-
Notifications
You must be signed in to change notification settings - Fork 12
Expand file tree
/
Copy pathpyproject.toml
More file actions
124 lines (113 loc) · 4.92 KB
/
Copy pathpyproject.toml
File metadata and controls
124 lines (113 loc) · 4.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
[build-system]
requires = ["hatchling"]
build-backend = "hatchling.build"
[project]
name = "fact_reasoner"
version = "0.8.0"
description = "Factuality Assessment for Foundation Models"
authors = [
{name = "Radu Marinescu", email = "radu.marinescu@ie.ibm.com"},
{name = "Javier Carnerero Cano", email = "javier.cano@ibm.com"},
{name = "Massimiliano Pronesti", email = "massimiliano.pronesti@ibm.com"},
]
license = {text = "Apache-2.0"}
readme = "README.md"
requires-python = ">=3.11"
classifiers = [
"License :: OSI Approved :: Apache Software License",
"Programming Language :: Python :: 3",
"Operating System :: OS Independent",
]
# `numpy`, `scikit-learn`, `sentence-transformers`, `rouge-score` and `joblib`
# were once an optional "simbauq" extra, but none of them is actually optional:
# * numpy is imported unguarded at module scope by fact_reasoner.uncertainty,
# which core.nli imports eagerly -- so even `fact-reasoner --help` needs it.
# * the sentence-transformers similarity gate backs `--nli-mode fast`, which is
# a cost control unrelated to SIMBA-UQ.
# * joblib is imported directly by uncertainty.nli_training rather than being
# used through scikit-learn, so it is declared here rather than relied on
# transitively.
# Lower bounds are security floors, not preferences: each one is the first
# release that patches a known advisory against this dependency set (see the
# repository's security tracking issue). Raise them when new advisories land;
# do not relax them. `chromadb` is deliberately not declared anywhere in this
# file -- not even as an optional extra -- see the note below.
dependencies = [
"beautifulsoup4",
"joblib",
"langchain-community",
"langchain-core>=1.3.3",
"langchain-huggingface",
"langchain-text-splitters",
"mellea==0.7.0",
"networkx",
"nltk>=3.10.3",
"numpy",
"pandas>=2.3.1",
"pymilvus[model,milvus-lite]",
# pypdf supersedes the abandoned PyPDF2 (last release 3.0.1, CVE-2023-36464
# unpatched). Drop-in for the only API we use: PdfReader(BytesIO(...)),
# .pages and .extract_text() in core/retriever.py.
"pypdf>=6.1.1",
"python-dotenv",
"requests",
"rouge-score",
"scikit-learn",
"sentence-transformers",
"thefuzz",
"tqdm",
"wikipedia",
# Transitive pins. These are pulled in by langchain / chromadb / vllm rather
# than imported here, but the resolver will happily pick a vulnerable version
# unless we floor it.
"aiohttp>=3.14.3",
"idna>=3.15",
# langsmith 0.9+ switches to an httpx2 stack; the cap keeps that migration a
# deliberate change rather than a silent one.
"langsmith>=0.8.18,<0.13",
"pillow>=12.3.0",
"pydantic-settings>=2.14.2",
"soupsieve>=2.8.4",
"urllib3>=2.7.0",
]
[project.optional-dependencies]
# There is deliberately no `chroma` extra. The `--service-type chromadb` backend is
# still supported, but `chromadb` is not declared here in any form, because every
# release up to and including 1.5.9 -- the latest on PyPI -- carries unpatched
# critical advisories: CVE-2026-45829 (pre-authentication code injection) and
# CVE-2026-45833 (code injection). No patched release exists to floor against.
#
# An optional extra would not help: `uv lock` pins every extra, so declaring
# chromadb even optionally writes a vulnerable version into uv.lock and keeps the
# whole project in scope of those alerts. Users who want the backend install it
# themselves (`pip install chromadb`), accepting that risk; ChromaReader imports it
# lazily and raises an actionable ImportError when it is absent. The other two
# backends (`google`, `wikipedia`) need no extra install.
# RITS backends (IBM internal). See README for the mellea-ibm install source.
rits = ["mellea-ibm"]
# Local vLLM server path (GPU node). vLLM is invoked as an external process, not
# imported, so this only needs to be installed where the server is launched.
vllm = ["vllm"]
dev = ["pytest", "pytest-asyncio", "ruff", "mypy", "build", "twine"]
[project.scripts]
fact-reasoner = "fact_reasoner.cli:main"
[project.urls]
Source = "https://github.com/IBM/FactReasoner"
# Test configuration (previously a standalone pytest.ini). `pythonpath` is what
# lets the suite import `fact_reasoner` from src/ without an editable install.
[tool.pytest.ini_options]
testpaths = ["tests"]
pythonpath = ["src"]
addopts = "-ra -q"
markers = ["asyncio: mark test as asyncio"]
asyncio_mode = "auto"
# uv-specific: tells `uv lock`/`uv sync` where to find the IBM-internal
# `mellea-ibm` package (the `rits` extra). This metadata is ignored by the built
# wheel and by pip/PyPI consumers; it only affects uv-based resolution and
# requires git-ssh access to github.ibm.com.
[tool.uv.sources]
mellea-ibm = { git = "ssh://git@github.ibm.com/generative-computing/mellea-ibm.git" }
[tool.hatch.build.targets.wheel]
packages = ["src/fact_reasoner"]
[tool.hatch.build.targets.sdist]
exclude = ["docs/", "data/", "lib/", "tests/", "configs/"]