130 wires and counting

$ follow Hugging Face

Keep up with Hugging Face in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-24
stories 83

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

TRL drops an experimental trainer as DPO moves to chunked log-probs

By RepoJournal · Filed · About Hugging Face · Composed from the cited sources · methodology

The day's work is mostly subtraction: TRL removed an unmeasurable trainer and a fused distillation path, while transformers and OpenEnv spent the day narrowing what their CI tokens and third-party actions are allowed to do.

Remove the experimental GSPO-token trainer huggingface/trl

by albertvillanova

`trl.experimental.gspo_token` is gone. It existed only to add a third `importance_sampling_level` value, "sequence_token", to a `GRPOTrainer` subclass, and the removal PR notes the module set no Hub tag of its own and reported as `GRPOTrainer` to telemetry, so nobody can measure who was using it. If you were importing it, that import now fails.

Scope GITHUB_TOKEN permissions per job (#49046) huggingface/transformers

by hf-security-analysis[bot]

CI jobs in transformers now declare their own `permissions:` blocks instead of inheriting the repository's default, as the commit puts it: a job with no block "inherits whatever the repository hands out." Fork PRs no longer run with write access they do not need.

Move DPO to chunked log probabilities huggingface/trl

by kashif

DPO moves onto the shared chunked log-probability path, deleting the duplicated fused DPO loss. The restrictions that implementation carried on mixed losses, f-divergences, and precomputed reference log-probs go away with it.

fix(ci): harden GitHub Actions workflows (#49057) (#49059) huggingface/transformers

by hf-security-analysis[bot]

The last of the security bot's sweep: workflow files flagged during review got patched, finishing the same hardening pass as the permission scoping and action pinning.

Fix mask creation not being skipped under `torch.compile` (#48975) huggingface/transformers

by jiqing-feng

One for `torch.compile` users: `_ignore_causal_mask_sdpa` and `_ignore_bidirectional_mask_sdpa` bailed out on `is_tracing(padding_mask)`, which is always true under tracing, so the 4D mask was materialized even with no padding mask and sdpa could never dispatch to its flash or oneDNN kernels via `is_causal`. The padding-mask check is now static.

Quick answers

What shipped in Hugging Face on September 24, 2026?
The day's work is mostly subtraction: TRL removed an unmeasurable trainer and a fused distillation path, while transformers and OpenEnv spent the day narrowing what their CI tokens and third-party actions are allowed to do. In total, 43 commits, 39 pull requests, and 1 releases landed.
Who contributed to Hugging Face on September 24, 2026?
11 developers shipped this update, including qgallouedec, kashif, albertvillanova, hf-security-analysis[bot], Michael Benayoun, jiqing-feng, surajsharan, and dacorvo, and 3 more.
What were the notable Hugging Face updates?
Remove the experimental GSPO-token trainer, Scope GITHUB_TOKEN permissions per job (#49046), and Move DPO to chunked log probabilities.