You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Document the generated CUDA dependency workflow and provide a shared installer path so users can select CPU, CUDA 12.8, or CUDA 13.0 with the required indexes and constraints.
Signed-off-by: Aaron Gonzales <aagonzales@nvidia.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
- CUDA/runtime extras: `cuda_deps.toml` is the source of truth. `pyproject.toml` is generated from it.
495
+
- Security floors: `[tool.uv] constraint-dependencies` in `pyproject.toml` is the source of truth. `constraints.txt` is generated from it and published for downstream `pip` / `uv pip` installs.
496
+
497
+
### CUDA and Accelerator Dependencies
498
+
499
+
Edit `cuda_deps.toml` for changes to the CPU, CUDA 12.8, CUDA 13.0, PyTorch, FlashInfer, or NVIDIA package matrix. Do not hand-edit the generated `cpu`, `cu128`, `cu130`, `[tool.uv.sources]`, or `[[tool.uv.index]]` sections in `pyproject.toml`.
500
+
501
+
After editing `cuda_deps.toml`, regenerate `pyproject.toml`:
502
+
503
+
```bash
504
+
uv run --script tools/gen_cuda_deps.py cuda_deps.toml --pyproject pyproject.toml
505
+
uv lock
506
+
```
507
+
508
+
Then verify the generated sections are current:
509
+
510
+
```bash
511
+
uv run --script tools/gen_cuda_deps.py cuda_deps.toml --pyproject pyproject.toml --check
512
+
uv run pytest tests/test_gen_cuda_deps.py
513
+
make lock-check
514
+
```
515
+
516
+
When adding a new CUDA extra, update all user-facing install surfaces in the same PR:
517
+
518
+
-`generated_extras` in `cuda_deps.toml`
519
+
-`install_nss.sh`
520
+
-`docs/user-guide/getting-started.md`
521
+
-`README.md`
522
+
523
+
Use dry runs to confirm the installer emits the expected command matrix:
524
+
525
+
```bash
526
+
DRY_RUN=1 CUDA=128 bash install_nss.sh
527
+
DRY_RUN=1 CUDA=130 bash install_nss.sh
528
+
DRY_RUN=1 CUDA=cpu bash install_nss.sh
529
+
```
530
+
531
+
### Security Floors and Constraints
532
+
533
+
Dependabot CVE floors are applied with `tools/patch_dependabot.py`. The script bumps direct dependencies in `pyproject.toml`, adds transitive floors to `[tool.uv] constraint-dependencies`, writes the exported `constraints.txt`, and refreshes `uv.lock`.
534
+
535
+
```bash
536
+
export GITHUB_TOKEN="$(gh auth token)"
537
+
uv run tools/patch_dependabot.py
538
+
```
539
+
540
+
The exported `constraints.txt` is intentionally not CUDA-version-specific. Runtime selection comes from the selected extra (`cpu`, `cu128`, `cu130`) and package indexes; security floors come from the shared constraints file.
541
+
542
+
If you update `[tool.uv] constraint-dependencies` by hand, regenerate `constraints.txt` before opening a PR. The simplest supported path is to run `tools/patch_dependabot.py` with a cached `dependabot.json` or an active `GITHUB_TOKEN`, then review the resulting `pyproject.toml`, `constraints.txt`, and `uv.lock` diff.
543
+
490
544
## Documentation
491
545
492
546
This project uses [MkDocs Material](https://squidfunk.github.io/mkdocs-material/) for its documentation site, hosted at <https://nvidia-nemo.github.io/Safe-Synthesizer/>.
@@ -576,7 +630,29 @@ Before contributing, run `make format` and `make check`. See `AGENTS.md` for ful
576
630
577
631
Releases are published to PyPI via the **Release NeMo Safe Synthesizer** GitHub Actions workflow. The workflow builds the wheel from a git tag, publishes to Test PyPI as a pre-flight check, publishes to the real PyPI, and creates a GitHub release.
578
632
579
-
### 1. Create and push a tag
633
+
### 1. Run dependency and install preflight
634
+
635
+
Before tagging a release, verify generated dependency artifacts and install instructions are current:
636
+
637
+
```bash
638
+
uv run --script tools/gen_cuda_deps.py cuda_deps.toml --pyproject pyproject.toml --check
639
+
uv run pytest tests/test_gen_cuda_deps.py
640
+
make lock-check
641
+
DRY_RUN=1 CUDA=128 bash install_nss.sh
642
+
DRY_RUN=1 CUDA=130 bash install_nss.sh
643
+
DRY_RUN=1 CUDA=cpu bash install_nss.sh
644
+
```
645
+
646
+
If Dependabot security floors changed since the last release, run:
647
+
648
+
```bash
649
+
export GITHUB_TOKEN="$(gh auth token)"
650
+
uv run tools/patch_dependabot.py
651
+
```
652
+
653
+
Review `pyproject.toml`, `constraints.txt`, and `uv.lock` together. The release publishes the wheel to PyPI, but downstream installers also depend on the raw `constraints.txt` and `install_nss.sh` URLs from the release branch.
654
+
655
+
### 2. Create and push a tag
580
656
581
657
Release versions follow [PEP440](https://peps.python.org/pep-0440/) with major, minor, and patch release numbers.
582
658
This project uses stable releases and release candidates only; prerelease versions append the suffix rcN (no dash, as specified by PEP440).
@@ -607,7 +683,7 @@ git tag v0.1.0rc1 <commit-sha>
607
683
git push origin <tag>
608
684
```
609
685
610
-
### 2. Monitor the workflow run
686
+
### 3. Monitor the workflow run
611
687
612
688
The [workflow](https://github.com/NVIDIA-NeMo/Safe-Synthesizer/actions/workflows/release.yml) to release is triggered automatically when a tag starting with `v` is pushed to GitHub.
make setup # installs the pinned mise version (if missing) + pinned tool versions from mise.lock
38
-
make bootstrap-nss cuda
68
+
uv sync --frozen --extra cu128 --extra engine --group dev
69
+
# or, for CUDA 13.0:
70
+
uv sync --frozen --extra cu130 --extra engine --group dev
39
71
```
40
72
41
73
Development tools (`ruff`, `ty`, `yq`, `gh`, etc.) are managed via [mise](https://mise.jdx.dev/). Tool versions are declared in `.mise.toml` and locked in `mise.lock` (committed). mise also manages environment variables -- place project-local secrets or overrides in `.env` or `.env.local` (both git-ignored, auto-loaded by mise).
0 commit comments