Bump Microsoft.ML.OnnxRuntime from 1.29.0 to 1.30.0 - #1417
dependabot[bot] wants to merge 1 commit into
Conversation
--- updated-dependencies: - dependency-name: Microsoft.ML.OnnxRuntime dependency-version: 1.30.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 14, 2026, 2:14 AM ET / 06:14 UTC. ClawSweeper reviewWhat this changesUpdates the shared library’s Microsoft.ML.OnnxRuntime dependency from 1.29.0 to 1.30.0 for the bundled native speech stack. Merge readiness✅ Ready for maintainer review This focused dependency update remains useful: current main and the latest release still use 1.29.0. No introduced correctness or security defect was identified. Priority: P3 Review scores
Verification
How this fits togetherONNX Runtime supplies model inference and native libraries used by the Windows companion’s speech components. The shared library retains a Silero speech detector, while current microphone capture uses managed energy detection; native packaging also supports Piper speech output. flowchart LR
A[NuGet dependency version] --> B[Shared library build]
B --> C[ONNX managed and native libraries]
C --> D[Shared model inference]
C --> E[Native speech stack]
E --> F[Piper speech output]
C --> G[Windows load and packaging checks]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep the update confined to the existing package reference and retain the established Windows native-loading and release-packaging safeguards. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates a dependency and does not report a specific application bug. Is this the best way to solve the issue? Yes: changing the existing package reference is the narrowest update path, and the inspected code supplies native-loading regression checks. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against bd9ce43b4d9c. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Updated Microsoft.ML.OnnxRuntime from 1.29.0 to 1.30.0.
Release notes
Sourced from Microsoft.ML.OnnxRuntime's releases.
1.30.0
ONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU performance, adds Go bindings, and strengthens runtime reliability. These notes cover changes since ONNX Runtime 1.29.1.
Highlights
Announcements & Compatibility
-Donnxruntime_USE_FP4_QMOE=OFF(#32096, #32163).block_size=32. Set-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ONwhen building from source to retain the full kernel set, including BF16, zero-point, bias, larger-block-size, and native Hopper variants (#32324).GemmandMatMulexecution is gated on hardware acceleration. CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 (#32301, #32197).Security & Reliability
Model Loading, Memory, and Input Validation
Split,Scan,GatherND,ScatterND,SpaceToDepth/DepthToSpace,Crop,Conv,Normalizer, and pooling (#29461, #31668, #32034, #32039, #32076, #32157, #32160, #32161, #32345, #32349).BifurcationDetectorinputs, generation subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now uses dynamic shape storage (#31648, #31701, #32009, #32078, #32144).TreeEnsemblenode references and bounded subtree comparison, rejected non-finite CPURoiAligncoordinates, and requiredImageScalerbias to match the channel count (#32031, #32043, #32011, #32002).MatMulFpQ4shape inputs, and checked MLAS blockwise quantization/dequantization index ranges (#31682, #32032, #32007).GPU Bounds and Resource Lifetimes
MatMulNBits,RemovePadding,RotaryEmbedding,SparseAttention, Whisper beam search, NMS, QDQ, andGatherElements(#31643, #31994, #31995, #31996, #31998, #32014, #32029, #32030).CudaAsyncBufferstaging storage alive across CUDA graph replay (#31968, #32121).Dependencies and Tooling
js-yaml,joi,fast-uri, and the Next.js end-to-end fixture (#32397, #32486, #32488, #32505, #32508).New Features
Core APIs & Runtime
KernelContext::GetPreallocatedOutput(#29726, #32089).EngramGateandNGramHashMapping, and expanded kernel coverage for Qwen-3.5 operators (#32268, #32106).Plugin Execution Providers
... (truncated)
1.29.1
This is a patch release on top of v1.29.0, containing GroupQueryAttention capability and KV-cache layout improvements, plugin Execution Provider performance tooling updates, and targeted graph and optimizer fixes.
GroupQueryAttention
causalattribute, with explicit handling for unsupported execution paths (#31704)attention_biaswith a sliding-window KV cache, including explicit position IDs and post-eviction bias indexing (#32302)Runtime and Performance Tools
onnxruntime_perf_testto use plugin Execution Provider device allocators for generated inputs, loaded test data, and pre-allocated outputs, avoiding unnecessary per-run host/device copies (#32244)Bug Fixes and Documentation
MulandPowpatterns (#32016)Contributors
Thanks to our 7 contributors for this release!
@adrastogi, @apsonawane, @edgchen1, @javier-intel, @jnagi-intel, @tianleiwu, @Wayne-Ch
Release highlights were drafted with AI assistance and are subject to release-team review.
Full Changelog: v1.29.0...v1.29.1
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)