Skip to content

feat: promote dev to main (v0.2.1-beta) - #5

Merged
n24q02m merged 5 commits into
mainfrom
promote/dev-to-main
Feb 14, 2026
Merged

feat: promote dev to main (v0.2.1-beta)#5
n24q02m merged 5 commits into
mainfrom
promote/dev-to-main

Conversation

@n24q02m

@n24q02m n24q02m commented Feb 14, 2026

Copy link
Copy Markdown
Owner

Promote dev to main

Automated merge of dev into main with conflicts auto-resolved.

Pre-checks passed:

  • CI workflow passed on dev
  • CD workflow passed on dev

Latest beta version: v0.2.1-beta

n24q02m and others added 4 commits February 14, 2026 14:19
- Add Q4F16 ONNX model variant for Embedding and Reranker
- Add GGUF (llama-cpp) backend for Embedding and Reranker
- Add float16-to-float32 cast after ONNX inference for Q4F16 outputs
- Add llama-cpp-python as optional dependency
- Register Q4F16 and GGUF variants in model descriptions
- Point GGUF model sources to n24q02m/*-GGUF repos instead of *-ONNX
- Update model_file paths (root level, no gguf/ prefix)
@github-actions

github-actions Bot commented Feb 14, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/diskcache 5.6.3 UnknownUnknown
pip/jinja2 3.1.6 🟢 5.3
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 0Found 1/18 approved changesets -- score normalized to 0
Maintained⚠️ 10 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 1
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Binary-Artifacts🟢 10no binaries found in the repo
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Packaging🟢 10packaging workflow detected
Fuzzing🟢 10project is fuzzed
Signed-Releases🟢 104 out of the last 4 releases have a total of 4 signed artifacts.
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Security-Policy🟢 9security policy file detected
Vulnerabilities⚠️ 014 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
pip/llama-cpp-python 0.3.16 UnknownUnknown
pip/markupsafe 3.0.3 🟢 5.3
Details
CheckScoreReason
Code-Review⚠️ 1Found 3/22 approved changesets -- score normalized to 1
Maintained⚠️ 00 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 9dependency not pinned by hash detected -- score normalized to 9
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Packaging🟢 10packaging workflow detected
Security-Policy🟢 9security policy file detected
Vulnerabilities⚠️ 19 existing vulnerabilities detected
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases🟢 84 out of the last 5 releases have a total of 4 signed artifacts.
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • uv.lock

@n24q02m
n24q02m merged commit 8d8dbc1 into main Feb 14, 2026
13 checks passed
@n24q02m n24q02m mentioned this pull request Feb 14, 2026
@n24q02m
n24q02m deleted the promote/dev-to-main branch February 14, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant