You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Simplify setup and link the training tutorial and model weights - #1
Previously, uv sync --locked omitted the Together SDK and tg CLI because they were optional training dependencies. Make the pinned Together SDK a standard dependency so the tutorial's basic setup installs both.
Update the lockfile, README, training guide, contribution instructions, and CI to use the simpler commands. The SDK serialization test now fails if the required dependency is missing instead of skipping.
Add prominent links near the top of the README to the full $17 classifier training tutorial and the Hugging Face model weights, replacing the outdated announcement of a forthcoming blog post.
Validation: uv sync --locked --offline succeeds; uv run --locked --offline tg --version reports 2.23.0; all 25 tests pass for the dependency change. The subsequent README-only change passes git diff --check.
Tick a box to dismiss the finding; untick it to bring the finding back. That is the same as replying /broly dismiss d1 and /broly undismiss d1. To record why it is a false positive, reply with /broly dismiss d1: your reason instead — Broly reuses those reasons to triage similar findings across the org.
d1 · 🟡 MEDIUM · uv.lock:1 · PYSEC-2026-3716: datasets@4.8.5
Note
Re-scan this PR anytime with /broly scan — useful after /broly undismiss, or to refresh findings without a new push.
We're continuously improving Broly's accuracy and finding quality — your feedback is valuable. False positives, missed findings, bugs, and feature requests all welcome.
Nutlope
changed the title
Install Together SDK and CLI with plain uv sync --locked
Simplify setup and link the training tutorial and model weights
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously,
uv sync --lockedomitted the Together SDK andtgCLI because they were optional training dependencies. Make the pinned Together SDK a standard dependency so the tutorial's basic setup installs both.Update the lockfile, README, training guide, contribution instructions, and CI to use the simpler commands. The SDK serialization test now fails if the required dependency is missing instead of skipping.
Add prominent links near the top of the README to the full $17 classifier training tutorial and the Hugging Face model weights, replacing the outdated announcement of a forthcoming blog post.
Validation:
uv sync --locked --offlinesucceeds;uv run --locked --offline tg --versionreports 2.23.0; all 25 tests pass for the dependency change. The subsequent README-only change passesgit diff --check.