[Snyk] Upgrade onnxruntime-web from 1.14.0 to 1.23.0 #8426
      
        
          +1
        
        
          −1
        
        
          
        
      
    
  
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
Snyk has created this PR to upgrade onnxruntime-web from 1.14.0 to 1.23.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 245 versions ahead of your current version.
The recommended version was released a month ago.
Release notes
Package name: onnxruntime-web
Announcements
This release introduces Execution Provider (EP) Plugin API, which is a new infrastructure for building plugin-based EPs. (#24887 , #25137, #25124, #25147, #25127, #25159, #25191, #2524)
This release introduces the ability to dynamically download and install execution providers. This feature is exclusively available in the WinML build and requires Windows 11 version 25H2 or later. To leverage this new capability, C/C++/C# users should use the builds distributed through the Windows App SDK, and Python users should install the onnxruntime-winml package(will be published soon). We encourage users who can upgrade to the latest Windows 11 to utilize the WinML build to take advantage of this enhancement.
Upcoming Changes
Execution & Core Optimizations
Shutdown logic on Windows is simplified
Now on Windows some global object will be not destroyed if we detect that the process is being shutting down(#24891) . It will not cause memory leak as when a process ends all the memory will be returned to the operating system. This change can reduce the chance of having crashes on process exit.
AutoEP/Device Management
Now ONNX Runtime has the ability to automatically discovery computing devices and select the best EPs to download and register. The EP downloading feature currently only works on Windows 11 version 25H2 or later.
Execution Provider (EP) Updates
ROCM EP was removed from the source tree. Users are recommended to use Migraphx or Vitis AI EPs from AMD.
A new EP, Nvidia TensorRT RTX, was added.
Web
EMDSK is upgraded from 4.0.4 to 4.0.8
WebGPU EP
Added WGSL template support.
QNN EP
SDK Update: Added support for QNN SDK 2.37.
KleidiAI
Enhanced performance for SGEMM, IGEMM, and Dynamic Quantized MatMul operations, especially for Conv2D operators on hardware that supports SME2 (Scalable Matrix Extension v2).
Known Problems
Contributions
Contributors to ONNX Runtime include members across teams at Microsoft, along with our community members:
@ 1duo, @ Akupadhye, @ amarin16, @ AndreyOrb, @ ankan-ban, @ ankitm3k, @ anujj, @ aparmp-quic, @ arnej27959, @ bachelor-dou, @ benjamin-hodgson, @ Bonoy0328, @ chenweng-quic, @ chuteng-quic, @ clementperon, @ co63oc, @ daijh, @ damdoo01-arm, @ danyue333, @ fanchenkong1, @ gedoensmax, @ genarks, @ gnedanur, @ Honry, @ huaychou, @ ianfhunter, @ ishwar-raut1, @ jing-bao, @ joeyearsley, @ johnpaultaken, @ jordanozang, @ JulienMaille, @ keshavv27, @ kevinch-nv, @ khoover, @ krahenbuhl, @ kuanyul-quic, @ mauriciocm9, @ mc-nv, @ minfhong-quic, @ mingyueliuh, @ MQ-mengqing, @ NingW101, @ notken12, @ omarhass47, @ peishenyan, @ pkubaj, @ qc-tbhardwa, @ qti-jkilpatrick, @ qti-yuduo, @ quic-ankus, @ quic-ashigarg, @ quic-ashwshan, @ quic-calvnguy, @ quic-hungjuiw, @ quic-tirupath, @ qwu16, @ ranjitshs, @ saurabhkale17, @ schuermans-slx, @ sfatimar, @ stefantalpalaru, @ sunnyshu-intel, @ TedThemistokleous, @ thevishalagarwal, @ toothache, @ umangb-09, @ vatlark, @ VishalX, @ wcy123, @ xhcao, @ xuke537, @ zhaoxul-qti
Announcements
GenAI & Advanced Model Features
Execution & Core Optimizations
Core
Execution Provider (EP) Updates
CPU EP/MLAS
MatMulNBits, enabling matrix multiplication with weights quantized to 8 bits.OpenVINO EP
QNN EP
TensorRT EP
NV TensorRT RTX EP
CUDA EP
MatMulNBits.VitisAI EP
Infrastructure & Build Improvements
Build System & Packages
Dependencies / Version Updates
Web
Mobile
Contributions
Contributors to ONNX Runtime include members across teams at Microsoft, along with our community members:
Yulong Wang, Jian Chen, Changming Sun, Satya Kumar Jandhyala, Hector Li, Prathik Rao, Adrian Lizarraga, Jiajia Qin, Scott McKay, Jie Chen, Tianlei Wu, Edward Chen, Wanming Lin, xhcao, vraspar, Dmitri Smirnov, Jing Fang, Yifan Li, Caroline Zhu, Jianhui Dai, Chi Lo, Guenther Schmuelling, Ryan Hill, Sushanth Rajasankar, Yi-Hong Lyu, Ankit Maheshkar, Artur Wojcik, Baiju Meswani, David Fan, Enrico Galli, Hans, Jambay Kinley, John Paul, Peishen Yan, Yateng Hong, amarin16, chuteng-quic, kunal-vaishnavi, quic-hungjuiw, Alessio Soldano, Andreas Hussing, Ashish Garg, Ashwath Shankarnarayan, Chengdong Liang, Clément Péron, Erick Muñoz, Fanchen Kong, George Wu, Haik Silm, Jagadish Krishnamoorthy, Justin Chu, Karim Vadsariya, Kevin Chen, Mark Schofield, Masaya, Kato, Michael Tyler, Nenad Banfic, Ningxin Hu, Praveen G, Preetha Veeramalai, Ranjit Ranjan, Seungtaek Kim, Ti-Tai Wang, Xiaofei Han, Yueqing Zhang, co63oc, derdeljan-msft, genmingz@AMD, jiangzhaoming, jing-bao, kuanyul-quic, liqun Fu, minfhong-quic, mingyue, quic-tirupath, quic-zhaoxul, saurabh, selenayang888, sfatimar, sheetalarkadam, virajwad, zz002, Ștefan Talpalaru
What's new?
Announcements
GenAI & Advanced Model Features
Enhanced Decoding & Pipeline Support
API & Compatibility Updates
Bug Fixes for Model Output
top_kon CPU.Execution & Core Optimizations
Core Refinements
Execution Provider (EP) Updates
General
TensorRT EP Improvements
NMS,RoiAlign,NonZero) to TensorRT by default.trt_op_types_to_excludeto exclude specific ops from TensorRT assignment.CUDA EP Improvements
QNN EP Improvements
--use_qnn static_lib.DirectML EP Support & Upgrades
OpenVINO EP Improvements
SkipLayerNormalization,MatMulNBits,FusedGemm,FusedConv,EmbedLayerNormalization,BiasGelu,Attention,DynamicQuantizeMatMul,FusedMatMul,QuickGelu,SkipSimplifiedLayerNormalizationVitisAI EP Improvements
Mobile Platform Enhancements
CoreML Updates
Extensions & Tokenizer Improvements
Expanded Tokenizer Support
ChatGLM,Baichuan2,Phi-4, etc.Phi-4pre/post-processing support for text, vision, and audio.tokenizer.json.Image Codec Enhancements
ImageCodecnow links to native APIs if available; otherwise, falls back to built-in libraries.Unified Tokenizer API
Infrastructure & Build Improvements
Runtime Requirements
All the prebuilt Windows packages now require VC++ Runtime version >= 14.40(instead of 14.38). If your VC++ runtime version is lower than that, you may see a crash when ONNX Runtime was initializing. See https://github.com/microsoft/STL/wiki/Changelog#vs-2022-1710 for more details.
Updated minimum iOS and Android SDK requirements to align with React Native 0.76:
All macOS packages now require macOS version >= 13.3.
CMake File Changes
CMake Version: Increased the minimum required CMake version from 3.26 to 3.28. Added support for CMake 4.0.
Python Version: Increased the minimum required Python version from 3.8 to 3.10 for building ONNX Runtime from source.
Improved VCPKG support
Added the following cmake options for WebGPU EP
Added cmake option onnxruntime_BUILD_QNN_EP_STATIC_LIB for building with QNN EP as a static library.
Removed cmake option onnxruntime_USE_PREINSTALLED_EIGEN.
Fixed a build issue with Visual Studio 2022 17.3 (#23911)
Modernized Build Tools
onnxruntime_USE_CUDA_NHWC_OPSby default for CUDA builds.Dependency Cleanup
nsyncfrom dependencies.Others
Updated Node.js installation script to support network proxy usage (#23231)
Web
Contributors
Contributors to ONNX Runtime include members across teams at Microsoft, along with our community members:
Changming Sun, Yulong Wang, Tianlei Wu, Jian Chen, Wanming Lin, Adrian Lizarraga, Hector Li, Jiajia Qin, Yifan Li, Edward Chen, Prathik Rao, Jing Fang, shiyi, Vincent Wang, Yi Zhang, Dmitri Smirnov, Satya Kumar Jandhyala, Caroline Zhu, Chi Lo, Justin Chu, Scott McKay, Enrico Galli, Kyle, Ted Themistokleous, dtang317, wejoncy, Bin Miao, Jambay Kinley, Sushanth Rajasankar, Yueqing Zhang, amancini-N, ivberg, kunal-vaishnavi, liqun Fu, Corentin Maravat, Peishen Yan, Preetha Veeramalai, Ranjit Ranjan, Xavier Dupré, amarin16, jzm-intel, kailums, xhcao, A-Satti, Aleksei Nikiforov, Ankit Maheshkar, Javier Martinez, Jianhui Dai, Jie Chen, Jon Campbell, Karim Vadsariya, Michael Tyler, PARK DongHa, Patrice Vignola, Pranav Sharma, Sam Webster, Sophie Schoenmeyer, Ti-Tai Wang, Xu Xing, Yi-Hong Lyu, genmingz@AMD, junchao-zhao, sheetalarkadam, sushraja-msft, Akshay Sonawane, Alexis Tsogias, Ashrit Shetty, Bilyana Indzheva, Chen Feiyue, Christian Larson, David Fan, David Hotham, Dmitry Deshevoy, Frank Dong, Gavin Kinsey, George Wu, Grégoire, Guenther Schmuelling, Indy Zhu, Jean-Michaël Celerier, Jeff Daily, Joshua Lochner, Kee, Malik Shahzad Muzaffar, Matthieu Darbois, Michael Cho, Michael Sharp, Misha Chornyi, Po-Wei (Vincent), Sevag H, Takeshi Watanabe, Wu, Junze, Xiang Zhang, Xiaoyu, Xinpeng Dou, Xinya Zhang, Yang Gu, Yateng Hong, mindest, mingyue, raoanag, saurabh, shaoboyan091, sstamenk, tianf-fff, wonchung-microsoft, xieofxie, zz002
What's new?
Python Quantization Tool
CPU EP
QNN EP
TensorRT EP
Packaging
Contributions
Big thank you to the release manager @ yf711, along with @ adrianlizarraga,