipeline: Validated
from_configlayers and avoid mutating input config.
Other Improvements
- Callbacks: Fixed
EarlyStopping/ReduceLROnPlateauresettingself.bestbetween fit calls; fixedTensorBoardcallback step counter never updating. - Progress Bar: Removed double averaging of metrics.
- LoRA Weights: Use float32 to avoid underflow/overflow risk.
- Tree Utilities: Optimized
tree.flattenandtree.map_structurefor common cases. - Depthwise/Separable Conv: Removed backend-specific strides + dilation_rate restriction; validated output shapes in build; transposed channels_first to NHWC on CPU.
- Regularizers: Allow plain callables as regularizers; fixed
L1L2regularizer. - Added AI Contribution Policy.
- Added
CITATION.cfffor repository citation.
New Contributors
We would like to thank our new contributors for making their first contribution to the Keras project:
- @ssam18 made their first contribution in #22617
- @chir4gm made their first contribution in #22635
- @MalyalaKarthik66 made their first contribution in #22179
- @satishkc7 made their first contribution in #22641
- @Saumay made their first contribution in #22718
- @shashaka made their first contribution in #22679
- @AdonaiVera made their first contribution in #22739
- @gaga1313 made their first contribution in #22538
- @bzantium made their first contribution in #22740
- @ShaunakDas88 made their first contribution in #22728
- @mgomes0 made their first contribution in #22689
- @pctablet505 made their first contribution in #22797
- @sharesth23 made their first contribution in #22781
- @othakkar made their first contribution in #22847
- @rahulrathnavel made their first contribution in #22835
- @codewithyug06 made their first contribution in #22444
- @JyotinderSingh made their first contribution in #22362
- @divakaivan made their first contribution in #21556
- @buildwithsuhana made their first contribution in #22903
- @LinZiyuu made their first contribution in #22899
- @jeffcarp made their first contribution in #22961
- @2HParaa made their first contribution in #22974
- @dvadym made their first contribution in #23003
- @Lawson-Darrow made their first contribution in #23004
- @ul611 made their first contribution in #22892
- @rni418 made their first contribution in #23026
- @peinguim made their first contribution in #23057
Full Changelog: v3.14.0...v3.15.0
v3.14.1
Saving & Reloading
- Harden path and link resolution when extracting files from archives (#22839)
- Fixed link resolution bug when validating links extracted from TAR archives.
- Fixed path confusion bug when validating files extracted from ZIP and TAR archives (including
.kerasfiles). - Added path validation when extracting assets from Orbax checkpoints.
- Harden H5 validation code and apply it to legacy .h5 files (#22801)
- Disallow external links and virtual datasets in H5 files.
- Also apply all the validation to the legacy .h5 file extraction.
- Improve validation and error reporting in functional model deserialization (#22800)
- Detect loops in the graph when deserializing a functional model.
- Improve error reporting for missing nodes in the graph.
Other Fixes
- Fix data sharding logic in
ModelParallel(#22179) - Fix regression with metrics passed to
compile(#22663)- Fixed a regression introduced in #22308 where
y_pred(as a list) andy_true(as a dict with keys matching Functional model output names) were not ordered identically and could be paired incorrectly.
- Fixed a regression introduced in #22308 where
- Fix regression preventing compilation with the
L1L2regularizer (#22629) - Fix test compatibility with JAX 0.10.0 (#22694)
Full Changelog: v3.14.0...v3.14.1
v3.12.2
Saving & Reloading
- Harden path and link resolution when extracting files from archives (#22194 & #22839)
- Fixed based folder used when validating files extracted from ZIP and TAR archives.
- Fixed link resolution bug when validating links extracted from TAR archives.
- Fixed path confusion bug when validating files extracted from ZIP and TAR archives (including
.kerasfiles). - Added path validation when extracting assets from Orbax checkpoints.
- Harden H5 validation code and apply it to legacy .h5 files (#22801)
- Disallow external links and virtual datasets in H5 files.
- Also apply all the validation to the legacy .h5 file extraction.
- Improve validation and error reporting in functional model deserialization (#22800)
- Detect loops in the graph when deserializing a functional model.
- Improve error reporting for missing nodes in the graph.
Other Fixes
- Fix lazy module import for
h5py- Fixed lazy module import handling for
h5pyto ensure correct and safe validation behavior when the package is lazy-loaded.
- Fixed lazy module import handling for
- Remove deprecated
openvino.runtimeimport (#21826)
What's Changed
- Patch fix 3.12.2 by @sachinprasadhs in #22850
Full Changelog: v3.12.1...v3.12.2
v3.14.0
Highlights
- Orbax Checkpoint Integration: Full support for Orbax checkpoints, including sharding, remote paths, and step recovery.
- Quantization Upgrades: Added support for Activation-aware Weight Quantization (AWQ) and Asymmetric INT4 Sub-Channel Quantization.
- Batch Renormalization in BatchNorm: Added batch renormalization feature to the
BatchRenormalizationlayer. - New Optimizer: Added
ScheduleFreeAdamWoptimizer. - Gated Attention: Introduced optional Gated Attention support in
MultiHeadAttentionandGroupedQueryAttentionlayers.
New Features and Operations
Multi-Backend Operations
- NaN-aware NumPy Operations: Added support for
nanmin,nanmax,nanmean,nanmedian,nanvar,nanstd,nanprod,nanargmin,nanargmax, andnanquantileinkeras.ops.numpy. - New Math & Linear Algebra Operators: Added
nextafter,ptp,view,sinc,fmod,i0,fliplr,flipud,rad2deg,geomspace,depth_to_space,space_to_depth, andfold.
Preprocessing and Layers
- CLAHE Layer: Added Contrast Limited Adaptive Histogram Equalization preprocessing layer.
- Adapt Support for Iterables: Preprocessing layers now support Python iterables in the
adapt()method, which allows the direct use of Grain datasets.
OpenVINO Backend Support
The OpenVINO backend received a massive update, implementing a wide array of NumPy and Neural Network operations to achieve feature parity with other backends:
- NumPy Operations:
vander,trapezoid,corrcoef,correlate,flip,diagonal,cbrt,hypot,trace,kron,argpartition,logaddexp2,ldexp,select,round,vstack,hsplit,vsplit,tile,nansum,tensordot,exp2,trunc,gcd,unravel_index,inner,cumprod,searchsorted,hanning,diagflat,norm,histogram,lcm,allclose,real,imag,isreal,kaiser,shuffle,einsum,quantile,conj,randint,in_top_k,signbit,gamma,heaviside,var,std,inv,solve,cholesky_inverse,fft,fft2,ifft2,rfft,irfft,stft,istft,scatter,binomial,unfold,QR decomposition,view, and more. - Neural Network Operations: Added support for
separable_conv,conv_transpose,adaptive_average_pool,adaptive_max_pool,RNN,LSTM, andGRU. - Control Flow Operations: Implemented
cond,scan,associative_scan,map,switch,fori_loop, andvectorized_map.
Bug Fixes and Improvements
Backend Specific Improvements
- PyTorch: Dynamic shapes support in export, device selection improvements, and bug fixes to the CuDNN based LSTM and GRU implementation.
- JAX: Improved RNG handling in
FlaxLayerandJaxLayer, variable jitting improvements, and direct JAX-to-ONNX export. - NumPy: Enabled masking support for the NumPy backend.
Other Improvements
- Fixed multiple symbolic shape bugs across layers like
Conv1DTranspose,IndexLookup, andTextVectorization. - Fixed activity regularizer normalization by batch size.
- Improved
Sequentialerror messages for incompatible layers. - Minimized memory usage issues in
sparse_categorical_crossentropy.
New Contributors
We would like to thank our new contributors for making their first contribution to the Keras project:
- @vaidik-gupta made their first contribution in #21939
- @HyperPS made their first contribution in #21880
- @calad0i made their first contribution in #21959
- @KarSri7694 made their first contribution in #21963
- @MarcosAsh made their first contribution in #21961
- @orbin123 made their first contribution in #21935
- @ayulockedin made their first contribution in #21985
- @Shi-pra-19 made their first contribution in #21987
- @mahi21tha made their first contribution in #21989
- @PES2UG23CS205 made their first contribution in #21984
- @samudraneel05 made their first contribution in #22017
- @Junead04 made their first contribution in #21784
- @nexeora made their first contribution in #22051
- @bittoby made their first contribution in #22048
- @0xManan made their first contribution in #22035
- @sharpenteeth made their first contribution in #22079
- @maitry63 made their first contribution in #22068
- @Kh9705 made their first contribution in #22110
- @timon0305 made their first contribution in #22112
- @goyaladitya05 made their first contribution in #22131
- @Sikandar1310291 made their first contribution in #22014
- @haroon10725 made their first contribution in #22159
- @andersendsa made their first contribution in #22155
- @Rahuldrabit made their first contribution in #22146
- @jerryxyj made their first contribution in #22178
- @aaishwarymishra made their first contribution in #22173
- @Sujanian1304 made their first contribution in #22236
- @CityBoy-Claude made their first contribution in #22243
- @rstar327 made their first contribution in #22252
- @daehyun99 made their first contribution in #22289
- @kysolvik made their first contribution in #22290
- @ItzCobaltboy made their first contribution in #22158
- @cpuguy96 made their first contribution in #22284
- @0xRozier made their first contribution in #22218
- @tanguyguyot made their first contribution in #22327
- @AlanPonnachan made their first contribution in #21953
- @shriramThakare3 made their first contribution in #22306
- @Eruis2579 made their first contribution in #22350
- @satheeshbhukya made their first contribution in #22388
- @sam-shubham made their first contribution in #22265
- @Passavee-Losripat made their first contribution in #22404
- @ChiragSW made their first contribution in #22439
- @rishi-sangare made their first contribution in #22407
- @Caslyn made their first contribution in #22488
- @Abineshabee made their first contribution in #22469
- @dagecko made their first contribution in #22555
Full Changelog: v3.13.2...v3.14.0
v3.13.2
Security Fixes & Hardening
This release introduces critical security hardening for model loading and saving, alongside improvements to the JAX backend metadata handling.
-
Disallow
TFSMLayerdeserialization insafe_mode(#22035)- Previously,
TFSMLayercould load external TensorFlow SavedModels during deserialization without respecting Kerassafe_mode. This could allow the execution of attacker-controlled graphs during model invocation. TFSMLayernow enforcessafe_modeby default. Deserialization viafrom_config()will raise aValueErrorunlesssafe_mode=Falseis explicitly passed orkeras.config.enable_unsafe_deserialization()is called.
- Previously,
-
Fix Denial of Service (DoS) in
KerasFileEditor(#21880)- Introduces validation for HDF5 dataset metadata to prevent "shape bomb" attacks.
- Hardens the
.kerasfile editor against malicious metadata that could cause dimension overflows or unbounded memory allocation (unbounded numpy allocation of multi-gigabyte tensors).
-
Block External Links in HDF5 files (#22057)
- Keras now explicitly disallows external links within HDF5 files during loading. This prevents potential security risks where a weight file could point to external system datasets.
- Includes improved verification for H5 Groups and Datasets to ensure they are local and valid.
Backend-specific Improvements (JAX)
- Set
mutable=Trueby default innnx_metadata(#22074)- Updated the JAX backend logic to ensure that variables are treated as mutable by default in
nnx_metadata. - This makes Keras 3.13.2 compatible with Flax 0.12.3 when the Keras NNX integration is enabled.
- Updated the JAX backend logic to ensure that variables are treated as mutable by default in
Saving & Serialization
- Improved H5IOStore Integrity (#22057)
- Refactored
H5IOStoreandShardedH5IOStoreto remove unused, unverified methods. - Fixed key-ordering logic in sharded HDF5 stores to ensure consistent state loading across different environments.
- Refactored
Contributors
We would like to thank the following contributors for their security reports and code improvements:
@0xManan, @HyperPS, @hertschuh, and @divyashreepathihalli.
Full Changelog: v3.13.1...v3.13.2
v3.12.1
Security Fixes & Hardening
This release introduces critical security hardening for model loading and saving, alongside improvements to the JAX backend metadata handling.
-
Disallow
TFSMLayerdeserialization insafe_mode(#22035)- Previously,
TFSMLayercould load external TensorFlow SavedModels during deserialization without respecting Kerassafe_mode. This could allow the execution of attacker-controlled graphs during model invocation. TFSMLayernow enforcessafe_modeby default. Deserialization viafrom_config()will raise aValueErrorunlesssafe_mode=Falseis explicitly passed orkeras.config.enable_unsafe_deserialization()is called.
- Previously,
-
Fix Denial of Service (DoS) in
KerasFileEditor(#21880)- Introduces validation for HDF5 dataset metadata to prevent "shape bomb" attacks.
- Hardens the
.kerasfile editor against malicious metadata that could cause dimension overflows or unbounded memory allocation (unbounded numpy allocation of multi-gigabyte tensors).
-
Block External Links in HDF5 files (#22057)
- Keras now explicitly disallows external links within HDF5 files during loading. This prevents potential security risks where a weight file could point to external system datasets.
- Includes improved verification for H5 Groups and Datasets to ensure they are local and valid.
Saving & Serialization
- Improved H5IOStore Integrity (#22057)
- Refactored
H5IOStoreandShardedH5IOStoreto remove unused, unverified methods. - Fixed key-ordering logic in sharded HDF5 stores to ensure consistent state loading across different environments.
- Refactored
Acknowledgments
Special thanks to the security researchers and contributors who reported these vulnerabilities and helped implement the fixes: @0xManan, @HyperPS, and @hertschuh.
Full Changelog: v3.12.0...v3.12.1
v3.13.1
Bug Fixes & Improvements
- General
- Removed a persistent warning triggered during
import keraswhen using NumPy 2.0 or higher. (#21949)
- Removed a persistent warning triggered during
- Backends
- JAX: Fixed an issue where CUDNN flash attention was broken when using JAX versions greater than 0.6.2. (#21970)
- Export & Serialization
- Resolved a regression in the export pipeline that incorrectly forced batch sizes to be dynamic. The export process now correctly respects static batch sizes when defined. (#21944)
Full Changelog: v3.13.0...v3.13.1