$ cat huggingface/week/2026-09-21.log
the week in review · Sep 21 – Sep 27, 2026
TRL 1.14 removes trl.losses, drops GSPO-token
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
The breaking release moves DPO, KTO and GRPO onto chunked, fused log-probs, so any code importing from trl.losses stops working.
v1.14.0 huggingface/trl
v1.13 vendored the fused linear losses; 1.14 removes the module and lets DPO, KTO and GRPO stream their own log-probs instead. The import path your training script uses today will raise on upgrade.
Move DPO to chunked log probabilities huggingface/trl
DPO now runs on the shared chunked log-probability route with the loss math kept in one place, which lifts its restrictions on mixed losses, f-divergences, and precomputed reference log-probs. It is the mechanism behind the trl.losses removal, so treat them as one migration.
Use fused kernels for logprobs and entropy huggingface/trl
The fused logprob and entropy kernel published to trl-lib/trl-losses handles temperature scaling and row masking for GRPO, RLOO, DPO, KTO and TPO, with the PyTorch implementation kept as a fallback. If you were relying on the old fused linear loss module, this is where that path now lives.
Remove the experimental GSPO-token trainer huggingface/trl
The GRPOTrainer subclass existed only to add a third `importance_sampling_level` value, `"sequence_token"`, and the PR reports that most surveyed users could not say what it did for them. Configs setting that value need to change before the trainer disappears from their imports.
Resolve the Hub revision once per load instead of passing a private _commit_hash around huggingface/transformers
The Hub revision is now resolved once per load rather than carried around as a private `_commit_hash`. Key-value caches are keyed off the resolved revision, so local caching behaves predictably across the load path.
kernels: verify the signature of a kernel while loading huggingface/kernels
Signature verification, previously reachable only through the `kernels verify-signature` command, now runs during kernel loading. The release notes describe it as a step-wise roll-out, so expect the strictness to increase rather than arrive all at once.
chore(deps): bump rustls to 0.23.45 to fix RUSTSEC-2026-0285 (cargo audit) huggingface/xet-core
rustls moves to 0.23.45, clearing the Cargo Audit failure on RUSTSEC-2026-0285, a medium-severity TLS 1.3 handshake flaw published 2026-09-14. Anything in the Xet stack you build yourself should take the same bump.
LanceDB loader quick wins: fail-closed open, lazy blob handles, row ids resolved once huggingface/lerobot
The lance reader now publishes its handles last, so a transient error mid-open no longer leaves a reader failing every later read with `'NoneType' object is not subscriptable`; blob handles are lazy and row ids are resolved once. The fixes come from running the reader on a large dataset, which is the failure mode to watch for in long training jobs.
$ ls huggingface/week/ # the briefings behind this review
Keep up with Hugging Face in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.