Skip to content

build(deps): bump onnxruntime-gpu from 1.26.0 to 1.29.0 - #273

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/onnxruntime-gpu-1.28.0
Open

build(deps): bump onnxruntime-gpu from 1.26.0 to 1.29.0#273
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/onnxruntime-gpu-1.28.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown

Bumps onnxruntime-gpu from 1.26.0 to 1.29.0.

Release notes

Sourced from onnxruntime-gpu's releases.

ONNX Runtime v1.29.0

Announcements & Breaking Changes

  • onnxruntime-web has announced the deprecation of WebGL and JSEP. The native WebGPU EP is the recommended path going forward. See the deprecation and migration plans for details (#29716, #31683).
  • POSIX telemetry is now available on Linux, macOS, Android, and iOS when ONNX Runtime is built with telemetry enabled. It does not change the public ABI, WebAssembly remains telemetry-free, and setting ORT_DISABLE_TELEMETRY=1 before initialization disables non-Windows telemetry for the process (#27379, #29872).
  • The unused internal onnxruntime/python/tools/tensorrt dashboard tooling was removed. This does not affect the TensorRT Execution Provider APIs (#29395).

Security Fixes

Path, bounds, and input validation

  • Fixed a path traversal vulnerability in TensorRT and NvTensorRTRTX engine refitting by making external-data path validation unconditional (#29396).
  • Validated the CPU MoE k attribute against the number of experts and fixed a CPU TensorScatter security issue (#29907, #29916).
  • Added missing rank, shape, and parameter validation for pooling, LSTM and DynamicQuantizeLSTM, Sampling, FeatureVectorizer, SkipLayerNorm, QLinearConv, Whisper decoding, RNN activations, GridSample, contrib Range, and CropAndResize (#29254, #29255, #29265, #29579, #29595, #29605, #29871, #31636, #31671, #31675, #31676, #31684).
  • Hardened CUDA indexing and buffer handling in GridSample, transpose, GatherBlockQuantized, InstanceNormalization, LayerNorm/RMSNorm, BeamSearch, DeformConv, AveragePool, and MaxPool (#29581, #29631, #29638, #31640, #31642, #31644, #31645, #31647, #31650).
  • Fixed packed sub-byte tensor over-copying in OrtApi::GetValue and validated DML constant tensor byte sizes (#29157, #31665).

Supply chain and tooling

  • Updated npm lockfiles, refreshed the Next.js end-to-end fixture lockfile for security advisories, and upgraded adm-zip for onnxruntime-node (#29827, #29926, #31192).

New Features

Core APIs & Runtime

  • Default intra-op and inter-op thread-pool sizes can now be set with ORT_INTRA_OP_NUM_THREADS and ORT_INTER_OP_NUM_THREADS. Explicit thread settings still take precedence, and 0 preserves machine-sized defaults (#29688).
  • Added weightless-model support for all initializer types, allowed zero-input EpContext nodes, and wired maximum-shape inference into workspace estimation (#29607, #29799, #31613).
  • Added ONNX-domain support for rotary embedding and a fused MRotaryEmbedding contrib operator for Qwen mRoPE variants (#29261, #31728).
  • Added multi-shape profiling to onnxruntime_perf_test through --data_shape, plus verbose graph-transformer tracing and broader inference-session error-path coverage (#29555, #29558, #29569, #29571).

Execution Provider ABI & Plugin EPs

  • WebGPU now supports device-free compile-only sessions for offline graph transformation (#29681).
  • Expanded CUDA plugin EP packaging and testing, including Windows ARM64 package and size options, updated package outputs, and aligned architecture selections across Python, C API, TensorRT, Node.js, and plugin packages (#31635, #31722, #31992).
  • Improved plugin lifecycle handling by unloading failed EP library loads and fixing allocator-deleter lifetime (#29634, #29770).

Execution Provider Updates

NVIDIA CUDA EP

Attention and decoding

  • Added PagedAttention with quantized KV cache, XQA decode, MLA, QK-Norm, and head-sink support (#29912).
  • Extended quantized KV-cache support with attention sinks, independent and per-channel scales, sliding-window cache support, and a fused K/V dequantization launch (#29900, #29904, #31480).
  • Added a cuDNN SDPA decode tier to the standard ONNX Attention CUDA kernel and enabled cuDNN SDPA for contrib Attention (#29715, #29717).
  • Added attention_bias support to the GroupQueryAttention unfused path and state_window support to LinearAttention and CausalConvWithState for MTP (#29525, #31157).
  • Fixed LinearAttention on GPUs with limited shared memory (#31982).

MoE and quantized GEMM

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Dependency updates python Pull requests that update python code labels Jul 27, 2026
@github-actions github-actions Bot added the onnx Changes to the ONNX plugin label Jul 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/onnxruntime-gpu-1.28.0 branch 9 times, most recently from 39f0d4f to 95281f5 Compare August 2, 2026 21:46
@dependabot
dependabot Bot force-pushed the dependabot/pip/onnxruntime-gpu-1.28.0 branch from 95281f5 to 5a01f81 Compare August 4, 2026 09:10
@github-actions github-actions Bot added the onnx-legacy Changes to the ONNX Legacy plugin label Aug 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/onnxruntime-gpu-1.28.0 branch 2 times, most recently from 46fa360 to 1e9c7f9 Compare August 16, 2026 02:04
@dependabot
dependabot Bot force-pushed the dependabot/pip/onnxruntime-gpu-1.28.0 branch 2 times, most recently from 9aac5d4 to f31fe0d Compare August 19, 2026 12:36
@dependabot dependabot Bot changed the title build(deps): bump onnxruntime-gpu from 1.26.0 to 1.28.0 build(deps): bump onnxruntime-gpu from 1.26.0 to 1.29.0 Aug 21, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/onnxruntime-gpu-1.28.0 branch 2 times, most recently from 45a92a5 to 35883d6 Compare August 21, 2026 23:41
Bumps [onnxruntime-gpu](https://github.com/microsoft/onnxruntime) from 1.26.0 to 1.29.0.
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](microsoft/onnxruntime@v1.26.0...v1.29.0)

---
updated-dependencies:
- dependency-name: onnxruntime-gpu
  dependency-version: 1.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/onnxruntime-gpu-1.28.0 branch from 35883d6 to 4d82991 Compare August 22, 2026 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates onnx Changes to the ONNX plugin onnx-legacy Changes to the ONNX Legacy plugin python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants