Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: keras-team/keras
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v3.13.1
Choose a base ref
...
head repository: keras-team/keras
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v3.13.2
Choose a head ref
  • 1 commit
  • 7 files changed
  • 6 contributors

Commits on Jan 30, 2026

  1. Version bump and cherry picks for 3.13.2 (#22080)

    * Fix DoS via malicious HDF5 dataset metadata in KerasFileEditor (#21880)
    
    * Fix DoS via malicious HDF5 dataset metadata in KerasFileEditor
    
    * Refactor: move MAX_BYTES constant outside loop per review feedback
    
    * Fix: harden HDF5 dataset metadata validation in KerasFileEditor
    
    * Do not allow external links in HDF5 files. (#22057)
    
    Keras never uses this feature.
    
    - verify that we get H5 Groups when expected, otherwise, merely by doing `[key]` we may be loading an external Dataset.
    - verify that the H5 Datasets are not external links and fail if they are.
    - remove unused methods `items` and `values` in `H5IOStore` and `ShardedH5IOStore`. They are not used, the implementation of `MutableMapping` was incomplete anyway and these methods we return unverified Datasets.
    - fixed logic related to `failed_saveables` in `load_state`.
    - preserve the order of keys in the implementation of `ShardedH5IOStore.keys()`.
    
    * Set mutable to True by default in nnx_metadata (#22074)
    
    * Disallow TFSMLayer deserialization in safe_mode to prevent external SavedModel execution (#22035)
    
    * Implement safe mode checks in TFSMLayer
    
    Added safe mode checks for loading TFSMLayer from external SavedModels.
    
    * Update keras/src/export/tfsm_layer.py
    
    Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
    
    * Align logic with __init__ method for robust checks
    
    Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
    
    * Fix indentation and formatting in tfsm_layer.py
    
    * Add setup method to enable unsafe deserialization
    
    Enable unsafe deserialization for TFSM Layer tests.
    
    * Update TFSMLayer initialization in tests
    
    * Fix import for TFSMLayer in tfsm_layer_test.py
    
    * Remove safe_mode check from TFSMLayer.__init__()
    
    The safe_mode check should only be in from_config(), not __init__().
    
    Direct instantiation (TFSMLayer(filepath=...)) is a legitimate use case
    where the user explicitly creates the layer. The security concern is
    only during deserialization of untrusted .keras files, which goes
    through from_config().
    
    This allows attackers to create malicious .keras files while still
    blocking victims from loading them with safe_mode=True.
    
    * Implement tests for TFSMLayer safe mode functionality
    
    Add comprehensive tests for TFSMLayer safe_mode behavior:
    - test_safe_mode_direct_instantiation_allowed: Verifies direct
      TFSMLayer instantiation works as expected
    - test_safe_mode_from_config_blocked: Verifies from_config() raises
      ValueError when safe_mode=True
    - test_safe_mode_from_config_allowed_when_disabled: Verifies
      from_config() works with safe_mode=False
    - test_safe_mode_model_loading_blocked: Tests the full attack scenario
      where loading a .keras file with safe_mode=True is blocked
    
    * Clarify test docstrings in tfsm_layer_test.py
    
    Updated test docstrings for clarity on instantiation and loading behavior.
    
    * Invoke model with random input in tfsm_layer tests
    
    Added model invocation with random input to tests for TFSMLayer.
    
    * Set safe_mode default to True in from_config method
    
    * Update tfsm_layer_test.py
    
    * Update tfsm_layer_test.py
    
    * Update tfsm_layer_test.py to original
    
    * New test case tfsm_layer_test.py
    
    * Update Comments tfsm_layer.py
    
    * Update tfsm_layer_test.py
    
    * Update tfsm_layer.py
    
    * Update tfsm_layer.py to remove ruff errors
    
    * Update tfsm_layer.py
    
    * Update tfsm_layer_test.py
    
    * Update tfsm_layer.py
    
    * Update tfsm_layer.py
    
    * Update tfsm_layer_test.py
    
    * Update tfsm_layer.py format fix
    
    Changes in format
    
    * Update tfsm_layer.py
    
    * Update tfsm_layer_test.py
    
    * Update tfsm_layer.py
    
    * Update tfsm_layer_test.py
    
    * Fixes unnecessary changes tfsm_layer.py
    
    * Added new test case tfsm_layer_test.py
    
    * Set `safe_mode=None` in `from_config`, which fixes the unit tests.
    
    Also re-added empty lines.
    
    * Remove unneeded `custom_objects` in unit tests.
    
    ---------
    
    Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
    Co-authored-by: Fabien Hertschuh <1091026+hertschuh@users.noreply.github.com>
    
    * patch release 3.12.2 changes
    
    ---------
    
    Co-authored-by: sarvesh patil <103917093+HyperPS@users.noreply.github.com>
    Co-authored-by: hertschuh <1091026+hertschuh@users.noreply.github.com>
    Co-authored-by: Divyashree Sreepathihalli <divyashreepathihalli@gmail.com>
    Co-authored-by: Manan Patel <70314133+0xManan@users.noreply.github.com>
    Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
    6 people authored Jan 30, 2026
    Configuration menu
    Copy the full SHA
    e29d0ef View commit details
    Browse the repository at this point in the history
Loading