[Snyk] Upgrade onnxruntime-node from 1.14.0 to 1.23.2#10146
Closed
[Snyk] Upgrade onnxruntime-node from 1.14.0 to 1.23.2#10146
Conversation
Snyk has created this PR to upgrade onnxruntime-node from 1.14.0 to 1.23.2. See this package in npm: onnxruntime-node See this project in Snyk: https://app.snyk.io/org/continue-dev-inc.-default/project/27a1a273-81ac-40fc-9af7-ac9cf0349aff?utm_source=github&utm_medium=referral&page=upgrade-pr
|
|
✅ Review Complete Code Review Summary |
…nyk-upgrade-3095d9fd5e6b0170e79d83641d320c82
Collaborator
|
this moves the onnxruntime node binary and messes stuff up. I believe this only effects deprecated features at this point. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade onnxruntime-node from 1.14.0 to 1.23.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 55 versions ahead of your current version.
The recommended version was released 3 months ago.
Issues fixed by the recommended upgrade:
SNYK-JS-FASTXMLPARSER-15155603
SNYK-JS-BABELHELPERS-9397697
SNYK-JS-INFLIGHT-6095116
SNYK-JS-JSYAML-13961110
Release notes
Package name: onnxruntime-node
ORT 1.23.2 cherrypick 1 (#26368)
Adds the following commits to the release-1.23.2 branch for ORT 1.23.2:
- [TensorRT] Fix DDS output bug during engine update
- PR: #26272
- commit id: 00e85dd
- Fix shape inference failure with in-memory external data
- PR: #26263
- commit id: d955476
- [CUDA] replace 90a-virtual by 90-virtual for forward compatible
- PR: #26230
- commit id: b58911f
- [QNN-EP] Fix logic flow bug
- PR: #26148
- commit id: b282379
- Internal Dupe of #25255 - [MLAS] Optimize MlasConv using thread
partition opt
- PR: #26103
- commit id: 7362518
- Update qMoE spec to support block quantization
- PR: #25641
- commit id: 7a8ffa8
- [VitisAI] add new api to VitisAI to save graph as a string
- PR: #25602
- commit id: 3361d72
- [[Build] Lock torch, onnxscript and onnx-ir versions to latest]
- PR: #26315
- commit id: ea69c4d
---------
Co-authored-by: Hariharan Seshadri <shariharan91@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@ users.noreply.github.com>
Co-authored-by: Edward Chen <18449977+edgchen1@users.noreply.github.com>
Co-authored-by: Yateng Hong <toothache9010@gmail.com>
Co-authored-by: Changming Sun <chasun@microsoft.com>
Co-authored-by: Dmitri Smirnov <dmitrism@microsoft.com>
Co-authored-by: Tianlei Wu <tlwu@microsoft.com>
Co-authored-by: quic-calvnguy <quic_calvnguy@quicinc.com>
Co-authored-by: quic_calvnguy <quic_calvnguy@quic_inc.com>
Co-authored-by: yifei410 <31260809+yifei410@users.noreply.github.com>
Co-authored-by: yifei <y.zhou@xilinx.com>
Announcements
This release introduces Execution Provider (EP) Plugin API, which is a new infrastructure for building plugin-based EPs. (#24887 , #25137, #25124, #25147, #25127, #25159, #25191, #2524)
This release introduces the ability to dynamically download and install execution providers. This feature is exclusively available in the WinML build and requires Windows 11 version 25H2 or later. To leverage this new capability, C/C++/C# users should use the builds distributed through the Windows App SDK, and Python users should install the onnxruntime-winml package(will be published soon). We encourage users who can upgrade to the latest Windows 11 to utilize the WinML build to take advantage of this enhancement.
Upcoming Changes
Execution & Core Optimizations
Shutdown logic on Windows is simplified
Now on Windows some global object will be not destroyed if we detect that the process is being shutting down(#24891) . It will not cause memory leak as when a process ends all the memory will be returned to the operating system. This change can reduce the chance of having crashes on process exit.
AutoEP/Device Management
Now ONNX Runtime has the ability to automatically discovery computing devices and select the best EPs to download and register. The EP downloading feature currently only works on Windows 11 version 25H2 or later.
Execution Provider (EP) Updates
ROCM EP was removed from the source tree. Users are recommended to use Migraphx or Vitis AI EPs from AMD.
A new EP, Nvidia TensorRT RTX, was added.
Web
EMDSK is upgraded from 4.0.4 to 4.0.8
WebGPU EP
Added WGSL template support.
QNN EP
SDK Update: Added support for QNN SDK 2.37.
KleidiAI
Enhanced performance for SGEMM, IGEMM, and Dynamic Quantized MatMul operations, especially for Conv2D operators on hardware that supports SME2 (Scalable Matrix Extension v2).
Known Problems
Contributions
Contributors to ONNX Runtime include members across teams at Microsoft, along with our community members:
@ 1duo, @ Akupadhye, @ amarin16, @ AndreyOrb, @ ankan-ban, @ ankitm3k, @ anujj, @ aparmp-quic, @ arnej27959, @ bachelor-dou, @ benjamin-hodgson, @ Bonoy0328, @ chenweng-quic, @ chuteng-quic, @ clementperon, @ co63oc, @ daijh, @ damdoo01-arm, @ danyue333, @ fanchenkong1, @ gedoensmax, @ genarks, @ gnedanur, @ Honry, @ huaychou, @ ianfhunter, @ ishwar-raut1, @ jing-bao, @ joeyearsley, @ johnpaultaken, @ jordanozang, @ JulienMaille, @ keshavv27, @ kevinch-nv, @ khoover, @ krahenbuhl, @ kuanyul-quic, @ mauriciocm9, @ mc-nv, @ minfhong-quic, @ mingyueliuh, @ MQ-mengqing, @ NingW101, @ notken12, @ omarhass47, @ peishenyan, @ pkubaj, @ qc-tbhardwa, @ qti-jkilpatrick, @ qti-yuduo, @ quic-ankus, @ quic-ashigarg, @ quic-ashwshan, @ quic-calvnguy, @ quic-hungjuiw, @ quic-tirupath, @ qwu16, @ ranjitshs, @ saurabhkale17, @ schuermans-slx, @ sfatimar, @ stefantalpalaru, @ sunnyshu-intel, @ TedThemistokleous, @ thevishalagarwal, @ toothache, @ umangb-09, @ vatlark, @ VishalX, @ wcy123, @ xhcao, @ xuke537, @ zhaoxul-qti
Announcements
GenAI & Advanced Model Features
Execution & Core Optimizations
Core
Execution Provider (EP) Updates
CPU EP/MLAS
MatMulNBits, enabling matrix multiplication with weights quantized to 8 bits.OpenVINO EP
QNN EP
TensorRT EP
NV TensorRT RTX EP
CUDA EP
MatMulNBits.VitisAI EP
Infrastructure & Build Improvements
Build System & Packages
Dependencies / Version Updates
Web
Mobile
Contributions
Contributors to ONNX Runtime include members across teams at Microsoft, along with our community members:
Yulong Wang, Jian Chen, Changming Sun, Satya Kumar Jandhyala, Hector Li, Prathik Rao, Adrian Lizarraga, Jiajia Qin, Scott McKay, Jie Chen, Tianlei Wu, Edward Chen, Wanming Lin, xhcao, vraspar, Dmitri Smirnov, Jing Fang, Yifan Li, Caroline Zhu, Jianhui Dai, Chi Lo, Guenther Schmuelling, Ryan Hill, Sushanth Rajasankar, Yi-Hong Lyu, Ankit Maheshkar, Artur Wojcik, Baiju Meswani, David Fan, Enrico Galli, Hans, Jambay Kinley, John Paul, Peishen Yan, Yateng Hong, amarin16, chuteng-quic, kunal-vaishnavi, quic-hungjuiw, Alessio Soldano, Andreas Hussing, Ashish Garg, Ashwath Shankarnarayan, Chengdong Liang, Clément Péron, Erick Muñoz, Fanchen Kong, George Wu, Haik Silm, Jagadish Krishnamoorthy, Justin Chu, Karim Vadsariya, Kevin Chen, Mark Schofield, Masaya, Kato, Michael Tyler, Nenad Banfic, Ningxin Hu, Praveen G, Preetha Veeramalai, Ranjit Ranjan, Seungtaek Kim, Ti-Tai Wang, Xiaofei Han, Yueqing Zhang, co63oc, derdeljan-msft, genmingz@AMD, jiangzhaoming, jing-bao, kuanyul-quic, liqun Fu, minfhong-quic, mingyue, quic-tirupath, quic-zhaoxul, saurabh, selenayang888, sfatimar, sheetalarkadam, virajwad, zz002, Ștefan Talpalaru
What's new?
Announcements
GenAI & Advanced Model Features
Enhanced Decoding & Pipeline Support
API & Compatibility Updates
Bug Fixes for Model Output
top_kon CPU.Execution & Core Optimizations
Core Refinements
Execution Provider (EP) Updates
General
TensorRT EP Improvements
NMS,RoiAlign,NonZero) to TensorRT by default.trt_op_types_to_excludeto exclude specific ops from TensorRT assignment.CUDA EP Improvements
QNN EP Improvements
--use_qnn static_lib.DirectML EP Support & Upgrades
OpenVINO EP Improvements
SkipLayerNormalization,MatMulNBits,FusedGemm,FusedConv,EmbedLayerNormalization,BiasGelu,Attention,DynamicQuantizeMatMul,FusedMatMul,QuickGelu,SkipSimplifiedLayerNormalizationVitisAI EP Improvements
Mobile Platform Enhancements
CoreML Updates
Extensions & Tokenizer Improvements
Expanded Tokenizer Support
ChatGLM,Baichuan2,Phi-4, etc.Phi-4pre/post-processing support for text, vision, and audio.tokenizer.json.Image Codec Enhancements
ImageCodecnow links to native APIs if available; otherwise, falls back to built-in libraries.Unified Tokenizer API
Infrastructure & Build Improvements
Runtime Requirements
All the prebuilt Windows packages now require VC++ Runtime version >= 14.40(instead of 14.38). If your VC++ runtime version is lower than that, you may see a crash when ONNX Runtime was initializing. See https://github.com/microsoft/STL/wiki/Changelog#vs-2022-1710 for more details.
Updated minimum iOS and Android SDK requirements to align with React Native 0.76:
All macOS packages now require macOS version >= 13.3.
CMake File Changes
CMake Version: Increased the minimum required CMake version from 3.26 to 3.28. Added support for CMake 4.0.
Python Version: Increased the minimum required Python version from 3.8 to 3.10 for building ONNX Runtime from source.
Improved VCPKG support
Added the following cmake options for WebGPU EP
Added cmake option onnxruntime_BUILD_QNN_EP_STATIC_LIB for building with QNN EP as a static library.
Removed cmake option onnxruntime_USE_PREINSTALLED_EIGEN.
Fixed a build issue with Visual Studio 2022 17.3 (#23911)
Modernized Build Tools
onnxruntime_USE_CUDA_NHWC_OPSby default for CUDA builds.Dependency Cleanup
nsyncfrom dependencies.Others
Updated Node.js installation script to support network proxy usage (#23231)
Web
Contributors
Contributors to ONNX Runtime include members across teams at Microsoft, along with our community members:
Changming Sun, Yulong Wang, Tianlei Wu, Jian Chen, Wanming Lin, Adrian Lizarraga, Hector Li, Jiajia Qin, Yifan Li, Edward Chen, Prathik Rao, Jing Fang, shiyi, Vincent Wang, Yi Zhang, Dmitri Smirnov, Satya Kumar Jandhyala, Caroline Zhu, Chi Lo, Justin Chu, Scott McKay, Enrico Galli, Kyle, Ted Themistokleous, dtang317, wejoncy, Bin Miao, Jambay Kinley, Sushanth Rajasankar, Yueqing Zhang, amancini-N, ivberg, kunal-vaishnavi, liqun Fu, Corentin Maravat, Peishen Yan, Preetha Veeramalai, Ranjit Ranjan, Xavier Dupré, amarin16, jzm-intel, kailums, xhcao, A-Satti, Aleksei Nikiforov, Ankit Maheshkar, Javier Martinez, Jianhui Dai, Jie Chen, Jon Campbell, Karim Vadsariya, Michael Tyler, PARK DongHa, Patrice Vignola, Pranav Sharma, Sam Webster, Sophie Schoenmeyer, Ti-Tai Wang, Xu Xing, Yi-Hong Lyu, genmingz@AMD, junchao-zhao, sheetalarkadam, sushraja-msft, Akshay Sonawane, Alexis Tsogias, Ashrit Shetty, Bilyana Indzheva, Chen Feiyue, Christian Larson, David Fan, David Hotham, Dmitry Deshevoy, Frank Dong, Gavin Kinsey, George Wu, Grégoire, Guenther Schmuelling, Indy Zhu, Jean-Michaël Celerier, Jeff Daily, Joshua Lochner, Kee, Malik Shahzad Muzaffar, Matthieu Darbois, Michael Cho, Michael Sharp, Misha Chornyi, Po-Wei (Vincent), Sevag H, Takeshi Watanabe, Wu, Junze, Xiang Zhang, Xiaoyu, Xinpeng Dou, Xinya Zhang, Yang Gu, Yateng Hong, mindest, mingyue, raoanag, saurabh, shaoboyan091, sstamenk, tianf-fff, wonchung-microsoft, xieofxie, zz002
What's new?
Python Quantization Tool
CPU EP
QNN EP
TensorRT EP
Packaging
Contributions
Big thank you to the release manager View all
Summary by cubic
Upgraded onnxruntime-node from 1.14.0 to 1.23.2 to resolve Snyk-reported vulnerabilities and pick up performance and stability improvements in ONNX Runtime. Dependency-only change (core/package.json and package-lock.json); no app code changes.
Written for commit 76844a0. Summary will update on new commits.