Safetensors, the secure tensor serialization format created by Hugging Face, is joining the PyTorch Foundation under the Linux Foundation's governance. The format — designed to safely store and share ML model weights without arbitrary code execution risks — has become the default for model distribution on the Hugging Face Hub and across the open ML ecosystem. The move transfers trademark and repository governance to a vendor-neutral home while Hugging Face maintainers remain on the Technical Steering Committee. No breaking changes for existing users. Upcoming work includes PyTorch core integration, device-aware loading (CUDA/ROCm), Tensor Parallel and Pipeline Parallel loading APIs, and formalized support for quantized formats like FP8, GPTQ, and AWQ.

4m read timeFrom huggingface.co
Post cover image
Table of contents
How we got hereWhy the PyTorch FoundationWhat this means for users and contributorsWhat comes nextGet involved

Sort: