hf jobs stats and HfApi.fetch_job_metrics now return a single snapshot instead of streaming until job completion, with -f/--follow on the CLI and follow=True in Python restoring the previous behavior. Also fixed a race in _get_version that made concurrent downloads skip hf_xet, and multiple HfFileSystem cache issues including duplicate listings and stale not-found results.
Hub
Python client for the Hugging Face Hub API
npx @buildinternet/releases get hubA 9-PR sandbox security audit replaces host-wide credentials with per-sandbox capability tokens, validates pool hosts before sending credentials, and keeps secret values out of argv; torch checkpoint deserialization now defaults to safe=True across 11 reported vulnerabilities. Imports drop from 2.36s to 0.39s through lazy loading, and the cache now deduplicates Xet files across repos via a shared blob store.
Dedicated sandboxes now accept custom labels for cost attribution and bookkeeping, attached to the underlying Job. Downloads are more resilient to server response issues, network hiccups, and concurrent usage: timeouts on streamed response headers are now retried, HEAD requests without Content-Length no longer fail, snapshot_download writes cache files atomically to fix races under concurrent access, and dry-run no longer copies cached files to disk. A path-traversal vulnerability in HfFileSystem.get() on Windows is fixed, and httpx is now re-exported from huggingface_hub.utils for library integrators.
Jobs filter flag deprecated; ResolvedRevision pins per-repo
Breaking (minor)hf jobs scheduled ls now filters by --status, repeatable --label, and --name, matching hf jobs ls; the old -f/--filter flag is accepted but ignored with a warning and will be removed in a future release. ResolvedRevision now records the repo_id and repo_type it was resolved for, so re-resolving for the same repo returns as-is while different repos are resolved again.
New chunked loss option for SFT reduces peak activation memory by processing tokens in checkpointed chunks, enabling longer sequences without OOM errors. Includes new DPO loss variant, OpenReward adapter, Cohere Cohere2 Gemma 3 Qwen3 Qwen2.5 chat templates; fixes CLI wildcard uploads and click 8.5 compatibility.
The new hf endpoints hardware command lists valid hardware combinations with pricing and quota, mirrored in the SDK via list_inference_endpoints_hardware(). custom_image now accepts engine-specific container types (keyed by engine name) with new --engine, --tensor-parallel-size, and --data-parallel-size flags for deploy and update, while INFERENCE_ENDPOINT_IMAGE_KEYS is removed.
The hf-cli skill for AI agents is now installed globally by default by the standalone installers (bash and PowerShell), refreshed on hf update, with a once-daily hint if missing — silenced by HF_HUB_DISABLE_UPDATE_CHECK=1. --container-command and --container-args no longer require --custom-image for Inference Endpoints and can be changed after deploy via hf endpoints update; --health-route and --port still require a custom image. Baseten joins as an inference provider for the conversational task, plus a bucket prefix collision fix in HfFileSystem and a fix preventing double deletion of snapshot files.
HfApi.resolve_revision and ResolvedRevision let libraries pin a revision once and guarantee all files come from the same commit. Two security fixes: downloads now reject absolute, UNC, and traversal filenames on all platforms, and the sandbox bootstrap no longer injects the HF token. Resource groups are now supported for Jobs and Collections, and the CLI surfaces job names as a first-class field.
Jobs now get an automatic name derived from the Docker image plus a command hash, making reruns and grouping easier. Also adds timeout parameter to safetensors metadata methods, updates file-count progress bars on download completion, and warns on cache inconsistency.
Jobs on the Hub now support an optional --name flag on the CLI and a name parameter on the Python API, making them easier to find in the UI. The README was recast to put the hf CLI first, with a new "For AI agents" section.
Sandboxes introduce isolated cloud VMs with live-streamed output, file transfer, and a proxy for reaching in-sandbox servers. Snapshot downloads now cache repo file listings on disk for a single-network-call re-download. The CLI was rebuilt on Click, deprecating Typer. Breaking changes include case-sensitive pattern matching on all platforms, removal of six inference providers, and deprecation of upload_large_folder.