# The environment the published numbers were measured in.
#
# WHY THIS FILE EXISTS
#
# A version range says which versions a run COULD have used. It does not say which one it did, and
# for a project whose whole argument is that other people's numbers deserve scrutiny, "you can
# probably reproduce this" is not good enough. `pyproject.toml` keeps the ranges, because a library
# that pins its dependencies is a library nobody can install beside anything else. This file is the
# other half: the exact set a reader can install to stand where the numbers were produced.
#
#     pip install -e . -c constraints.txt
#
# HOW IT WAS PRODUCED, so it can be produced again
#
# Read from the interpreter that ran the benchmark, on the GPU machine, on 2026-08-16, rather than
# resolved fresh. A constraints file generated by re-resolving would pin whatever is current today,
# which is a different environment wearing the same filename.
#
# WHAT IS DELIBERATELY NOT PINNED HERE
#
# The CUDA build suffix. The card ran `torch==2.13.0` built against CUDA 13.0; a reader on CPU
# installs the same version with no suffix and gets the same arithmetic in a different number of
# seconds. Pinning `+cu130` would make this file uninstallable for most readers to buy a guarantee
# that is not about the result. The version is what matters and the version is here.
#
# TWO KNOWN DRIFTS, stated rather than smoothed over. The development machine carries
# `transformers==5.14.1`, `datasets==5.0.1` and `huggingface-hub==1.25.1` against the card's
# 5.13.1, 5.0.0 and 1.23.0. Every published number comes from the card, so the card's versions are
# the ones pinned. The suite passes on both, which is the only claim being made about the pair.
#
# ONE PIN HAS BEEN MOVED OFF THE CARD'S VERSION, on 2026-09-22, and it is recorded here rather
# than quietly changed. `datasets` ran at 5.0.0 on the card. That release carries a path
# traversal in its folder-based builders, where a `file_name` in the metadata is joined to the
# dataset directory without validation, and this tool reads datasets somebody else published. So
# the pin is the fixed release, which is the one the development machine was already running and
# which the suite has therefore always been passing on. The advisory is in the builder rather
# than in anything that computes a number, so no published figure depends on which of the two
# was used; if that ever stops being obvious, the honest move is to re-measure rather than to
# argue about it.
#
# THE GENERAL RULE THIS SETS. A file recording what produced a number must not be edited to make
# a number look better, and that is not what this is: the version moved for a defect that has
# nothing to do with measurement, and the version it moved from is written above. Anything that
# would change a figure gets a re-measurement, not a note.

torch==2.13.0
transformers==5.13.1
tokenizers==0.22.2
huggingface-hub==1.23.0
safetensors==0.8.0
accelerate==1.14.0
datasets==5.0.1
# A DIRECT dependency since `trackio.py`, and the library that now hands the prompts to every
# run. It was present transitively underneath `datasets` in every measurement to date, but the
# July sweep did not record it and neither did the card, so this is the version the development
# machine carries rather than one read off a run. Runs from here on record it themselves:
# `crashsafe.PROVENANCE_PACKAGES` names it, so the next published number can say which pyarrow
# read its corpus instead of leaving a reader to work it out from the `datasets` pin.
pyarrow==25.0.0
optuna==4.9.0
numpy==2.5.1
scipy==1.18.0

# The 4-bit path, which the scorer and the compass accept and the abliterator refuses on purpose:
# a Params4bit tensor cannot be orthogonalised. Pinned because a reader measuring a large model in
# 4-bit is measuring with this, and because it is the dependency most likely to move under a
# reader's feet.
bitsandbytes==0.49.2
