Bump Microsoft.ML.OnnxRuntime from 1.27.0 to 1.27.1 - #978
#978Bump Microsoft.ML.OnnxRuntime from 1.27.0 to 1.27.1#978shanselman merged 1 commit intomainopenclaw/openclaw-windows-node:mainfrom dependabot/nuget/src/OpenClaw.Shared/Microsoft.ML.OnnxRuntime-1.27.1openclaw/openclaw-windows-node:dependabot/nuget/src/OpenClaw.Shared/Microsoft.ML.OnnxRuntime-1.27.1Copy head branch name to clipboard
Conversation
--- updated-dependencies: - dependency-name: Microsoft.ML.OnnxRuntime dependency-version: 1.27.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex review: needs maintainer review before merge. Reviewed July 13, 2026, 2:26 AM ET / 06:26 UTC. Summary Reproducibility: not applicable. This PR is a direct dependency-maintenance update rather than a report of broken repository behavior. Review metrics: 2 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Next step before merge
Security Review detailsBest possible solution: Merge the one-line patch update after the full build, shared tests, tray tests, and applicable native packaging or audio-runtime checks pass on the exact PR head. Do we have a high-confidence way to reproduce the issue? Not applicable; this PR is a direct dependency-maintenance update rather than a report of broken repository behavior. Is this the best way to solve the issue? Yes; updating the existing direct PackageReference in place is the narrowest maintainable approach, provided the repository's Windows build, test, and packaging gates pass. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against 06b4f6362594. Label changesLabel changes:
Label justifications:
Evidence reviewedWhat I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
|
Minor update. For dependency bumps, please confirm whether any CI or lockfile regeneration side-effects were expected and if any runtime compatibility checks changed. |
|
Thanks. For dependency bumps, could you list any runtime/manual validation done for the desktop + tray paths? |
|
Dependency bump looks straightforward. For traceability maybe confirm if package signature/source policy accepts this patch without additional changelog update in this repo? |
Updated Microsoft.ML.OnnxRuntime from 1.27.0 to 1.27.1.
Release notes
Sourced from Microsoft.ML.OnnxRuntime's releases.
1.27.1
This is a patch release on top of v1.27.0, containing targeted bug fixes, a CUDA QMoE decode-path optimization, and CI/build infrastructure fixes.
Bug Fixes
igemmregression in the KleidiAI path (#28571)Performance
NVIDIA CUDA EP
CI & Build Infrastructure
azcopy(#29274)brew install applesimutilsfailure by trusting the wix/brew tap (#29450)mac-cpu-packing-jobs.yml(#29575)Contributors
Thanks to our 8 contributors for this release!
@tianleiwu, @chilo-ms, @edgchen1, @adrastogi, @damdoo01-arm, @JonathanC-ARM, @martin-klacer-arm, @sanaa-hamel-microsoft
Full Changelog: v1.27.0...v1.27.1
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)