Skip to content

release: 2.33.0 - #548

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main
Open

release: 2.33.0#548
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Automated Release PR

2.33.0 (2026-08-28)

Features

  • cli: add list/delete aliases for beta endpoints ls/rm (ENG-92294) (#538) (b071670)
  • CLI: add tg batches commands for the batch API (#525) (013976d)
  • cli: introduce ExperimentalConfig for experimental opt-in features in jig (#543) (d653373)
  • endpoints: List enum values for endpoint scaling metric values (be959b2)
  • ENG-92086 - call prewarm API after volume upload and image build (#535) (b436f0c)
  • Evals CLI: show files upload progress during evals create (#534) (37ddff1)
  • expose RL GPU configurations in OpenAPI (91b508a)
  • expose RL session policy state (e83ef66)

Bug Fixes

  • cli: preserve endpoint API failure diagnostics (#537) (ba27d45)
  • cli: preserve endpoint creation diagnostics (#541) (4641ddf)
  • cli: preserve endpoint deletion failure diagnostics (#533) (6c706ae)
  • cli: preserve missing argument diagnostics (#549) (d98ddc1)
  • cli: remove --scale-to-zero-window from beta endpoints (#545) (53710f9)
  • cli: show upload progress for batch submit (#546) (5b23e37)
  • cli: stabilize UnknownOptionError telemetry (#539) (23c3498)
  • Finetuning CLI: remove broken pagination on list-events command (#540) (cd8018d)

Chores

Documentation

  • openapi: sync rollout landing floor descriptions (222b48a)
  • sync rollout final target semantics (be0aa66)

This PR was generated with Release Please. See documentation.

@broly-code-security-scanner

broly-code-security-scanner Bot commented Aug 26, 2026

Copy link
Copy Markdown

Broly Security Scan

Note

Summary

113 actionable finding(s) in this PR

  • 🟡 113 medium

5 highest-priority actionable rows in the table below (critical/high first, then top medium).

No finding is at or above high, so this check is not blocking. The findings above are still tracked and reported.

Severity Scanner Issue Location Dismiss
🟡 MEDIUM SCA GHSA-27mf-ghqm-j3j8:
aiohttp@
→ >= 3.10.11
pyproject.toml:1 d20
🟡 MEDIUM SCA GHSA-2fqr-mr3j-6wp8:
aiohttp@
→ >= 3.14.1
pyproject.toml:1 d21
🟡 MEDIUM SCA GHSA-2vrm-gr82-f7m5:
aiohttp@
→ >= 3.13.4
pyproject.toml:1 d22
🟡 MEDIUM SCA GHSA-3pqx-4fqf-j49f:
PyYAML@
→ >= 5.2
pyproject.toml:1
🟡 MEDIUM SCA GHSA-3wq7-rqq7-wx6j:
aiohttp@
→ >= 3.13.4
pyproject.toml:1 d23

Dismiss false positives

Tick a box to dismiss the finding; untick it to bring the finding back. That is the same as replying /broly dismiss d1 and /broly undismiss d1. To record why it is a false positive, reply with /broly dismiss d1: your reason instead — Broly reuses those reasons to triage similar findings across the org.

  • d1 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-h8pj-cxx2-jfg2: httpx@
  • d2 · 🟡 MEDIUM   · pyproject.toml:1 · PYSEC-2022-183: httpx@
  • d3 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-5jqp-qgf6-3pvh: pydantic@
  • d4 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-mr82-8j83-vxmv: pydantic@
  • d5 · 🟡 MEDIUM   · pyproject.toml:1 · PYSEC-2021-47: pydantic@
  • d6 · 🟡 MEDIUM   · pyproject.toml:1 · PYSEC-2026-1812: pydantic@
  • d7 · 🟡 MEDIUM   · pyproject.toml:1 · filelock@3.13.1 — 4 vulnerabilities (worst: GHSA-qmgc-5h2g-mvrw)
  • d16 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-6g87-ff9q-v847: websockets@
  • d17 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-8ch4-58qp-g3mp: websockets@
  • d18 · 🟡 MEDIUM   · pyproject.toml:1 · PYSEC-2018-79: websockets@
  • d19 · 🟡 MEDIUM   · pyproject.toml:1 · PYSEC-2021-95: websockets@
  • d20 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-27mf-ghqm-j3j8: aiohttp@
  • d21 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-2fqr-mr3j-6wp8: aiohttp@
  • d22 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-2vrm-gr82-f7m5: aiohttp@
  • d23 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-3wq7-rqq7-wx6j: aiohttp@
  • d24 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-45c4-8wx5-qw6w: aiohttp@
  • d25 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-4fvr-rgm6-gqmc: aiohttp@
  • d26 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-4m7w-qmgq-4wj5: aiohttp@
  • d27 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-54jq-c3m8-4m76: aiohttp@
  • d28 · 🟡 MEDIUM   · pyproject.toml:1 · GHSA-5h86-8mv2-jq9f: aiohttp@

93 more dismissable finding(s) omitted (max 20 per scan). Reply with /broly dismiss ID using the IDs above.

Note

Re-scan this PR anytime with /broly scan — useful after /broly undismiss, or to refresh findings without a new push.

Broly — SAST (zai-org/GLM-5.3-Flash) · Secrets · SCA · IaC · GH Actions · Base Images · Supply Chain Threats · Exploit Chains · Adversarial Verification

We're continuously improving Broly's accuracy and finding quality — your feedback is valuable. False positives, missed findings, bugs, and feature requests all welcome.

Ask in #security-engineering   Powered by Together AI

@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 8 times, most recently from 7d1f2b8 to e62a6ec Compare August 28, 2026 14:03
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from e62a6ec to 0f333ee Compare August 28, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants